Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Wayne_Hammond
Contributor
Jump to solution

Cant renew expiring certificate

Screenshot 2025-01-02 114202.png

Hi,

My VPN certificate on R81.20 Gateway expires soon and I went through the usual process of deleting the existing and creating a new one, however today I got hit with this message

 

I have not seen this before and cant find anyway round it. Found a similar post about using GuiDBedit, but that didnt work.

 

Any help greatly appreciated

Happy New Year

Wayne

0 Kudos
1 Solution

Accepted Solutions
AkosBakos
Leader Leader
Leader

Maybe it is time to open a TAC case.

----------------
\m/_(>_<)_\m/

View solution in original post

0 Kudos
19 Replies
Lesley
Mentor Mentor
Mentor

I never delete and always use renew, have you tried that?

So instead of delete either add or renew?

You try it now to renew it under IPSec VPN correct? 

-------
If you like this post please give a thumbs up(kudo)! 🙂
Wayne_Hammond
Contributor

Hi Lesley,

The renew option has never been available for certs generated by external CA (i assumed this was the case)

I cannot renew and if i try ADD i cant use the same CN details

 

Cheers

Wayne

0 Kudos
Lesley
Mentor Mentor
Mentor

Ah not self-signed.

What if you create a temp self signed cert and attach that, after that try to remove the old one. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Wayne_Hammond
Contributor

Still no go

0 Kudos
AkosBakos
Leader Leader
Leader

Hi @Wayne_Hammond 

Can you share a little bit larger screenshot? In which menu did you get this message?

Whan you changed this cert last time, this cert was used in clientless VPN too?

Akos

----------------
\m/_(>_<)_\m/
0 Kudos
Wayne_Hammond
Contributor

Hi Akos,

My larger images seem to get removed. I always do this under IPSecVPN and have never configured Clientless VPN

Cheers

Wayne

0 Kudos
AkosBakos
Leader Leader
Leader

To clarify this, so here:

You add the new one, then can't remove the old one?

2025-01-02 13_45_35-10.211.190.100-R81.20-SmartConsole.png

----------------
\m/_(>_<)_\m/
0 Kudos
Wayne_Hammond
Contributor

Correct, at the moment I have a cert installed from an EXT CA

When i try to remove (as renew greyed out), the error message appears

I have never seen this before

Thanks

0 Kudos
AkosBakos
Leader Leader
Leader

I had a try, I wanted to delete the cert which was issued by ICA

I got this error: 

2025-01-02 14_08_11-10.211.190.100-R81.20-SmartConsole.png

Maybe helps.

A

----------------
\m/_(>_<)_\m/
0 Kudos
the_rock
Legend
Legend

Weird, just tried in my lab and though its part of 3 commuities, does not give that error.

Andy

0 Kudos
Lesley
Mentor Mentor
Mentor

Make sure that if you have the temp cert active the old one is not configured in a different place.

Did you checked all the menu options in the firewall object itself? Like under VPN clients. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Wayne_Hammond
Contributor

Hi Lesley,

Yes, i cannot see it selected anywhere else

0 Kudos
Lesley
Mentor Mentor
Mentor

I think we need some screenshots. Sometimes a feature is disabled and you need to enable it in order for renewal. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
AkosBakos
Leader Leader
Leader

We haven't talk about the version. What is current version?

I found this sk, but it is not relevant, R80.20 is not supported, and the error message is totally different.

https://support.checkpoint.com/results/sk/sk108064

Akos

----------------
\m/_(>_<)_\m/
0 Kudos
Wayne_Hammond
Contributor

Saw that, but it did nothing

Thanks

0 Kudos
AkosBakos
Leader Leader
Leader

Maybe it is time to open a TAC case.

----------------
\m/_(>_<)_\m/
0 Kudos
Wayne_Hammond
Contributor

Yes time for TAC

AkosBakos
Leader Leader
Leader

Please keep us updated. 🙂

----------------
\m/_(>_<)_\m/
0 Kudos
the_rock
Legend
Legend

I believe what its telling you to do is remove any references of that certificate currently, install policy and then delete option would work.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events