- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi Team,
We have configured personal certificate as First factor and Radius as second factor authentication.
In personal certificate authentication, the firewall will check for the DN(correct me if I am wrong),can we make it to check only CN instead of DN.
Second query is that the user is having multiple certificates, so in that case how Check Point will match the exact certificate if there are two VPN certificate with two different templates?
I believe it only checks DN. Your 2nd inquiry, are you referring to just a specific user cert here?
Andy
Yes, it is user certificate
As far as I know, what we check in the cert is hard coded and can't be changed.
For the second question, it depends on what kind of a certificate we're talking about.
Hi Phoneboy,
Thanks for the information.
Is there any supporting document which says that we can't change the configuration to check CN instead of DN.
Any article which says that it will use the latest certificate if it is machine certificate.
We are using user based certificate
Hi Phoneboy,
We are using user based certificate and there are multiple certificates(eg. includes expired cert aslo) in user machine.
Why Check Point is not able to pick the valid certificate ? User is not aware of the valid/expired certificates.
Hi Phoneboy,
You can change what is taken from the certificate for matching it against the user base (LDAP or local).
Before R80.x it was a bit of a pain to configure through GuiDBedit, but since R80.10 you can select it when configuration Multiple Login Options:
See chapter: Certificate Parsing
Besides the "Fetch username from" setting as described, you will have to match the "search LDAP for", so it can find it.
So you can even go for CN, SAN.email, SAN.UPN, etc...
Btw. I configured this on R77.10 already but not that comfortable 😉
DN.CN means the CN part of the DN.
A certificate has always CN as part of DN... So exactly what you asked.
I don‘t understand the and/or part of your answer?!
Hi Norbert,
We don't want to validate DN.
We need to validate only CN.
Is that possible ?
You can try Custom Fields, otherwise I assume this would be an RFE.
I don't understand this question?
Can you post a sample Subject or SAN and tell me which part of it you want to use for finding the user in LDAP?
Hello Phoneboy,
I have a question about user authentication when user/pass + user certificate is configured: did the user need to select the certificate every time he connects to vpn or the vpn client automatically recognize the certs from repository?
Thanks a lot
I believe the first time you need to specify the certificate.
After that, the certificate should be reused.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
3 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Mon 22 Sep 2025 @ 03:00 PM (CEST)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security EMEAMon 22 Sep 2025 @ 02:00 PM (EDT)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security AMERTue 23 Sep 2025 @ 06:00 PM (IDT)
Under the Hood: CloudGuard Network Security for Nutanix - Overview, Onboarding, and Best PracticesMon 22 Sep 2025 @ 03:00 PM (CEST)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security EMEAWed 24 Sep 2025 @ 03:00 PM (CEST)
Bereit für NIS2: Strategische Werkzeuge für Ihre Compliance-Reise 2025Thu 25 Sep 2025 @ 03:00 PM (IDT)
NIS2 Compliance in 2025: Tactical Tools to Assess, Secure, and ComplyAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY