Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
david_stardust
Explorer

Integrating with RSA SecurID REST

Hello Team, I would like to integrate Checkpoint with RSA SecurID REST authentication, not the SDK implementation, according to this guide https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topi... I have a question in this field about the certificate in particular:- Edit the $CPDIR/conf/RSARestServer.conf file. Fill in these fields: host - The configured host name of the RSA server. port, client key, and accessid - From the RSA SecurID Authentication API window. certificate - The name of the certificate file. 1- In case the REST API FQDN is based on intermediate and Root Certificate, which format is supported in Checkpoint ? p7b or pem 2- In the Certificate field, shall I put the certificate in the same directory of conf or specify the full path in this configuration file ? Since this was not mentioned in the guide, thanks for anyone to elaborate, I appreciate it. David
0 Kudos
3 Replies
david_stardust
Explorer

I figured it out and it needs the certificate in the same directory as $CPDIR/conf/ and also .pem as the extension. Now the last question would be :

I have multiple replica servers for RSA Authentication Manager, how can I do the load balancing or try another if one fails? I tried adding comma and ; between the host entries and it never understands it. Do I need to create a separate like this one ?

 

(
:host (7sp1.dawoud.com)
:port (5555)
:clientKey (l181du8y9sc236bmk8qdff4763t7sf360oo4i4ywt5wh46769721m66qm272o43d)
:accessId (rmtn51e85ljue2k2d450531kxy8ef78m385785w480rraqe22h0i034i43lw0i63)
:certificate (7sp1RootCA.pem)
)

(
:host (7sp1rep.dawoud.com)
:port (5555)
:clientKey (l181du8y9sc236bmk8qdff4763t7sf360oo4i4ywt5wh46769721m66qm272o43d)
:accessId (rmtn51e85ljue2k2d450531kxy8ef78m385785w480rraqe22h0i034i43lw0i63)
:certificate (7sp1RootCA.pem)
)

 

or how should it be done ? We can setup an API Gateway to loadbalance but asking if there is a way to add the hostnames for the other RSA Replicas in the same configuration file ?

Thanks

 

David

0 Kudos
david_stardust
Explorer

I tried space between hostnames and add like above , also tried adding comma, ; , and slashes , tried to have space between hostnames and still it doesn't work, it only works when I put 1 hostname. Can someone please help?

thanks.

David

0 Kudos
PhoneBoy
Admin
Admin

I suspect we do not allow adding multiple hosts in the relevant configuration.
This should be taken with the TAC and confirmed: https://help.checkpoint.com 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events