- Products
- Learn
- Local User Groups
- Partners
- More
Stop Babysitting Rules.
Go Agentic
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi Team,
We have configured personal certificate as First factor and Radius as second factor authentication.
In personal certificate authentication, the firewall will check for the DN(correct me if I am wrong),can we make it to check only CN instead of DN.
Second query is that the user is having multiple certificates, so in that case how Check Point will match the exact certificate if there are two VPN certificate with two different templates?
I believe it only checks DN. Your 2nd inquiry, are you referring to just a specific user cert here?
Andy
Yes, it is user certificate
As far as I know, what we check in the cert is hard coded and can't be changed.
For the second question, it depends on what kind of a certificate we're talking about.
Hi Phoneboy,
Thanks for the information.
Is there any supporting document which says that we can't change the configuration to check CN instead of DN.
Any article which says that it will use the latest certificate if it is machine certificate.
We are using user based certificate
Hi Phoneboy,
We are using user based certificate and there are multiple certificates(eg. includes expired cert aslo) in user machine.
Why Check Point is not able to pick the valid certificate ? User is not aware of the valid/expired certificates.
Hi Phoneboy,
You can change what is taken from the certificate for matching it against the user base (LDAP or local).
Before R80.x it was a bit of a pain to configure through GuiDBedit, but since R80.10 you can select it when configuration Multiple Login Options:
See chapter: Certificate Parsing
Besides the "Fetch username from" setting as described, you will have to match the "search LDAP for", so it can find it.
So you can even go for CN, SAN.email, SAN.UPN, etc...
Btw. I configured this on R77.10 already but not that comfortable 😉
DN.CN means the CN part of the DN.
A certificate has always CN as part of DN... So exactly what you asked.
I don‘t understand the and/or part of your answer?!
Hi Norbert,
We don't want to validate DN.
We need to validate only CN.
Is that possible ?
You can try Custom Fields, otherwise I assume this would be an RFE.
I don't understand this question?
Can you post a sample Subject or SAN and tell me which part of it you want to use for finding the user in LDAP?
Hello Phoneboy,
I have a question about user authentication when user/pass + user certificate is configured: did the user need to select the certificate every time he connects to vpn or the vpn client automatically recognize the certs from repository?
Thanks a lot
I believe the first time you need to specify the certificate.
After that, the certificate should be reused.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 3 | |
| 1 | |
| 1 | |
| 1 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY