Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dunkelmorten
Contributor
Contributor

Public SSL Certificate Domain Validation options

Hello all,

 

a customer of mine is running Remote Access using MEP VPN with site configuration having gateways defined by ip addressed insteaf of FQDNs using MFA with a third party provider solution hosted internally. As of now the GW certificates are self-signed by CP ICA and have been added to customer devices trust stores.

We are currently planning to switch to SAML/IdP integration using public certificates. Initially, in order not to change too many things at once, we don't want to change site configuration, but only do the SAML/IdP stuff and the public certificates. By this, the CSRs for the public certificates have been created as SAN with VIP FQDN, Node FQDN and their ip addresses as well.

However, public PKI provider (GlobalSign) requires domain validation (as per security defaults) which is working for the FQDNs within the CSR but not for the ip addresses. These would need to be checked by looking up a file on the CP web server under the path https://%GW-IP%/.well-known/pki-validation/gsdv.txt

Does anybody know if there is an option to create this file and knows in which path this needs to be located at enabling for domain validation of ip addresses provided in a SAN certificate?

I was trying with no luck to create at "/opt/CPshrd-R81.20/conf/multiportal/httpd-conf/" where "UserCheck" and "saml-vpn" folders are found with sub-folders ".well-known/pki-validation" and adding the required text file "gsdv.txt". Additionally, changed folder and file permission to 644, but the file could not be looked up externally, neither when addressing it my browser.

 

BR,

Morten

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

There are several web servers on a Check Point gateway, but there's one that rules them all: multiportal.
While I'm not clear on the specifics, perhaps there will be some clues in $FWDIR/conf/multiportal 

0 Kudos
dunkelmorten
Contributor
Contributor

That was I my assumption as well, but with no luck.
I was trying "/opt/CPshrd-R81.20/conf/multiportal/httpd-conf/" as there are the sub-folders for "UserCheck" and "saml-vpn" located used for each of the portals. I was assuming that the path is sort of root directory for the multiportal instances, but only for those being enabled.

Looks like I would need to have an additional / manually created portal within multiportal enabling for domain validation checks, but I am not sure how to get this done or if there is an option at all for this.

As of now, it looks like I cannot use a SAN certificate for VPN having ip addresses covered, but need to get remote access VPN changed to use FQDN within site configuration instead of ip addresses due to missing domain validation options by this text file on a web server on CP GW.

0 Kudos
dunkelmorten
Contributor
Contributor

Okay, had some clarifications with a former CP PSE and got some more insights on the VPN stuff.
We don't need to have the SAN elements on the certificates, hence, my requirement is obsolete.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events