- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all,
My CP VM R81.20 gives my browser VPN cert when connecting GAiA Portal.
I surmise it should be server.crt since it is included in /web/ subdirectory.
I heard from some version CP has changed its design and now VPN cert has only a year of validity.
However I have never got to see any case where a user is unable to access GAiA Portal.
(guess this is because validity does not matter anyway since this is mostly accessed internally, user ignoring ssl warning...)
Plus, my boss said to me that he has experienced the case where CP shows server.crt in accessing GAiA Portal.
Quick google search tells me that I can choose which certificate to present as web server.
my misgiving here is:
1. Is it expected for CP to bring VPN cert for validating itself as a web server?
2. In my little experience I assume VPN cert is not to be updated unless Site to Site VPN Blade is enabled.
After expiration which certificate would httpd choose to present, or does it stop working?
P.S.
I forgot to add I observed this in R81.20 appliance and open server as well.
One of my co-worker found out how VPN cert is selected for GAiA Portal.
When VPN Blade is OFF, server.crt is selected, the validity term of which is for 10 years.
On, GAiA Portal brings VPN cert to browser, whether it is expired or not.
My question remains unsolved...
It is like server.crt is replaced according to the status of VPN blade.
How are you validating it’s the VPN certificate, exactly?
You might be seeing a different certificate because of MultiPortal.
Bottom line: yes, you can change the certificate.
https://support.checkpoint.com/results/sk/sk97648
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY