Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ChoiYunSoo
Contributor

When renewing the https inspection cert, can I use a certificate from another management server?

Hi

 

The client's HTTPS Inspection Cert expires within 6 months.

So I plan to work on replacing the certificate soon.

 

But I have a problem.

As far as I know, if you press the certification renew button at checkpoint, the cert is automatically renewed.

As a result, there may be cases where the checkpoint gateway has 'new cert' and the client PC has 'old cert'.

the period for distributing certificates to clients after renewal is too short.

 

So I would like to distribute the certificate a week to a month in advance.

I would like to know if there is any problem if I proceed with the process below.

 

1. Issue https inspection cert from another management server

2. Distributed to clients about a month ago (GPO)

3. Import a certificate distributed by another management server to the actual server.

4. policy install an monitoring

 

 

What I am most curious about here is whether it is okay to use a certificate issued by another management server.

I don't think there will be any technical problems, and when referring to the "best parctice", I didn't see any issues.

 

Are there any problems that may arise when proceeding with step 4 above?

 

 

0 Kudos
3 Replies
emmap
Employee
Employee

A Renewed certificate is different from a New cert - I think the existing certificate that is pushed out should still work after the cert is renewed, while you then get that renewed cert pushed out. I've not tested this though so if someone could confirm that would be great.

0 Kudos
ChoiYunSoo
Contributor

thank you for your reply

 

I wrote this because I also needed the opinion of someone who had experienced it accurately.

The checkpoint guide document is not clearly expressed, so it is difficult to make an accurate judgment.

 

 

0 Kudos
PhoneBoy
Admin
Admin

The HTTPS Inspection certificate is a CA certificate.
This is necessary as certificates are generated and signed on the fly based on where users are surfing to.
It is completely unrelated to the ICA of your existing management server; thus any one can be used provided clients can be configured to trust it.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events