I once played in the lab and found other things which in my view should also be renewed:
CUT>>>
In addition, you should take the following extra security measures, which are documented in sk182336:
- Change the password of the LDAP Account Unit
- Reset password of local accounts connecting to VPN with password authentication
- Additional Frequently Asked Questions
- Prevent Local Accounts from connecting to VPN with Password Authentication
- Renew the server certificates for the Inbound HTTPS Inspection on the Security Gateway
- Renew the certificate for the Outbound HTTPS Inspection on the Security Gateway
- Reset Gaia OS passwords for all local users
- Regenerate the SSH local user certificate on the Security Gateway
- Renew the certificate for the SSH Inspection
<<<CUT
In my view, the list should be expanded to include the following points:
10) Web server private keys + crt
11) Grub password hashes
12) GAIA password hashes
13) IA password hashes
14) SSH server keys
15) Expert password hash
➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips