Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
k_schekotoff
Explorer

Generic Data Center HTTPS connection

Hi All!

The Generic Data Center resource has certificate issued by 3rd party CA (internal CA). During connection procedure we need to approve certificate. The issue is the expiration time of the certificate is 4 days due to some internal reasons. Every 4 days the certificate expired and the Data Center is not available. New approval is needed after that. How we can avoid the situation with every 4 days approvals? May be we can add the CA to trusted or some how else?

4 Replies
cdav
Collaborator

Is anyone able to provide information here? I am looking to utilise generic data center object and the file would be hosted somewhere that would require TLS.

0 Kudos
PhoneBoy
Admin
Admin

Have you tried adding the relevant CA to the trusted store?
This is configured with HTTPS Inspection, which has to be done in SmartDashboard prior to R82.
Otherwise, you'd have to ask TAC.

0 Kudos
AaronCP
Advisor

Hey @cdav,

I referenced this issue on this thread recently. It's operating as designed - if you were targeting a JSON file hosted on an external GitHub repo for your IP feed, if the certificate changes, you'd want to update the certificate to avoid any secuirty issues. As a result, the gateway will clear the object cache until you accept the new certificate, impacting traffic in the process.

This is a current concern of ours. We're starting to use more of these objects in our production firewall policies to enable application owners to automate traffic flows specific to their application. It's become crucial we track certificate expiry dates to avoid impact in production. I've got an open SR with our Diamond Engineer to investigate possible workarounds to this issue. I'll update this thread if I get anywhere with it!

cdav
Collaborator

Hi @AaronCP  this is exactly what I was after as I hadn't yet spent any time investigating myself so thank you.

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 20 May 2025 @ 11:30 AM (PDT)

    Las Vegas: Check Point Hybrid Mesh

    Wed 21 May 2025 @ 11:30 AM (MST)

    Tempe, AZ: Check Point Hybrid Mesh

    Tue 03 Jun 2025 @ 06:00 PM (EDT)

    Montreal: CPX Recap

    Tue 10 Jun 2025 @ 06:00 PM (EDT)

    Quebec City: CPX Recap
    CheckMates Events