Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Saul_Goodman
Participant
Participant

Restrict certificate extensions

Hi CheckMates,

 

Does Check Point support restriction of certificate extensions for https inspection? If yes how can we configure it?

 

Settings to Control Decrypted SSL Traffic (paloaltonetworks.com)

Restrict certificate extensions

  • Limits the certificate extensions used in the dynamic server certificate to key usage and extended key usage.
  • Restrict certificate extensions if your deployment requires no other certificate extensions.
0 Kudos
1 Reply
PhoneBoy
Admin
Admin

If it can be done anywhere, it would most likely be with the cipher_util utility on the gateway.
Otherwise, I suspect it's an RFE.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 20 May 2025 @ 11:30 AM (PDT)

    Las Vegas: Check Point Hybrid Mesh

    Wed 21 May 2025 @ 11:30 AM (MST)

    Tempe, AZ: Check Point Hybrid Mesh

    Tue 03 Jun 2025 @ 06:00 PM (EDT)

    Montreal: CPX Recap

    Tue 10 Jun 2025 @ 06:00 PM (EDT)

    Quebec City: CPX Recap
    CheckMates Events