CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-04-07
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Creating new certificate for web console

Using the CHKP supplied vmware zip, I fired up an R60 version of SPLAT. The preconfigured IP etc weren't satisfactory, so I changed them. Now the certificate doesn't match and I want to change this.

I found a binary called new_p12_cert in the directory /opt/spwm/bin. However, I don't know where to generate a new p12 file. Is there a tool in SPLAT to do this? Or is there perhaps an SK explaining this that I couldn't find.

On IPSO this is easy, I just don't know how to do this for SPAT.
Reply With Quote
  #2 (permalink)  
Old 2006-12-04
swelck swelck is offline
Junior Member
 
Join Date: 2006-12-04
Posts: 1
Rep Power: 0
swelck has an average reputation (10+)
Default Re: Creating new certificate for web console

Anyone know how to do this?
Reply With Quote
  #3 (permalink)  
Old 2006-12-11
aenima aenima is offline
Member
 
Join Date: 2006-10-04
Location: Rennes, FRANCE
Posts: 32
Rep Power: 0
aenima has an average reputation (10+)
Default Re: Creating new certificate for web console

Hi all,

I have the same problem here. Help ???
Reply With Quote
  #4 (permalink)  
Old 2006-12-11
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 445
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Creating new certificate for web console

Quote:
Originally Posted by RobertGraham View Post
.....
I found a binary called new_p12_cert in the directory /opt/spwm/bin. However, I don't know where to generate a new p12 file. .........

/opt/spwm/servcert
Reply With Quote
  #5 (permalink)  
Old 2006-12-11
aenima aenima is offline
Member
 
Join Date: 2006-10-04
Location: Rennes, FRANCE
Posts: 32
Rep Power: 0
aenima has an average reputation (10+)
Default Re: Creating new certificate for web console

OK thanks for that.

But now how can i generate a new certificate based on the new ip address since when i connect to the new https address i m asked to accept a certificate based on the old ip address ?
Reply With Quote
  #6 (permalink)  
Old 2006-12-12
seadog seadog is offline
Junior Member
 
Join Date: 2006-12-12
Posts: 1
Rep Power: 0
seadog has an average reputation (10+)
Default Re: Creating new certificate for web console

I'm not sure if it's the correct method or not, but here's what seems to have worked for me:

- /etc/rc.d/init.d/CPwebis checks to see if /opt/spwm/servcert/servcert.p12 exists

- if it doesn't exist then it runs the following command to generate one:
/opt/spwm/bin/new_p12_cert /opt/spwm/servcert/servcert.p12 CN="$MYIPADDR"
... where $MYIPADDR is the IP of eth0.

- I suppose I could have run the above command by hand, but what I chose to do was rename "servcert.p12" to "servcert.p12.old" and then reboot. Once it had come back up it had regenerated "servcert.p12" and I could login to the WebUI without problem (excepting the warning about the certificate not being signed by a trusted CA).

I *think* this is what we're all trying to do.
Reply With Quote
  #7 (permalink)  
Old 2006-12-13
aenima aenima is offline
Member
 
Join Date: 2006-10-04
Location: Rennes, FRANCE
Posts: 32
Rep Power: 0
aenima has an average reputation (10+)
Default Re: Creating new certificate for web console

Yes you are right, that's what i am trying to do.
And your method is simple and perfect !

Thanks a lot !!!

Last edited by aenima; 2006-12-13 at 02:40.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:59.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0