CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-21
Junior Member
 
Join Date: 2007-05-21
Posts: 1
Rep Power: 0
lostoath has an average reputation (10+)
Default ICA Cert expired? (screenshot inside)

Can't login with SPLAT.



I've checked clocks on GUI and CLI and they match. Any ideas?
If it's the ICA - how do I renew it through CLI?
Reply With Quote
  #2 (permalink)  
Old 2007-05-22
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 913
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: ICA Cert expired? (screenshot inside)

cpstop & cpstart on the SmartCenter should do the trick. It should auto-renew at 75% of its life, which is five years by default (whatever 75% of 5 is).

You'll get a message that the fingerprint changed, so you should check it against the one displayed by cpconfig on the SmartCenter.

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-05-27
Junior Member
 
Join Date: 2006-12-04
Posts: 6
Rep Power: 0
adam12345 has an average reputation (10+)
Default Re: ICA Cert expired? (screenshot inside)

ok fixed to problem had to manually remove the certificate from the object_5_.C file and do a FWM_reset_sic and reestabilsh the sic via cpconfig, luckily it's a stand alone installtion :P
Reply With Quote
  #4 (permalink)  
Old 2007-07-18
Junior Member
 
Join Date: 2005-09-29
Posts: 7
Rep Power: 0
sclausson has an average reputation (10+)
Default Re: ICA Cert expired? (screenshot inside)

I believe I am having a related issue, and want to be sure that my recently changed fingerprint is due to auto-renew, and not foul play.

RayPesek, where did you find information that the "the ICA cert is set to auto-renew at 75% of its life, which is five years by default." ??

Thanks,
Shayne
Reply With Quote
  #5 (permalink)  
Old 2007-07-18
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 913
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: ICA Cert expired? (screenshot inside)

Some SK article, I don't recall which. It also happened to me 4+ years after the initial installation of the SmartCenter. How long ago was your initial installation?

If you run cpconfig on the SmartCenter, it will show you the current fingerprint, which you can match up.

Ray
Reply With Quote
  #6 (permalink)  
Old 2007-08-01
Junior Member
 
Join Date: 2007-07-03
Posts: 18
Rep Power: 0
Jay_D has an average reputation (10+)
Default Re: ICA Cert expired? (screenshot inside)

There is a KB article about enable the ICA management page. There you can see the age of your certificates.

This command enables the ICA management tool:
cpca_client set_mgmt_tool on -no_ssl

now you can browse to http://yourfirewall:18265 and check the certificates

Don't forget to type this afterwards:
cpca_client set_mgmt_tool off

HTH
JD.
Reply With Quote
  #7 (permalink)  
Old 2007-08-02
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 913
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: ICA Cert expired? (screenshot inside)

It would be better to not use -nossl. As I recall, there is more to the setup. You have to generate an administrator certificate for yourself and specify it on the command line so that cert is authorized and used for login and you have to import it into your computer's certificate store.

Ray
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 10:25.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0