| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hello, Currently our SecureClient users are authenticated with SmartDirectory (username/password). We would like to increase the security and use instead certificates. I do not want to use the ICA but use Windows Certificate Authority. We are running Checkpoint NGX R61 on Nokia box. Does anyone has a kind of document that explain how to achieve this? Or What settings do I need to change on my Checkpoint FW. Thanks in advance Slimo |
| |||
| Hello, I set up my firewall to authenticate SecureClient with certificates generated by external CA (MS CA). When I try to connect I got the error: "Could not validate the certificate used by gateway cp001 at site xxx.xxx.xxx.xxx. cannot complete certificate chain CN=...." Can you help please? Thanks Slimo |
| |||
| Thanks for the reply. I already did this because before the error was unknown user. So I am one step further now Apparently, I need to 1. generate a certificate request in the FW object VPN property sheet 2. send the request to MS CA 3. apply the reply on the FW Is that correct? Slimo |
| |||
| I don't know. I'm thinking of doing the same thing so I knew which articles I had seen that looked relevant. I was hoping you could tell me what you do to make it work. :-) Ray |
| |||
| I succeeded to be able to authenticate with certificates. Like I said early: I had to go to the FW object, VPN sheet, then add a certificate on the list. This will generate a certificate request. I took that request to my Microsoft Enterprise CA and I submitted the request. With the reply, I gone back to my FW and completed the certificate request. Voila that 's alll PS: be sure also to define the external CA in OPSec Slimo |
| |||
| Do you know a way to force the SecureClient users to use only certificates for authentication? I don't want them to use MS AD username and password Thanks Slimo |
![]() |
| Thread Tools | |
| Display Modes | |
| |