CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-10
ocallaghanpaddy ocallaghanpaddy is offline
Junior Member
 
Join Date: 2007-10-01
Posts: 11
Rep Power: 0
ocallaghanpaddy has an average reputation (10+)
Default X509 Authentication and SecureClient

Hi all,

A client of mine is interested in making VPN connections as transparent as possible. Is it possible to use a certifiacte to authenticate the connection instead of user a username and password?

Any help would be brilliant.

Thanks,

Pat
Reply With Quote
  #2 (permalink)  
Old 2007-12-10
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: X509 Authentication and SecureClient

Easily, if you want to use the Check Point Internal Certificate Authority on the SmartCenter. Just remember that you may end up authenticating the computer and not the user. It's generally more secure as well, if you protect the certificate.

How exactly do you want this to work?

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-12-11
ocallaghanpaddy ocallaghanpaddy is offline
Junior Member
 
Join Date: 2007-10-01
Posts: 11
Rep Power: 0
ocallaghanpaddy has an average reputation (10+)
Default Re: X509 Authentication and SecureClient

Hi Ray,

Thanks for your help with this!

The client wants the VPN to initiate transparently when the user is off the local LAN. He does not want any user name or password prompt.

Is this difficult to implement using Secure remote?

thanks,

Pat
Reply With Quote
  #4 (permalink)  
Old 2007-12-11
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: X509 Authentication and SecureClient

I would certainly discourage that unless they have a rock-solid method of keeping unauthorized people out of the laptops, but it's their problem.

Create a user certificate and save it to a file. Log into the laptop, double-click on the certificate file, enter the PIN and let it import into the CAPI store. Set up SecureClient to use certificate authentication.

Ray
Reply With Quote
  #5 (permalink)  
Old 2007-12-12
ocallaghanpaddy ocallaghanpaddy is offline
Junior Member
 
Join Date: 2007-10-01
Posts: 11
Rep Power: 0
ocallaghanpaddy has an average reputation (10+)
Default Re: X509 Authentication and SecureClient

Thanks for your help Ray! Your a credit to the industry..
Reply With Quote
  #6 (permalink)  
Old 2007-12-12
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: X509 Authentication and SecureClient

Thanks, I hope it helped. If you have any problems, just post back.

Take care,

Ray
Reply With Quote
  #7 (permalink)  
Old 2007-12-20
tyoung tyoung is offline
Junior Member
 
Join Date: 2007-01-25
Posts: 2
Rep Power: 0
tyoung has an average reputation (10+)
Default Re: X509 Authentication and SecureClient

Quote:
Originally Posted by RayPesek View Post
Thanks, I hope it helped. If you have any problems, just post back.

Take care,

Ray
I'm looking to do this very thing, but after following your directions the client still requires a password in a "Password:" field just below the greyed out Certificate field, which shows the certificate file name.
Am I missing somthing?
Reply With Quote
  #8 (permalink)  
Old 2008-01-09
ocallaghanpaddy ocallaghanpaddy is offline
Junior Member
 
Join Date: 2007-10-01
Posts: 11
Rep Power: 0
ocallaghanpaddy has an average reputation (10+)
Default Re: X509 Authentication and SecureClient

I too am still having this issue. Is there any way for only certificate based authentication and for secure client to connect automatically and stay connected withing prompting the end user?
Reply With Quote
  #9 (permalink)  
Old 2008-01-09
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: X509 Authentication and SecureClient

Sorry for the delay in replying. When you imported the certificate into the CAPI store, did you check the boxes to NOT require a password to use it?

Ray
Reply With Quote
  #10 (permalink)  
Old 2008-01-10
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: X509 Authentication and SecureClient

Just to reiterate Ray's warning:
Using certificates without any password/PIN, means that anyone that steals a laptop or a certificate for that mater will be able to connect straight away into the LAN.

I understand that ease of use is important, but this is a VERY serious flaw in your security and you REALLY should consider something different.

Having a PIN on the certificate would make it very robust, as opposed to pretty weak, please consider that.

You can use a 4 digit PIN, like a phone PIN, or ideally something stronger, like a normal password. It shouldn't be that hard for a user to remember one such thing and enter it when requested.

Sorry for the rant...
Reply With Quote
  #11 (permalink)  
Old 2008-01-30
ocallaghanpaddy ocallaghanpaddy is offline
Junior Member
 
Join Date: 2007-10-01
Posts: 11
Rep Power: 0
ocallaghanpaddy has an average reputation (10+)
Default Re: X509 Authentication and SecureClient

Hi Guys,

Sorry for the delay in replying.

Everything worked fine. I explained the security issues to the client but in the end I had to follow their request.

Thanks a million for all your help!!!

Pat
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:37.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0