CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-09-04
Junior Member
 
Join Date: 2006-04-03
Posts: 15
Rep Power: 0
kai11 has an average reputation (10+)
Default Fingerprint on SmartCenter changed

last morning our SmartCenter Server was not accessible bye the the GUI-Client. ( Services not up .. ). I did a cpstop / cpstart on the Managment-Server. After that the GUI-Client could reach the server with the following message:
Warning: The Fingerprint on SmartCenter Server changed, the new Fingerprint is "....." , compare the new Fingerprint to the one displayed in the configuration tool on the SmartCenter server.

I compared the Fingerprints, they are the same.
But what has caused the message on the Clients?

thanks for your responses.
Reply With Quote
  #2 (permalink)  
Old 2007-01-15
Member
 
Join Date: 2006-03-14
Posts: 96
Rep Power: 3
avilT has an average reputation (10+)
Default Re: Fingerprint on SmartCenter changed

Even I faced the same problem today. Can anybody explain the reason for this? Has it got anythng to do with system date? Is there any expiration date for the Managenet server certificate?
Thank You

Last edited by avilT; 2007-01-16 at 00:29.
Reply With Quote
  #3 (permalink)  
Old 2007-01-16
Senior Member
 
Join Date: 2006-01-25
Posts: 895
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Fingerprint on SmartCenter changed

AFAIK the certificate does not expire. I've never had to do a cpstop / cpstart on my management server so I've never experienced your problem.

The only time I've seen prompts to accept a fingerprint has been when I've reinstalled / upgraded the dashboard on the client.
__________________
Its all in the documentation.
Reply With Quote
  #4 (permalink)  
Old 2007-07-18
Junior Member
 
Join Date: 2005-09-29
Posts: 7
Rep Power: 0
sclausson has an average reputation (10+)
Default Re: Fingerprint on SmartCenter changed

I am having the same issue today. I am the only administrator of the SmartCenter Server, and i know I did not change anything. Did you ever find an answer as to why your fingerprint changed?
Reply With Quote
  #5 (permalink)  
Old 2007-07-18
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Fingerprint on SmartCenter changed

The SmartCenter cert has a lifetime of five years. When you reboot it or run a cpstop/cpstart and it is within 20% of 25% of the end of its life, it will auto-renew and you'll see what you're seeing.

Ray
Reply With Quote
  #6 (permalink)  
Old 2007-11-08
Junior Member
 
Join Date: 2006-08-02
Posts: 11
Rep Power: 0
kaldek has an average reputation (10+)
Default Re: Fingerprint on SmartCenter changed

I just witnessed a problem where the certificate expired on a combined management/gateway bundle for NG FP3 (Windows), where it was also used for SecureClient VPN.

Before the certificate was able to be renewed, we had to remove Public/Private Key authentication from the traditional mode IKE settings tickbox, at which point a new certificate was able to be generated.
Reply With Quote
  #7 (permalink)  
Old 2007-11-12
Junior Member
 
Join Date: 2007-07-03
Posts: 16
Rep Power: 0
Jay_D has an average reputation (10+)
Default Re: Fingerprint on SmartCenter changed

This is something all NG customers will encounter when their firewall is 5 years old.
There are 3 internal certificates that will get renewed. We have some sites where we have to reboot the firewall and others where it isn't necessary and even others with a bigger problem (I'll post my issue in another thread).

If your SecureClient users get a message about a cert expired, then it's the VPN Certificate which you can renew in the GUI starting from R60 (button Renew). This button is not available in R55. There you have to delete the cert and create a new one. Of course deleting will not work when VPN is already configured so you first have to uncheck all that.

If you get a fingerprint change when connecting to the SmartCenter, then it's because the management cert has changed. Sometimes this requires rebooting.

I hope this info helps.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:34.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0