CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-22
Member
 
Join Date: 2007-06-06
Posts: 46
Rep Power: 0
GordonCopestake has an average reputation (10+)
Default Mystery certificate already exists with SIC communication?

I'm trying to connect a CP Gateway to my console (SmartDashboard) however when I initilize the SIC I get the error:

"A certificate with this name already exists, please specify a different name and try again."

However there are no other nodes with the same name. If I choose a different name for this new node it works fine, however as you can imagine all our nodes have very specific names and a rename would be a headache.

Is there a way to remove this mystery certificate to enable me to attach this new node?
Reply With Quote
  #2 (permalink)  
Old 2007-06-22
Member
 
Join Date: 2007-06-06
Posts: 46
Rep Power: 0
GordonCopestake has an average reputation (10+)
Default Re: Mystery certificate already exists with SIC communication?

Oh! I forgot to mention I am using R65 for both my logging server (Smartcenter server) and my gateways
Reply With Quote
  #3 (permalink)  
Old 2007-06-22
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Mystery certificate already exists with SIC communication?

If you want to revoke certificate issued by the ICA you should use - cpca_client revoke_cert [-p <ca_port>] -n "CN=<common name>".
I'm not sure that the command will work with SIC certificates.
Reply With Quote
  #4 (permalink)  
Old 2007-06-22
Member
 
Join Date: 2007-06-06
Posts: 46
Rep Power: 0
GordonCopestake has an average reputation (10+)
Default Re: Mystery certificate already exists with SIC communication?

I've managed to use the ICA web tool to take a look at the existing certificates. There are no existing VALID certifcates that I can see that would conflict. Unfortunatly I can't delete the revoked certificates because they havn't expired.

Does anyone know where the certificates are physically held on the system? Is it as easy as simply removing the .cer file for the revoked certs?
Reply With Quote
  #5 (permalink)  
Old 2007-06-22
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Mystery certificate already exists with SIC communication?

"CN=<common name>" in my example is object name. I would type the command with "bad" node name.

I found two usefull SK, 1'st - manual editing objects_5_0.C , 2'nd - cpca_client revoke_cert.
How to correct the error: "cannot create certificate for this object. Certificate already exists."
How to resolve the error: "cannot create certificate, object with this certificate name already exists"
Reply With Quote
  #6 (permalink)  
Old 2007-06-22
Member
 
Join Date: 2007-06-06
Posts: 46
Rep Power: 0
GordonCopestake has an average reputation (10+)
Default Re: Mystery certificate already exists with SIC communication?

Thanks for the hints kva.kva. I thought for just a moment you might have hit the nail on the head. But unfortunatly neither of those SK's seem to have a solution that works (although the problem is identical).

I followed both through but neither worked :(
Reply With Quote
  #7 (permalink)  
Old 2007-06-22
Junior Member
 
Join Date: 2006-06-22
Posts: 21
Rep Power: 0
masterloo has an average reputation (10+)
Default Re: Mystery certificate already exists with SIC communication?

not sure it would be feasible, but have you thought of doing a database revision then removing the FW object, saving then re-adding? GL!

Masterloo
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:51.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0