How to deal with CheckPoint Certificate if it is Expired

CheckPoint devices in the above, the default installation SecurePlatform OS, it will have a 5-year effective RootCA.
So next step is to talk about is how this deal expired CA!
Cause problems:
SmartDashboard Can not log SmartDashboard
Resolution:
Step 1. Adjust the system time to expire before (not a complete solution solution)
Step 2. Reload (it will be killed)
Step 3. Reset RootCA Reset this RootCA
Next to that is the third of the solution:
1: Before you begin, I briefly describe what the test environment operation
Site To Site VPN → The environment has been pre-set Site To Site VPN
Site to Site VPN – Therefore, we should first remove the Site to Site VPN settings on the device!
 2. Traditional mode configuration Public key sign Cancel Traditional mode configuration in the Public key sign
 3. Remove Root CA CA Remove pre-built Root CA (the so-called date CA)

Step2: Next Console or SSH to log into the system, the implementation of fwm sic_reset




Step3: ok, then we need to generate a certificate authority, perform cpconfig, select 7







Step4: fwm sic_reset done before because when the service is disabled, so the implementation of cpstart, cpridstart restart the service



Step5: After re-login SmartDashBoard there is such a message, this is normal

 Step6: After re-login, we need to produce CA to the VPN, and therefore the press Add

Step7: given name, by Generate will generate a certificate

Step8: Do not forget to come back just to cancel the setting, including a VPN set Oh!

Comments

0 Responses to "How to deal with CheckPoint Certificate if it is Expired"

Post a Comment

Search This Blog

Blog Archive

Total Pageviews