List Info

Thread: Problem renewing SecuRemote certificate




Problem renewing SecuRemote certificate
user name
2007-09-03 12:28:29
OK - Quick "I'm stuck" question here... should be
hopefully an easy one, but
I'm completely stumped!

I've got a FW1/VPN1 NG running on Windows.  The SecuRemote
certificate just
expired, and I can't get it to renew itself.  Remote users
get a
"Certificate expired" error when they connect via
SecuRemote.

If I go into:
  SmartDashboard -> Manage -> VPN Communities...
->
  <click my VPN community name> -> Edit... ->
  Participating Gateways ->
  <click my gateway name> -> Edit... -> VPN

.. then on the right I have a "Certificate List"
that says:

Nickname: defaultCert
DN: CN=<gateway> VPN Certificate...
Certificate Authority: internal_ca

If I click the cert, and click Remove, it first says:

A new internal CA certificate will be created when clicking
OK on a VPN-1
object.
If you delete this certificate the CRL list will be
increased.
Are you sure you want to delete this certificate?

I say Yes, but then get an error:

This certificate is used in IKE authentication. Prior to
deleting this
certificate,
define an alternative certificate, or remote the 'public key
signature'
authentication method.

I try to define another new certificate, but am told:

Cannot generate certificate from 'internal_ca' Certificate
Authority because
<gateway> already has a certificate generated by
'internal_ca' Certificate
Authority.

What am I doing wrong?  How do I get this certificate to
just renew
itself????  Many thanks!

~~Richard~~

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERVamadeus.us.checkpoint.com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http:
//www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-ownerts.checkpoint.com
=================================================

Re: Problem renewing SecuRemote certificate
user name
2007-09-03 21:27:58
Ray -- Thanks so much.  It looks like this did the trick. 
(It was the VPN
cert on the firewall that was expired.)

~~Richard~~

On 9/3/07, Ray <sixsigma44hotmail.com> wrote:
>
> Which certificate is expired? The one that the
SecuRemote uses to
> authenticate themselves to the firewall or the actual
VPN certificate on
> the
> firewall?
>
> If it is an end user certificate, it cannot be renewed
once it's expired.
>
> If it's the one for the firewall, try un-checking VPN
on the firewall
> object, save the firewall object, open the firewall
object, re-check VPN,
> save the firewall object and push the policy.
>
> Ray
>

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERVamadeus.us.checkpoint.com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http:
//www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-ownerts.checkpoint.com
=================================================

[1-2]

about | contact  Other archives ( Real Estate discussion Medical topics )