Archived from groups: comp.security.firewalls (More info?)
Hello,
I am using a CheckPoint Firewall NG FP3. External clients authenticate
via SecuRemote using certificates. I had to notice that the firewall
always sets the duration of validity for new certificates to 2 years.
Is it possible to make it generate certificates that are valid for a
longer time?
--
DeathAndPain
------------------------------------------------------------------------
Posted via http://www.webservertalk.com ------------------------------------------------------------------------
View this thread: http://www.webservertalk.com/message239384.html
Archived from groups: comp.security.firewalls (More info?)
Yes...however, with the amount of turnover experienced by many companies,
why would you want to? Especially for remote clients, all too often It is
the last to be notified of a termination and unless you keep tight control
on remote access ID's, there is often a an accumulation of invalid accounts.
"DeathAndPain" <DeathAndPain.1757tx@mail.webservertalk.com> wrote in message
news:689f304a5bc024cdbb5b38d5a983659c@news.thenewsgroups.com...
> Hello,
>
> I am using a CheckPoint Firewall NG FP3. External clients authenticate
> via SecuRemote using certificates. I had to notice that the firewall
> always sets the duration of validity for new certificates to 2 years.
> Is it possible to make it generate certificates that are valid for a
> longer time?
> --
> DeathAndPain
> ------------------------------------------------------------------------
> Posted via http://www.webservertalk.com > ------------------------------------------------------------------------
> View this thread: http://www.webservertalk.com/message239384.html >
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.688 / Virus Database: 449 - Release Date: 5/18/2004
You are about to answer a thread that has been inactive for more than 6 months. If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.