Client Certificates for Smartphones and Tablets
To allow your users to access their resources using their handheld devices, make sure they can authenticate to the Security Gateway with client certificates.
In many organizations, the daily task of assigning and maintaining client certificates is done by a different department than the one that maintains the Security Gateways. The computer help desk, for example. You can create an administrator that is allowed to use SmartConsole to create client certificates, while restricting other permissions (see Giving Permissions for Client Certificates).
To configure client certificates, open SmartConsole and go to Security Policies > Access Control > Access Tools > Client Certificates.
To configure the Mobile Access policy, go to Manage & Settings > Blades > Mobile Access > Configure in SmartDashboard. The Client Certificates page in SmartConsole is a shortcut to the SmartDashboard
Mobile Access tab, Client Certificates page.
Managing Client Certificates
Check Point Mobile Apps for mobile devices can use certificate-only authentication or two-factor authentication with client certificates and username/password. The certificate is signed by the internal CA of the Security Management Server that manages the Mobile Access Security Gateway.
Manage client certificates in Security Policies > Access Control > Access Tools > Client Certificates..
The page has two panes.
-
In the Client Certificates pane:
-
Create, edit, and revoke client certificates.
-
See all certificates, their status, expiration date and enrollment key. By default, only the first 50 results show in the certificate list. Click Show more to see more results.
-
Search for specified certificates.
-
Send certificate information to users.
-
-
In the Email Templates for Certificate Distribution pane:
-
Create and edit email templates for client certificate distribution.
-
Preview email templates.
-
Creating Client Certificates
Note - If you use LDAP or AD, creation of client certificates does not change the LDAP or AD server. If you get an error message regarding LDAP/AD write access, ignore it and close the window to continue.
Revoking Certificates
If the status of a certificate is Pending Enrollment, after you revoke it, the certificate does not show in the Client Certificate list.
Creating Templates for Certificate Distribution
Cloning a Template
Clone an email template to create a template that is similar to one that already exists.
Giving Permissions for Client Certificates
You can create an administrator that is allowed to use SmartConsole to create client certificates, and restrict other permissions.