sk96591 - RSA Key Lengths in Check Point Products

RSA Key Lengths in Check Point Products

Solution

Table of Contents:

Overview

This article outlines the lengths of RSA keys used in various Check Point products and instructs how to modify the default key length.

Notes:

Internal CA (Root) Certificate

Impact on the Environment and Warnings:

Therefore:

Supported RSA key lengths:

Key Length Availability
1024 bits Included starting from the version R60
2048 bits Included starting from the version R75
3072 bits Included starting from (PMTR-86409):
- Check Point R81.20
- Jumbo Hotfix Accumulator for R81.10 starting from Take 82
- Jumbo Hotfix Accumulator for R81 starting from Take 77
- Jumbo Hotfix Accumulator for R80.40 starting from Take 190
4096 bits Included starting from the version R75

Procedure to change the RSA key length for ICA certificate on the Management Server:

  1. Collect a full backup of the Management Server:

    1. Collect the backup of the management database (with the "migrate_server export" / "mds_backup" command).

      See the Command Line Interface (CLI) Reference Guide for your version.

    2. Take a Gaia snapshot.

      See the Gaia Administration Guide for your version.

  2. Connect to the command line on the Management Server.

  3. Log in to the Expert mode.

  4. On a Multi-Domain Security Management Server, go to the context of the applicable Domain Management Server: mdsenv <IP Address or Name of Domain Management Server>

  5. Back up the current $FWDIR/conf/InternalCA.C file: cp -v $FWDIR/conf/InternalCA.C{,_ORIGINAL}

  6. Edit the current $FWDIR/conf/InternalCA.C file: vi $FWDIR/conf/InternalCA.C

  7. Below the line "serial_num_of_digits", add these two lines: Note: Make sure to add a horizontal TAB before each line and a single space between the parameter name and its value in parentheses. :ica_key_size (<KEY_LENGTH>) :sic_key_size (<KEY_LENGTH>) Example for 3072 bits:

    (
            :mgmt_tools_web_gui (1)
            :mgmt_tools_admin_list (
            )
            :mgmt_tools_user_list (
            )
            :crl_duration (604800)
            :authorization_code_length (6)
            :serial_num_of_digits (5)
            :ica_key_size (3072)
            :sic_key_size (3072)
    )
    
  8. Save the changes in the file and exit Vi editor.

  9. Reset SIC as described in: sk14532 - "fwm sic_reset" command on Security Management fails with "There are IKE Certificates that were generated by the internal Certificate Authority

SIC Certificate

Supported RSA key lengths:

Key Length Availability
1024 bits Included starting from the version R60
2048 bits Included starting from the version R75
3072 bits Included starting from (PMTR-86409):
- Check Point R81.20
- Jumbo Hotfix Accumulator for R81.10 starting from Take 82
- Jumbo Hotfix Accumulator for R81 starting from Take 77
- Jumbo Hotfix Accumulator for R80.40 starting from Take 190
4096 bits Included starting from the version R75

Procedure to change the RSA key length for SIC certificates on the Management Server:

  1. Collect a full backup of the Management Server:

    1. Collect the backup of the management database (with the "migrate_server export" / "mds_backup" command).

      See the Command Line Interface (CLI) Reference Guide for your version.

    2. Take a Gaia snapshot.

      See the Gaia Administration Guide for your version.

  2. Connect to the Internal CA Management Tool on Security Management Server / Domain Management Server.

    For more information about the ICA Management Tool, see sk30501 - Setting up the ICA Management Tool.

  3. Change the SIC key size:

    1. In the upper left menu, go to Configure the CA.
    2. Go to the Key Size Attributes section.
    3. In the SIC key size field, enter the desired value - 1024, 2048, 3072, or 4096.
    4. At the top of the page, click the Apply button.
  4. Reset and stablish SIC again with all managed Security Gateways / Cluster Members as described in: sk65764 - How to reset SIC.

User Certificate, Client Certificate

  1. Collect a full backup of the Management Server:

    1. Collect the backup of the management database (with the "migrate_server export" / "mds_backup" command).

      See the Command Line Interface (CLI) Reference Guide for your version.

    2. Take a Gaia snapshot.

      See the Gaia Administration Guide for your version.

  2. Connect to the Internal CA Management Tool on Security Management Server / Domain Management Server.

    For more information about the ICA Management Tool, see sk30501 - Setting up the ICA Management Tool.

  3. Change the User / Client Certificate key size:

    1. In the upper left menu, go to Configure the CA.
    2. Go to the Key Size Attributes section.
    3. In the User Certificate key size field, enter the desired value - 1024, 2048, or 4096.
    4. At the top of the page, click the Apply button.
  4. Generate the User / Client Certificate again.

Gaia Portal Certificate

  1. Take a Gaia snapshot on the Gaia Server. See the Gaia Administration Guide for your version.
  2. Connect to the command line on the Gaia server.
  3. Log in to the Expert mode.
  4. Stop the Apache HTTPD2 process: tellpm process:httpd2
  5. Back up the current /web/conf/server.key file: cp -v /web/conf/server.key{,_ORIGINAL}
  6. Back up the current /web/conf/server.crt file: cp -v /web/conf/server.crt{,_ORIGINAL}
  7. Remove the current /web/conf/server.key file: rm -i /web/conf/server.key
  8. Remove the current /web/conf/server.crt file: rm -i /web/conf/server.crt
  9. Generate the Certificate Signing Request with the required RSA key length - 1024, 2048, or 4096 bits. Example for 4096 bits: cpopenssl req -new -x509 -sha256 -days 3652 -newkey rsa:4096 -nodes -keyout /web/conf/server.key -out /web/conf/server.crt -config $CPDIR/conf/openssl.cnf
  10. Start the Apache HTTPD2 process: tellpm process:httpd2 t

HTTPS Portals (Multi-Portal) Certificate, VPN Certificate

This section applies to:

Supported RSA key lengths:

Key Length Availability
1024 bits Included starting from the version R60
2048 bits Included starting from the version R75
3072 bits Included starting from (PMTR-94089):
- Jumbo Hotfix Accumulator for R81.20 starting from Take 70
- Jumbo Hotfix Accumulator for R81.10 starting from Take 152
4096 bits Included starting from the version R75

Procedure:

  1. Collect a full backup of the Management Server:
    1. Collect the backup of the management database (with the "migrate_server export" / "mds_backup" command).

      See the Command Line Interface (CLI) Reference Guide for your version.

    2. Take a Gaia snapshot.

      See the Gaia Administration Guide for your version.

  2. Connect with SmartConsole to the Security Management Server / Domain Management Server.
  3. In the top left corner, click Menu > Global properties.
  4. In the left panel, click the Advanced page.
  5. Click the Configure button.
  6. In the left panel, click the Certificates and PKI properties page.
  7. Find this option: host_certs_key_size.
  8. Click the drop-down and select the desired key size: 1024, 2048, 3072 or 4096.
  9. Click OK to close the Advanced Configuration window.
  10. Click OK to close the Global Properties window.
  11. Publish the session.
  12. Follow sk31539 to renew the default certificate.
  13. Generate the VPN Certificate again.
  14. Install the Access Control Policy on the Security Gateways / Clusters / VSX Virtual Systems.

Endpoint Certificate

Renewal of the Management Server SIC certificate will automatically renew the Endpoint certificate.

RSA Key Lengths for SSH

Summary:

Version RSA Key Length for SSH
R82.10 3072
R82 2048
R81.20 2048
R81.10 2048
R81 2048

Procedure:

  1. Connect to the command line on a Gaia OS server.

  2. Log in.

  3. If the default shell is Gaia Clish, go to the Expert mode:

    expert

  4. Run this command and refer to the leftmost column:

    ssh-keygen -lf /etc/ssh/ssh_host_rsa_key

    To see the length of all SSH keys, run:

    for KEY in $(grep ssh_host /etc/ssh/sshd_config | awk '{print $2}') ; do ssh-keygen -lf ${KEY} ; done

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access LevelGeneral

StatusApproved by TAC

Date Created2013-11-28

Last Modified2025-11-16

Was this page helpful?YesNo