sk96591 - RSA Key Lengths in Check Point Products
RSA Key Lengths in Check Point Products
Solution
Table of Contents:
- Overview
- Internal CA (Root) Certificate
- SIC Certificate
- User Certificate, Client Certificate
- Gaia Portal Certificate
- HTTPS Portals (Multi-Portal) Certificate, VPN Certificate
- Endpoint Certificate
- RSA Key Lengths for SSH
Overview
This article outlines the lengths of RSA keys used in various Check Point products and instructs how to modify the default key length.
Notes:
- The default key length of RSA keys generated by Check Point Internal CA is 2048-bit. You can see this information in the ICA portal in the section "Configure the CA".
- On a Multi-Domain Security Management Server:
- This configuration applies only in the Domain Management Server context, in which you configure these settings.
- You can configure these settings also in the "MDS" context (and they do not apply to the existing or new Domain Management Servers).
Internal CA (Root) Certificate
Impact on the Environment and Warnings:
This procedure deletes and creates again the Internal CA on the Management Server.
This procedure deletes all certificates from the Management Server.
You must generate and distribute all the certificates again.
You must establish SIC again with all managed Security Gateways / Cluster Members.
Therefore:
- Consult Check Point Support before recreating the CA.
- Test this in a controlled lab first.
- Make sure you have a good backup (including a Gaia Snapshot) for the Management Server.
- Perform this procedure during a downtime.
Supported RSA key lengths:
Key Length Availability 1024 bits Included starting from the version R60 2048 bits Included starting from the version R75 3072 bits Included starting from (PMTR-86409):
- Check Point R81.20
- Jumbo Hotfix Accumulator for R81.10 starting from Take 82
- Jumbo Hotfix Accumulator for R81 starting from Take 77
- Jumbo Hotfix Accumulator for R80.40 starting from Take 1904096 bits Included starting from the version R75
Procedure to change the RSA key length for ICA certificate on the Management Server:
Collect a full backup of the Management Server:
Collect the backup of the management database (with the "
migrate_server export" / "mds_backup" command).See the Command Line Interface (CLI) Reference Guide for your version.
Take a Gaia snapshot.
See the Gaia Administration Guide for your version.
Connect to the command line on the Management Server.
Log in to the Expert mode.
On a Multi-Domain Security Management Server, go to the context of the applicable Domain Management Server:
mdsenv <IP Address or Name of Domain Management Server>Back up the current $FWDIR/conf/InternalCA.C file:
cp -v $FWDIR/conf/InternalCA.C{,_ORIGINAL}Edit the current $FWDIR/conf/InternalCA.C file:
vi $FWDIR/conf/InternalCA.CBelow the line "
serial_num_of_digits", add these two lines: Note: Make sure to add a horizontal TAB before each line and a single space between the parameter name and its value in parentheses.:ica_key_size (<KEY_LENGTH>):sic_key_size (<KEY_LENGTH>)Example for 3072 bits:( :mgmt_tools_web_gui (1) :mgmt_tools_admin_list ( ) :mgmt_tools_user_list ( ) :crl_duration (604800) :authorization_code_length (6) :serial_num_of_digits (5) :ica_key_size (3072) :sic_key_size (3072) )Save the changes in the file and exit Vi editor.
Reset SIC as described in: sk14532 - "fwm sic_reset" command on Security Management fails with "There are IKE Certificates that were generated by the internal Certificate Authority
SIC Certificate
Supported RSA key lengths:
Key Length Availability 1024 bits Included starting from the version R60 2048 bits Included starting from the version R75 3072 bits Included starting from (PMTR-86409):
- Check Point R81.20
- Jumbo Hotfix Accumulator for R81.10 starting from Take 82
- Jumbo Hotfix Accumulator for R81 starting from Take 77
- Jumbo Hotfix Accumulator for R80.40 starting from Take 1904096 bits Included starting from the version R75
Procedure to change the RSA key length for SIC certificates on the Management Server:
Collect a full backup of the Management Server:
Collect the backup of the management database (with the "
migrate_server export" / "mds_backup" command).See the Command Line Interface (CLI) Reference Guide for your version.
Take a Gaia snapshot.
See the Gaia Administration Guide for your version.
Connect to the Internal CA Management Tool on Security Management Server / Domain Management Server.
For more information about the ICA Management Tool, see sk30501 - Setting up the ICA Management Tool.
Change the SIC key size:
- In the upper left menu, go to Configure the CA.
- Go to the Key Size Attributes section.
- In the SIC key size field, enter the desired value - 1024, 2048, 3072, or 4096.
- At the top of the page, click the Apply button.
Reset and stablish SIC again with all managed Security Gateways / Cluster Members as described in: sk65764 - How to reset SIC.
User Certificate, Client Certificate
Collect a full backup of the Management Server:
Collect the backup of the management database (with the "
migrate_server export" / "mds_backup" command).See the Command Line Interface (CLI) Reference Guide for your version.
Take a Gaia snapshot.
See the Gaia Administration Guide for your version.
Connect to the Internal CA Management Tool on Security Management Server / Domain Management Server.
For more information about the ICA Management Tool, see sk30501 - Setting up the ICA Management Tool.
Change the User / Client Certificate key size:
- In the upper left menu, go to Configure the CA.
- Go to the Key Size Attributes section.
- In the User Certificate key size field, enter the desired value - 1024, 2048, or 4096.
- At the top of the page, click the Apply button.
Generate the User / Client Certificate again.
Gaia Portal Certificate
- Take a Gaia snapshot on the Gaia Server. See the Gaia Administration Guide for your version.
- Connect to the command line on the Gaia server.
- Log in to the Expert mode.
- Stop the Apache HTTPD2 process:
tellpm process:httpd2- Back up the current /web/conf/server.key file:
cp -v /web/conf/server.key{,_ORIGINAL}- Back up the current /web/conf/server.crt file:
cp -v /web/conf/server.crt{,_ORIGINAL}- Remove the current /web/conf/server.key file:
rm -i /web/conf/server.key- Remove the current /web/conf/server.crt file:
rm -i /web/conf/server.crt- Generate the Certificate Signing Request with the required RSA key length - 1024, 2048, or 4096 bits. Example for 4096 bits:
cpopenssl req -new -x509 -sha256 -days 3652 -newkey rsa:4096 -nodes -keyout /web/conf/server.key -out /web/conf/server.crt -config $CPDIR/conf/openssl.cnf- Start the Apache HTTPD2 process:
tellpm process:httpd2 t
HTTPS Portals (Multi-Portal) Certificate, VPN Certificate
This section applies to:
- A certificate for various portals on the Security Gateway - Mobile Access Portal, Identity Awareness Portal, Data Loss Prevention Portal, UserCheck Portal.
- A VPN Certificate.
Supported RSA key lengths:
Key Length Availability 1024 bits Included starting from the version R60 2048 bits Included starting from the version R75 3072 bits Included starting from (PMTR-94089):
- Jumbo Hotfix Accumulator for R81.20 starting from Take 70
- Jumbo Hotfix Accumulator for R81.10 starting from Take 1524096 bits Included starting from the version R75 Procedure:
- Collect a full backup of the Management Server:
Collect the backup of the management database (with the "
migrate_server export" / "mds_backup" command).See the Command Line Interface (CLI) Reference Guide for your version.
Take a Gaia snapshot.
See the Gaia Administration Guide for your version.
- Connect with SmartConsole to the Security Management Server / Domain Management Server.
- In the top left corner, click Menu > Global properties.
- In the left panel, click the Advanced page.
- Click the Configure button.
- In the left panel, click the Certificates and PKI properties page.
- Find this option: host_certs_key_size.
- Click the drop-down and select the desired key size: 1024, 2048, 3072 or 4096.
- Click OK to close the Advanced Configuration window.
- Click OK to close the Global Properties window.
- Publish the session.
- Follow sk31539 to renew the default certificate.
- Generate the VPN Certificate again.
- Install the Access Control Policy on the Security Gateways / Clusters / VSX Virtual Systems.
Endpoint Certificate
Renewal of the Management Server SIC certificate will automatically renew the Endpoint certificate.
RSA Key Lengths for SSH
Summary:
Version RSA Key Length for SSH R82.10 3072 R82 2048 R81.20 2048 R81.10 2048 R81 2048 Procedure:
Connect to the command line on a Gaia OS server.
Log in.
If the default shell is Gaia Clish, go to the Expert mode:
expertRun this command and refer to the leftmost column:
ssh-keygen -lf /etc/ssh/ssh_host_rsa_keyTo see the length of all SSH keys, run:
for KEY in $(grep ssh_host /etc/ssh/sshd_config | awk '{print $2}') ; do ssh-keygen -lf ${KEY} ; done
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access LevelGeneral
StatusApproved by TAC
Date Created2013-11-28
Last Modified2025-11-16
Was this page helpful?YesNo