# RSA Key Lengths in Check Point Products

## Solution

**Table of Contents:**

- Overview
- Internal CA (Root) Certificate
- SIC Certificate
- User Certificate, Client Certificate
- Gaia Portal Certificate
- HTTPS Portals (Multi-Portal) Certificate, VPN Certificate
- Endpoint Certificate
- RSA Key Lengths for SSH

## Overview

> This article outlines the lengths of RSA keys used in various Check Point products and instructs how to modify the default key length.
>
> **Notes:**
>
> - The default key length of RSA keys generated by Check Point Internal CA is 2048-bit. You can see this information in the ICA portal in the section "Configure the CA".
> - On a Multi-Domain Security Management Server:
>   - This configuration applies only in the Domain Management Server context, in which you configure these settings.
>   - You can configure these settings also in the "MDS" context (and they do not apply to the existing or new Domain Management Servers).

## Internal CA (Root) Certificate

> Impact on the Environment and Warnings:
>
> - This procedure deletes and creates again the Internal CA on the Management Server.
> - This procedure deletes all certificates from the Management Server.
>
>   You must generate and distribute all the certificates again.
>
>   You must establish SIC again with all managed Security Gateways / Cluster Members.
>
> Therefore:
>
> - Consult Check Point Support before recreating the CA.
> - Test this in a controlled lab first.
> - Make sure you have a good backup (including a Gaia Snapshot) for the Management Server.
> - Perform this procedure during a downtime.
>
> Supported RSA key lengths:
>
> |     |     |
> | --- | --- |
> | Key Length | Availability |
> | 1024 bits | Included starting from the version R60 |
> | 2048 bits | Included starting from the version R75 |
> | 3072 bits | Included starting from (PMTR-86409):<br>- [Check Point R81.20](https://support.checkpoint.com/results/sk/sk173903)<br>- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 82<br>- [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 77<br>- [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 190 |
> | 4096 bits | Included starting from the version R75 |

> Procedure to change the RSA key length for ICA certificate on the Management Server:
>
> 1. Collect a full backup of the Management Server:
>    1. Collect the backup of the management database (with the "`migrate_server export`" / "`mds_backup`" command).
>
>       See the [Command Line Interface (CLI) Reference Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
>
>    2. Take a Gaia snapshot.
>
>       See the [Gaia Administration Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
> 2. Connect to the command line on the Management Server.
> 3. Log in to the Expert mode.
> 4. On a Multi-Domain Security Management Server, go to the context of the applicable Domain Management Server:
>    **`mdsenv <IP Address or Name of Domain Management Server>`**
> 5. Back up the current _$FWDIR/conf/InternalCA.C_ file:
>    **`cp -v $FWDIR/conf/InternalCA.C{,_ORIGINAL}`**
> 6. Edit the current _$FWDIR/conf/InternalCA.C_ file:
>    **`vi $FWDIR/conf/InternalCA.C`**
> 7. Below the line "`serial_num_of_digits`", add these two lines:
>    **Note**: Make sure to add a horizontal TAB before each line and a single space between the parameter name and its value in parentheses.
>    **`:ica_key_size (<KEY_LENGTH>)`**
>    **`:sic_key_size (<KEY_LENGTH>)`**
>    Example for 3072 bits:
>
>    ```
>    (
>            :mgmt_tools_web_gui (1)
>            :mgmt_tools_admin_list (
>            )
>            :mgmt_tools_user_list (
>            )
>            :crl_duration (604800)
>            :authorization_code_length (6)
>            :serial_num_of_digits (5)
>            :ica_key_size (3072)
>            :sic_key_size (3072)
>    )
>    ```
> 8. Save the changes in the file and exit Vi editor.
> 9. Reset SIC as described in:
>    [sk14532 - "fwm sic_reset" command on Security Management fails with "There are IKE Certificates that were generated by the internal Certificate Authority](https://support.checkpoint.com/results/sk/sk14532)

## SIC Certificate

> Supported RSA key lengths:
>
> |     |     |
> | --- | --- |
> | Key Length | Availability |
> | 1024 bits | Included starting from the version R60 |
> | 2048 bits | Included starting from the version R75 |
> | 3072 bits | Included starting from (PMTR-86409):<br>- [Check Point R81.20](https://support.checkpoint.com/results/sk/sk173903)<br>- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 82<br>- [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 77<br>- [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 190 |
> | 4096 bits | Included starting from the version R75 |

> Procedure to change the RSA key length for SIC certificates on the Management Server:
>
> 1. Collect a full backup of the Management Server:
>    1. Collect the backup of the management database (with the "`migrate_server export`" / "`mds_backup`" command).
>
>       See the [Command Line Interface (CLI) Reference Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
>
>    2. Take a Gaia snapshot.
>
>       See the [Gaia Administration Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
> 2. Connect to the Internal CA Management Tool on Security Management Server / Domain Management Server.
>
>    For more information about the ICA Management Tool, see [sk30501 - Setting up the ICA Management Tool](https://support.checkpoint.com/results/sk/sk30501).
> 3. Change the SIC key size:
>    1. In the upper left menu, go to **Configure the CA**.
>    2. Go to the **Key Size Attributes** section.
>    3. In the **SIC key size** field, enter the desired value - **1024**, **2048**, **3072**, or **4096**.
>    4. At the top of the page, click the **Apply** button.
> 4. Reset and stablish SIC again with all managed Security Gateways / Cluster Members as described in:
>    [sk65764 - How to reset SIC](https://support.checkpoint.com/results/sk/sk65764).

## User Certificate, Client Certificate

> 1. Collect a full backup of the Management Server:
>    1. Collect the backup of the management database (with the "`migrate_server export`" / "`mds_backup`" command).
>
>       See the [Command Line Interface (CLI) Reference Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
>
>    2. Take a Gaia snapshot.
>
>       See the [Gaia Administration Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
> 2. Connect to the Internal CA Management Tool on Security Management Server / Domain Management Server.
>
>    For more information about the ICA Management Tool, see [sk30501 - Setting up the ICA Management Tool](https://support.checkpoint.com/results/sk/sk30501).
> 3. Change the User / Client Certificate key size:
>    1. In the upper left menu, go to **Configure the CA**.
>    2. Go to the **Key Size Attributes** section.
>    3. In the **User Certificate key size** field, enter the desired value - **1024**, **2048**, or **4096**.
>    4. At the top of the page, click the **Apply** button.
> 4. Generate the User / Client Certificate again.

## Gaia Portal Certificate

> 01. Take a Gaia snapshot on the Gaia Server.
>     See the [Gaia Administration Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
> 02. Connect to the command line on the Gaia server.
> 03. Log in to the Expert mode.
> 04. Stop the Apache HTTPD2 process:
>     `tellpm process:httpd2`
> 05. Back up the current _/web/conf/server.key_ file:
>     `cp -v /web/conf/server.key{,_ORIGINAL}`
> 06. Back up the current _/web/conf/server.crt_ file:
>     **`cp -v /web/conf/server.crt{,_ORIGINAL}`**
> 07. Remove the current _/web/conf/server.key_ file:
>     `rm -i /web/conf/server.key`
> 08. Remove the current _/web/conf/server.crt_ file:
>     `rm -i /web/conf/server.crt`
> 09. Generate the Certificate Signing Request with the required RSA key length - **1024**, **2048**, or **4096** bits.
>     Example for 4096 bits:
>     **`cpopenssl req -new -x509 -sha256 -days 3652 -newkey rsa:4096 -nodes -keyout /web/conf/server.key -out /web/conf/server.crt -config $CPDIR/conf/openssl.cnf`**
> 10. Start the Apache HTTPD2 process:
>     **`tellpm process:httpd2 t`**

## HTTPS Portals (Multi-Portal) Certificate, VPN Certificate

> This section applies to:
>
> - A certificate for various portals on the Security Gateway - Mobile Access Portal, Identity Awareness Portal, Data Loss Prevention Portal, UserCheck Portal.
> - A VPN Certificate.
>
> Supported RSA key lengths:
>
> |     |     |
> | --- | --- |
> | Key Length | Availability |
> | 1024 bits | Included starting from the version R60 |
> | 2048 bits | Included starting from the version R75 |
> | 3072 bits | Included starting from (PMTR-94089):<br>- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 70<br>- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 152 |
> | 4096 bits | Included starting from the version R75 |
>
> Procedure:
>
> 01. Collect a full backup of the Management Server:
>     1. Collect the backup of the management database (with the "`migrate_server export`" / "`mds_backup`" command).
>
>        See the [Command Line Interface (CLI) Reference Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
>
>     2. Take a Gaia snapshot.
>
>        See the [Gaia Administration Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
> 02. Connect with SmartConsole to the Security Management Server / Domain Management Server.
> 03. In the top left corner, click **Menu** \> **Global properties**.
> 04. In the left panel, click the **Advanced** page.
> 05. Click the **Configure** button.
> 06. In the left panel, click the **Certificates and PKI properties** page.
> 07. Find this option: **host_certs_key_size**.
> 08. Click the drop-down and select the desired key size: **1024**, **2048**, **3072** or **4096**.
> 09. Click **OK** to close the **Advanced Configuration** window.
> 10. Click **OK** to close the **Global Properties** window.
> 11. Publish the session.
> 12. Follow [sk31539](https://support.checkpoint.com/results/sk/sk31539) to renew the default certificate.
> 13. Generate the VPN Certificate again.
> 14. Install the Access Control Policy on the Security Gateways / Clusters / VSX Virtual Systems.

## Endpoint Certificate

> Renewal of the Management Server SIC certificate will automatically renew the Endpoint certificate.

## RSA Key Lengths for SSH

> Summary:
>
> |     |     |
> | --- | --- |
> | Version | RSA Key Length for SSH |
> | R82.10 | 3072 |
> | R82 | 2048 |
> | R81.20 | 2048 |
> | R81.10 | 2048 |
> | R81 | 2048 |
>
> Procedure:
>
> 1. Connect to the command line on a Gaia OS server.
> 2. Log in.
> 3. If the default shell is Gaia Clish, go to the Expert mode:
>
>    `expert`
> 4. Run this command and refer to the leftmost column:
>
>    `ssh-keygen -lf /etc/ssh/ssh_host_rsa_key`
>
>    To see the length of all SSH keys, run:
>
>    `for KEY in $(grep ssh_host /etc/ssh/sshd_config | awk '{print $2}') ; do ssh-keygen -lf ${KEY} ; done`

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

Access LevelGeneral

StatusApproved by TAC

Date Created2013-11-28

Last Modified2025-11-16

Was this page helpful?YesNo
