certego / fw1-loggrabber

FW1-Loggrabber is a command-line tool to grab logfiles from remote Checkpoint devices using OPSEC LEA (Log Export API)
GNU General Public License v2.0
52 stars 35 forks source link

Windows version 1.11 cannot use Auth with R77 #34

Closed kempy007 closed 7 years ago

kempy007 commented 7 years ago

I would suspect the older SDK that 1.11 was compiled with did not support Sha-256 signing of the certs. Why can it no longer be compiled on windows?

auth lea.conf that does not work

lea_server auth_type sslca lea_server ip 192.168.0.254 lea_server auth_port 18184 opsec_sic_name "CN=host1,O=some.local." opsec_sslca_file C:\bin\FW1-LogGrabber\opsec.p12 lea_server opsec_entity_sic_name "cn=cp_mgmt,o=some.local."

unauth lea.conf does work

lea_server ip 192.168.0.254 lea_server port 50001

I am changing the fwopsec.conf appropriately by commenting out relevant lines at end of file.

lea_server auth_port 18184

lea_server port 0

lea_server auth_type ssl_opsec

lea_server auth_type auth_opsec

lea_server auth_type ssl_ca

lea_server auth_port 0 lea_server port 50001

adepasquale commented 7 years ago

We are very sorry but our 2.0 branch has:

If you are using R77 and above you will need to build FW1-LogGrabber on a Linux machine.

Again, sorry about that.