<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: https inspection - NET::ERR_CERT_AUTHORITY_INVALID error in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181709#M33263</link>
    <description>&lt;P&gt;Tried this, same error.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 23 May 2023 06:29:12 GMT</pubDate>
    <dc:creator>aks_2512</dc:creator>
    <dc:date>2023-05-23T06:29:12Z</dc:date>
    <item>
      <title>https inspection - NET::ERR_CERT_AUTHORITY_INVALID error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181643#M33247</link>
      <description>&lt;P&gt;hi, we setup a vm and created an https inspection policy rule to allow access to "Internet" on port https/443 and set the action to inspect and to use the outbound_certificate. Before the rule was set, the vm was able to access internet sites ok. After the https inspection rule was enabled and policy installed, access to any internet website pops up with&amp;nbsp;&lt;SPAN&gt;NET::ERR_CERT_AUTHORITY_INVALID error.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;we use sub-CA on the gateway issued by our enterprise root CA. This sub-CA is present in the Trusted CA's of the gateway object.&amp;nbsp;&lt;/P&gt;&lt;P&gt;root CA cert is installed on the vm under trusted root ca. I have also exported the sub-CA cert from the https inspection tab of the gateway and imported it under root ca of the vm (tried it under intermediate ca and third party ca as well).&amp;nbsp;&lt;/P&gt;&lt;P&gt;checkpoint logs show http validation == untrusted certificate. reboot of the vm did not help either.&amp;nbsp;&lt;/P&gt;&lt;P&gt;using version r81.10&lt;/P&gt;&lt;P&gt;not sure what am i missing.. any suggestions please. Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 12:22:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181643#M33247</guid>
      <dc:creator>aks_2512</dc:creator>
      <dc:date>2023-05-22T12:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection - NET::ERR_CERT_AUTHORITY_INVALID error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181652#M33250</link>
      <description>&lt;P&gt;Maybe &lt;A href="https://support.checkpoint.com/results/sk/sk112722" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk112722&lt;/A&gt; ?&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 13:49:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181652#M33250</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-05-22T13:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection - NET::ERR_CERT_AUTHORITY_INVALID error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181675#M33256</link>
      <description>&lt;P&gt;If its under trusted root, that sounds right. Here is how customer I worked with on this issue last year fixed it, maybe you can confirm this. Also, make sure that automatic update is checked in https legacy dashboard (its under blades tab in smart console)&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21040iBF0DF4FA477BC0DE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 18:50:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181675#M33256</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-22T18:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection - NET::ERR_CERT_AUTHORITY_INVALID error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181709#M33263</link>
      <description>&lt;P&gt;Tried this, same error.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 06:29:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181709#M33263</guid>
      <dc:creator>aks_2512</dc:creator>
      <dc:date>2023-05-23T06:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection - NET::ERR_CERT_AUTHORITY_INVALID error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181710#M33264</link>
      <description>&lt;P&gt;automatic updates already checked in the legacy dashboard.&lt;/P&gt;&lt;P&gt;Viewing the cert from the url bar gives - Issued by - Common name = Untrusted.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 06:40:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181710#M33264</guid>
      <dc:creator>aks_2512</dc:creator>
      <dc:date>2023-05-23T06:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection - NET::ERR_CERT_AUTHORITY_INVALID error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181735#M33269</link>
      <description>&lt;P&gt;I have fully working https inspection lab, will check later.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 10:50:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181735#M33269</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-23T10:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection - NET::ERR_CERT_AUTHORITY_INVALID error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181771#M33270</link>
      <description>&lt;P&gt;I have fully working https inspection lab, will check later.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 13:44:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181771#M33270</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-23T13:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection - NET::ERR_CERT_AUTHORITY_INVALID error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181772#M33271</link>
      <description>&lt;P&gt;Btw, just checked and that error might not be cert issue necessarily. Do you get this for any given browser and on every machine or you just tested on one?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.hostinger.com/tutorials/err_cert_authority_invalid" target="_blank"&gt;https://www.hostinger.com/tutorials/err_cert_authority_invalid&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 13:45:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181772#M33271</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-23T13:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection - NET::ERR_CERT_AUTHORITY_INVALID error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181798#M33274</link>
      <description>&lt;P&gt;I would suggest to contact CP TAC to get this resolved !&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 15:16:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181798#M33274</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-05-23T15:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection - NET::ERR_CERT_AUTHORITY_INVALID error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181806#M33275</link>
      <description>&lt;P&gt;I agree with Guenther, please work with TAC to get this solved, might be much faster via remote session.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 16:41:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/181806#M33275</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-23T16:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: https inspection - NET::ERR_CERT_AUTHORITY_INVALID error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/182234#M33405</link>
      <description>&lt;P&gt;When using a sub-CA root cert, make sure the whole chain is included and can be validated through CLRs. If not, the actual certificate will be shown as untrusted.&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 09:21:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/https-inspection-NET-ERR-CERT-AUTHORITY-INVALID-error/m-p/182234#M33405</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-05-26T09:21:00Z</dc:date>
    </item>
  </channel>
</rss>

