<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS inspection TLS warning in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214445#M40933</link>
    <description>&lt;P&gt;I have R81.20 jumbo 54 in the lab, all works well. Did you check file I uploaded?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 15 May 2024 22:01:56 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-05-15T22:01:56Z</dc:date>
    <item>
      <title>HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214289#M40903</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I have enabled HTTPS and exported the certificate to a test machine. When visiting various websites it works as expected.&lt;/P&gt;
&lt;P&gt;But a websites like checkpoint.com or cisco.com would show a warning&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tls-warning-checkpoint.JPG" style="width: 694px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25683i1A149A386A781DFD/image-size/large?v=v2&amp;amp;px=999" role="button" title="tls-warning-checkpoint.JPG" alt="tls-warning-checkpoint.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;it works fine with google for example!&lt;/P&gt;
&lt;P&gt;so I wonder why will some work and some not?&lt;/P&gt;
&lt;P&gt;the log looks like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tls-warning-checkpoint1.JPG" style="width: 385px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25685i4E07F254C26BEAAD/image-size/large?v=v2&amp;amp;px=999" role="button" title="tls-warning-checkpoint1.JPG" alt="tls-warning-checkpoint1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I suspect that we need to buy a well trusted certificate to make that work?!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 08:35:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214289#M40903</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-15T08:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214340#M40906</link>
      <description>&lt;P&gt;Code level?&lt;/P&gt;
&lt;P&gt;Make sure your list of trusted CAs for HTTPS Inspection is up to date, the ability to update these is still located in the SmartDashboard accessible from Manage &amp;amp; Settings...Blades...HTTPS Inspection...Configure in SmartDashboard...HTTPS Inspection...Trusted CAs.&amp;nbsp; Later code levels keep this CA list up to date automatically.&lt;/P&gt;
&lt;P&gt;Could also be this:&amp;nbsp;&lt;A href="https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning" target="_blank" rel="noopener"&gt;https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 12:49:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214340#M40906</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-05-15T12:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214344#M40907</link>
      <description>&lt;P&gt;No, you dont need to buy trusted CA for this to work, I have https inspectin lab and I use one generated from the mgmt server and works fine. Is it just one website or multiple? Make sure below is checked in legacy smart console.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25691i6AD9A7C0FCFB12F7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 12:53:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214344#M40907</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-15T12:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214356#M40911</link>
      <description>&lt;P&gt;version 81.20&lt;/P&gt;
&lt;P&gt;Now I have installed the latest updates and done this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="enable-automatic-ca-updates.JPG" style="width: 905px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25693i5A124583DD35F889/image-size/large?v=v2&amp;amp;px=999" role="button" title="enable-automatic-ca-updates.JPG" alt="enable-automatic-ca-updates.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;but still getting the same tls warning!&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tls-logs.JPG" style="width: 810px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25694iBD87AEB9FF1190C0/image-size/large?v=v2&amp;amp;px=999" role="button" title="tls-logs.JPG" alt="tls-logs.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 13:14:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214356#M40911</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-15T13:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214357#M40912</link>
      <description>&lt;P&gt;You see this on EVERY site or just some?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 13:17:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214357#M40912</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-15T13:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214360#M40914</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ca-download.JPG" style="width: 488px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25695iA905EB606DC7E903/image-size/large?v=v2&amp;amp;px=999" role="button" title="ca-download.JPG" alt="ca-download.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;it is not working for example:&lt;/P&gt;
&lt;P&gt;microsoft.com&lt;/P&gt;
&lt;P&gt;cisco.com&lt;/P&gt;
&lt;P&gt;as what i could notice!&lt;/P&gt;
&lt;P&gt;I am getting this error:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;NET::ERR_CERT_AUTHORITY_INVALID&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 13:28:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214360#M40914</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-15T13:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214373#M40915</link>
      <description>&lt;P&gt;You see that on every browser?&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 14:37:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214373#M40915</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-15T14:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214376#M40916</link>
      <description>&lt;P&gt;Google chrome and Edge&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 14:40:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214376#M40916</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-15T14:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214378#M40917</link>
      <description>&lt;P&gt;Can you send screenshot of https inspection policy?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 14:41:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214378#M40917</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-15T14:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214421#M40925</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="https-policy.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25710iA1F384FE67D17B62/image-size/large?v=v2&amp;amp;px=999" role="button" title="https-policy.JPG" alt="https-policy.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 18:52:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214421#M40925</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-15T18:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214422#M40926</link>
      <description>&lt;P&gt;Did it ever work or its brand new issue?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 18:56:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214422#M40926</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-15T18:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214424#M40927</link>
      <description>&lt;P&gt;this is the first time I am testing HTTPS inspection, maybe I need to add some certificate under Trusted CAs, but which one, I have tested many but stil have same problem&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 19:11:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214424#M40927</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-15T19:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214425#M40928</link>
      <description>&lt;P&gt;You dont, they are all auto updated. I attached doc with how I have it configured, so maybe you can see if something is "missing". I will also make separate post about it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 19:28:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214425#M40928</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-15T19:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214442#M40930</link>
      <description>&lt;P&gt;If your setup is bugged like mine (R81.10 JHF 141), the automatic install does not work, and you have to manually add the certificates from the list. Just click on all of them or the ones you need, then publish install.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-05-15 15_54_50-Window.png" style="width: 1018px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25714iE97E3E0EE4B3C4F9/image-dimensions/1018x217?v=v2" width="1018" height="217" role="button" title="2024-05-15 15_54_50-Window.png" alt="2024-05-15 15_54_50-Window.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 20:57:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214442#M40930</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-05-15T20:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214443#M40931</link>
      <description>&lt;P&gt;I am running this version:&lt;/P&gt;
&lt;P&gt;Product version Check Point Gaia R81.20&lt;BR /&gt;OS build 631&lt;/P&gt;
&lt;P&gt;So I don't know if it is bugged or not!&lt;/P&gt;
&lt;P&gt;Did you have a similar problem where many websites work but some don't?&lt;/P&gt;
&lt;P&gt;Which certificates did you add?'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 21:54:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214443#M40931</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-15T21:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214445#M40933</link>
      <description>&lt;P&gt;I have R81.20 jumbo 54 in the lab, all works well. Did you check file I uploaded?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 22:01:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214445#M40933</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-15T22:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214448#M40935</link>
      <description>&lt;P&gt;If you click the "add" button and stuff is in the list, it is bugged, as the list should be empty. Yes, I was having the same exact issue you were having. I also noticed it because of Check Point and Cisco websites. Honestly, you should add all of them in the list, but if you only want to add a few I had to do the following: go to the website on a computer not being HTTPS inspected, view the certificate, that will supply you with who the Root CA is for the site, and then add that.&lt;/P&gt;&lt;P&gt;If you open a TAC case, they can supply you with a script that will add all of them in the list if you don't want to manually do it.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 23:23:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214448#M40935</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-05-15T23:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214450#M40936</link>
      <description>&lt;P&gt;I think they all get updated automatically, specially in R81.20&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 23:39:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214450#M40936</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-15T23:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214453#M40937</link>
      <description>&lt;P&gt;Bro, message me tomorrow, you got my gmail, lets do remote. IM available any time up until 4 pm GMT or between 5-8 GMT. Im in EST, which is GMT-4&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 00:22:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214453#M40937</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-16T00:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection TLS warning</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214481#M40941</link>
      <description>&lt;P&gt;I am not allowed to do remote because this the production environment.&lt;/P&gt;
&lt;P&gt;But now I have succeeded adding "Digicert Global Root G2" manually which resulted to connect correctly to microsoft.com&lt;/P&gt;
&lt;P&gt;I have used the way &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75772"&gt;@CaseyB&lt;/a&gt; decribed above!&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 09:11:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-TLS-warning/m-p/214481#M40941</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-05-16T09:11:43Z</dc:date>
    </item>
  </channel>
</rss>

