<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about sk173629 to install Trusted CAs list automatically in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk173629-to-install-Trusted-CAs-list/m-p/245900#M47915</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/92523"&gt;@Cypress&lt;/a&gt;&amp;nbsp;I would still double check with TAC to confirm, but thats what I know &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 07 Apr 2025 20:01:41 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-04-07T20:01:41Z</dc:date>
    <item>
      <title>Question about sk173629 to install Trusted CAs list automatically</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk173629-to-install-Trusted-CAs-list/m-p/245892#M47913</link>
      <description>&lt;P&gt;I have a question regarding the Trusted CAs List on a Security Gateway running HTTPS inspection.&lt;/P&gt;&lt;P&gt;I have encountered, in some rare cases, where a legitimate website with a legitimate CA-issued certificate will show as a Cert Error for our users.&amp;nbsp; When this happened, the logs in Logs &amp;amp; Monitoring would show "Untrusted Certificate."&amp;nbsp; Previously, I was fixing this by bypassing inspection for that domain.. but I have very recently come to realize the TRUE root cause is because the website's issuing CA is not present in our gateway's 'Trusted CAs' list.&amp;nbsp; Ah ha, a root cause finally found.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So.. anyway now on to my actual questions:&lt;/P&gt;&lt;P&gt;1. Is it the best practice from Check Point to toggle this setting in SmartDashboard Trusted CAs to "download and install updates automatically?"&amp;nbsp; I'm assuming this is the recommendation now, but thought I would ask.&lt;/P&gt;&lt;P&gt;2. I have read some OLDER posts on here that after installing an updated Trusted CAs list, you still have to install policy to the gateway.&amp;nbsp; Is that still true?&amp;nbsp; (In R81.20?)&amp;nbsp; sk173629 mentions installing policy to the gateways after making the settings change, but it doesn't mention installing policy upon subsequent updates?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 18:42:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk173629-to-install-Trusted-CAs-list/m-p/245892#M47913</guid>
      <dc:creator>Cypress</dc:creator>
      <dc:date>2025-04-07T18:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Question about sk173629 to install Trusted CAs list automatically</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk173629-to-install-Trusted-CAs-list/m-p/245896#M47914</link>
      <description>&lt;P&gt;My own experience and based on answers about this from TAC:&lt;/P&gt;
&lt;P&gt;1) Yes&lt;/P&gt;
&lt;P&gt;2) It depends, its 50-50, but TAC told me its best to install policy anyway&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 23:58:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk173629-to-install-Trusted-CAs-list/m-p/245896#M47914</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-07T23:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: Question about sk173629 to install Trusted CAs list automatically</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk173629-to-install-Trusted-CAs-list/m-p/245900#M47915</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/92523"&gt;@Cypress&lt;/a&gt;&amp;nbsp;I would still double check with TAC to confirm, but thats what I know &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 20:01:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk173629-to-install-Trusted-CAs-list/m-p/245900#M47915</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-07T20:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: Question about sk173629 to install Trusted CAs list automatically</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk173629-to-install-Trusted-CAs-list/m-p/245905#M47920</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/92523"&gt;@Cypress&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FWIW, I also have up to date R82 mgmt server in the lab that manages R81.20 cluster with ssl inspection on, so can get you updated zip file that can be uploaded for certificate list. But, just FYI, though it does work in R81.20 lab, its my "disclosure" that it may not work for you : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 00:22:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk173629-to-install-Trusted-CAs-list/m-p/245905#M47920</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-08T00:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Question about sk173629 to install Trusted CAs list automatically</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk173629-to-install-Trusted-CAs-list/m-p/245907#M47921</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/92523"&gt;@Cypress&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Was doing some Azure labs, so figured would double check on this. So, whatever you see for download in below sk, is literally same thing I see in my R82 lab:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk64521" target="_blank"&gt;sk64521 - How to update the Trusted Certificate Authorities (CAs) list for HTTPS Inspection and HTTPS Categorization&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There is no .zip file in R82 folder, where you would have found it in R81.20 and below, as mechanism is a bit different. I also attacxhed screenshots for reference. If you need more help, let me know.&lt;/P&gt;
&lt;P&gt;/opt/CPshrd-R82/database/downloads/CA_BUNDLE/1.0/1.1&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 02:10:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk173629-to-install-Trusted-CAs-list/m-p/245907#M47921</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-08T02:10:57Z</dc:date>
    </item>
  </channel>
</rss>

