<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trusted CA list update issues in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261647#M61347</link>
    <description>&lt;P&gt;This is what I was referring to (attached)&lt;/P&gt;</description>
    <pubDate>Sun, 02 Nov 2025 21:34:00 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-11-02T21:34:00Z</dc:date>
    <item>
      <title>Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261641#M61345</link>
      <description>&lt;P&gt;My trusted CA lists is outdated.&lt;/P&gt;&lt;P&gt;I have Trusted CAs configured to "Download and install updates automatically"&lt;/P&gt;&lt;P&gt;Diagnose steps I took:&lt;/P&gt;&lt;P&gt;cat $CPDIR/database/downloads/TRUSTED_CA/2.0/Update_Status.dat&lt;/P&gt;&lt;P&gt;[Expert@fc-fw-mgmt:0]# cat Update_Status.dat&lt;BR /&gt;(&lt;BR /&gt;:Last_Update_Status (3)&lt;BR /&gt;:Last_Update_Time (1762070951)&lt;BR /&gt;:Last_Update_Reason ()&lt;BR /&gt;:Success_Time (1756302852)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;[Expert@fc-fw-mgmt:0]# date -d 1756302852d @&lt;BR /&gt;Wed Aug 27 16:54:12 IDT 2025&lt;/P&gt;&lt;P&gt;[Expert@fc-fw-mgmt:0]# date -d @176207095&lt;BR /&gt;Sun Nov 2 10:09:11 IST 2025&lt;/P&gt;&lt;P&gt;[Expert@fc-fw-mgmt:0]# ll&lt;BR /&gt;total 16&lt;BR /&gt;drwx------ 2 admin root 56 Aug 12 16:53 3.8&lt;BR /&gt;drwx------ 2 admin root 56 Aug 27 16:54 3.9&lt;BR /&gt;-rw-rw-r-- 1 admin config 113 Nov 2 10:09 Update_Status.dat&lt;BR /&gt;-rw-rw---- 1 admin root 66 Aug 27 16:54 last_revision.xml&lt;BR /&gt;-rw-rw---- 1 admin config 66 Aug 27 16:54 last_revision_old.xml&lt;BR /&gt;-rw-rw---- 1 admin root 10 Aug 27 16:54 tmp_revisions_order.txt&lt;/P&gt;&lt;P&gt;Looks like it had a successful update 2 months ago&lt;/P&gt;&lt;P&gt;I have looked into few articles and threads such as:&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk64521" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk64521&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk173629" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk173629&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk132812" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk132812&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk64521" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk64521&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Updating-trusted-CA-list-on-mgmt-server/m-p/150614" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Management/Updating-trusted-CA-list-on-mgmt-server/m-p/150614&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-root-CA-updates/td-p/5006" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-root-CA-updates/td-p/5006&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;None of those has information regarding updates logs or troubleshoot.&lt;/P&gt;&lt;P&gt;Ver: R81.20&lt;/P&gt;&lt;P&gt;R81_20_JUMBO_HF_MAIN Take: 113&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I know the list is not updated?&lt;BR /&gt;For example: msn.com chain is&amp;nbsp;&lt;SPAN&gt;DigiCert Global Root G2&amp;nbsp; &amp;gt;&amp;nbsp;Microsoft Azure RSA TLS Issuing CA 03 &amp;gt;&amp;nbsp;*.msn.com&lt;BR /&gt;DigiCert Global Root G2 is missing from the list.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ef341705-a178-44eb-be95-3da2005c030f.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31969i7E865BD177C96A1E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ef341705-a178-44eb-be95-3da2005c030f.png" alt="ef341705-a178-44eb-be95-3da2005c030f.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I also get HTTPS inspection errors like:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Certificate Chain is not signed by a Trusted CA. Refer to sk179944 for more details.&lt;BR /&gt;Certificate DN: 'CN=*.msn.com,O=Microsoft Corporation,L=Redmond,ST=WA,C=US' Requested Server Name: msn.com&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 20:50:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261641#M61345</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-11-02T20:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261644#M61346</link>
      <description>&lt;P&gt;I dont sadly have R81.20 to test, but I believe this is all auto updated in R82.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 21:25:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261644#M61346</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-02T21:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261647#M61347</link>
      <description>&lt;P&gt;This is what I was referring to (attached)&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 21:34:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261647#M61347</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-02T21:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261649#M61348</link>
      <description>&lt;P&gt;It's autoupdates in 81.20 as well&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-11-02 164404.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31971i5515CA90B482A21A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2025-11-02 164404.png" alt="Screenshot 2025-11-02 164404.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What I need is logs...&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 21:46:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261649#M61348</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-11-02T21:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261650#M61349</link>
      <description>&lt;P&gt;try this filter in the logs:&lt;/P&gt;
&lt;P&gt;blade:"HTTPS Inspection"&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 21:50:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261650#M61349</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-02T21:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261652#M61350</link>
      <description>&lt;P&gt;Nop, this shows only inspection traffic logs&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-11-02 170407.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31972i5F225F06931D9FD1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2025-11-02 170407.png" alt="Screenshot 2025-11-02 170407.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 22:04:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261652#M61350</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-11-02T22:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261653#M61351</link>
      <description>&lt;P&gt;Let me see if I can figure this out in the lab tomorrow. So essentially, you want to see logs when trusted CA list has been updated, correct?&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 22:42:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261653#M61351</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-02T22:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261654#M61352</link>
      <description>&lt;P&gt;Yes. What I really need is to see the failure log / debug because it's not updating&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 22:48:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261654#M61352</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-11-02T22:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261655#M61353</link>
      <description>&lt;P&gt;Does anything come up if you search for “Untrusted Certificate – Certificate Chain is not signed by a Trusted CA” or just&amp;nbsp;“Untrusted Certificate"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 22:53:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261655#M61353</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-02T22:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261666#M61354</link>
      <description>&lt;P&gt;Yes, exactly like I wrote in the issue description:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Quote:&lt;BR /&gt;"I also get HTTPS inspection errors like:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Certificate Chain is not signed by a Trusted CA. Refer to sk179944 for more details.&lt;BR /&gt;Certificate DN: 'CN=*.msn.com,O=Microsoft Corporation,L=Redmond,ST=WA,C=US' Requested Server Name: msn.com"&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 06:58:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261666#M61354</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-11-03T06:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261673#M61355</link>
      <description>&lt;P&gt;I know thats what you wrote, thats why I was wondering if you see any logs with those messages?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 12:32:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261673#M61355</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-03T12:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261675#M61356</link>
      <description>&lt;P&gt;Hey Emil,&lt;/P&gt;
&lt;P&gt;This is what I was referring to.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 13:04:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261675#M61356</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-03T13:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261684#M61357</link>
      <description>&lt;P&gt;Yes. This s the log I see in traffic monitor: (This is one example)&lt;BR /&gt;&lt;SPAN&gt;Certificate Chain is not signed by a Trusted CA. Refer to sk179944 for more details.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Certificate DN: 'CN=*.msn.com,O=Microsoft Corporation,L=Redmond,ST=WA,C=US' Requested Server Name: msn.com"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 14:17:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261684#M61357</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-11-03T14:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261686#M61358</link>
      <description>&lt;P&gt;Yes. It is set. I attached a screenshot in the original question. In my version it's slightly different. But it is set to automatic and I need the debug logs to understand what is the problem with the updates&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 14:20:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261686#M61358</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-11-03T14:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261687#M61359</link>
      <description>&lt;P&gt;Hm...thats a bit odd. Not sure why it would give an sk related to standalone config.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 14:20:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261687#M61359</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-03T14:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261689#M61360</link>
      <description>&lt;P&gt;Yeah but that's not important. The issue here is the CA updating.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 14:25:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261689#M61360</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-11-03T14:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261690#M61361</link>
      <description>&lt;P&gt;I get it. Might be worth TAC case, if you had not opened one yet.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 14:28:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261690#M61361</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-03T14:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted CA list update issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261795#M61362</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Please let us know once you figure this out, Im also super curious.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 20:20:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Trusted-CA-list-update-issues/m-p/261795#M61362</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-04T20:20:14Z</dc:date>
    </item>
  </channel>
</rss>

