<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Import a trusted CA cert to Gaia OS in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/212850#M35211</link>
    <description>&lt;P&gt;Root CA and any intermediate CAs needed to validate the relevant certificates.&lt;/P&gt;</description>
    <pubDate>Wed, 01 May 2024 14:49:27 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-05-01T14:49:27Z</dc:date>
    <item>
      <title>Import a trusted CA cert to Gaia OS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/134617#M24117</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have our Checkpoint manager behind another device doing HTTPS inspection, what we need is to import its cert as a trusted root ca to the operating system so its trusted, like you would need to do for all Windows/Linux clients behind a checkpoint gateway doing inspection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this possible? I have tried adding it to the https inspection blade trusted CA list but it still shows an untrusted error when connecting.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can we access the cert store on a checkpoint box?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 02:29:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/134617#M24117</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2021-11-22T02:29:36Z</dc:date>
    </item>
    <item>
      <title>Re: Import a trusted CA cert to Gaia OS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/134631#M24119</link>
      <description>&lt;P&gt;Did you follow&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108202&amp;amp;partition=Basic&amp;amp;product=HTTPS" target="_blank"&gt;sk108202: Best Practices - &lt;STRONG&gt;HTTPS&lt;/STRONG&gt; &lt;STRONG&gt;Inspection&amp;nbsp;&lt;/STRONG&gt;&lt;/A&gt;and u&lt;SPAN&gt;se "Update certificate list" option ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 08:53:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/134631#M24119</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-11-22T08:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: Import a trusted CA cert to Gaia OS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/134685#M24126</link>
      <description>&lt;P&gt;Hi yes I have read that, however it's not really my case, my checkpoint manager is not doing https inspection and should have no configuration relating to that, its behind another device doing https inspection (for arguments sakes lets say its not a checkpoint nor a device we have management of and bypassing is not possible), how can I make the manager trust it as a root CA?&lt;/P&gt;
&lt;P&gt;Is there access to the gaia system cert store I can drop the certificate in? normal linux systems you can copy and paste the cert to&amp;nbsp;ca-certificates folder but I dont see any such folder on checkpoint&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 20:31:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/134685#M24126</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2021-11-22T20:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: Import a trusted CA cert to Gaia OS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/134691#M24127</link>
      <description>&lt;P&gt;I've done something similar, but sure if its applicable in this case.&lt;/P&gt;
&lt;P&gt;My requirement was to allow the CP Mgr access to the internet via a Fortigate which was doing https inspection.&amp;nbsp; Therefore the only way to achieve this was to ensure the Fortigates certificate was trusted by the Mgr.&lt;/P&gt;
&lt;P&gt;We had to add the cert in two places, the reason for this was to firstly ensure the Application level could get updates ie. IPS etc, and secondly so that the OS could get updates, ie. Jumbos etc.&lt;/P&gt;
&lt;P&gt;The way I got it working was never confirmed as a supported solution by TAC, but at the same time they never really gave me a solution either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this what you want to do?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 22:24:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/134691#M24127</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-11-22T22:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Import a trusted CA cert to Gaia OS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/134692#M24128</link>
      <description>&lt;P&gt;yes 100% what i need!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please share how to do it? thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 22:25:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/134692#M24128</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2021-11-22T22:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Import a trusted CA cert to Gaia OS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/134708#M24131</link>
      <description>&lt;P&gt;Here is the note I made:&lt;/P&gt;
&lt;P&gt;How to get updates working when there is an upstream Proxy doing Deep SSL Inspection:&lt;BR /&gt;You will need to export the CA file from the upstream device and then add this to the ca-bundle.crt file in two locations on the Checkpoint Manager (assuming that this is where the issue is).&lt;/P&gt;
&lt;P&gt;$CPDIR/conf/ca-bundle.crt &amp;lt;-- This is so that Application level updates can work.&lt;BR /&gt;$FWDIR/bin/ca-bundle.crt &amp;lt;-- This is so that GAIA level updates work.&lt;/P&gt;
&lt;P&gt;Note this has been tested from a R80.40 SMS. However important to note that the file could change as part of upgrade or jumbo installation.&lt;/P&gt;
&lt;P&gt;Additionally the above solution is not supported by TAC.&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 10:26:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/134708#M24131</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2024-05-03T10:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Import a trusted CA cert to Gaia OS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/134769#M24138</link>
      <description>&lt;P&gt;thank you!! that did the trick.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 01:28:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/134769#M24138</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2021-11-24T01:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: Import a trusted CA cert to Gaia OS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/209593#M34714</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;On which machine should you edit the CA-Bundle file mgmt or gateways?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I need to run an update command? for example "rehash_ca_bundle?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2024 12:11:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/209593#M34714</guid>
      <dc:creator>Max91</dc:creator>
      <dc:date>2024-03-25T12:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: Import a trusted CA cert to Gaia OS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/209685#M34727</link>
      <description>&lt;P&gt;- mgmt&lt;/P&gt;
&lt;P&gt;- no, you add it manually&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 10:22:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/209685#M34727</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-03-26T10:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: Import a trusted CA cert to Gaia OS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/212839#M35208</link>
      <description>&lt;P&gt;My purpose is to add our local root Certificate as we're having some issues, wondering if this will solve the inspection issue.&lt;/P&gt;&lt;P&gt;Do we just add the root certificate as text to this bundle-ca.crt file and nothing else?&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2024 13:01:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/212839#M35208</guid>
      <dc:creator>emreturkmenler</dc:creator>
      <dc:date>2024-05-01T13:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: Import a trusted CA cert to Gaia OS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/212850#M35211</link>
      <description>&lt;P&gt;Root CA and any intermediate CAs needed to validate the relevant certificates.&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2024 14:49:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Import-a-trusted-CA-cert-to-Gaia-OS/m-p/212850#M35211</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-01T14:49:27Z</dc:date>
    </item>
  </channel>
</rss>

