<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS inspection - Create a CSR for outbound certificate for external CA in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257643#M43434</link>
    <description>&lt;P&gt;I am fairly sure to import it into smart console, it would have to be .p12 extension, but I could be mistaken.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 18 Sep 2025 15:51:09 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-09-18T15:51:09Z</dc:date>
    <item>
      <title>HTTPS inspection - Create a CSR for an external CA to use for the outbound certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257426#M43365</link>
      <description>&lt;P&gt;How can I&amp;nbsp;create a new CSR&amp;nbsp; (Certificate Signing Request)&amp;nbsp; for outbound certificate for external CA ? The CA is a windows CA server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 05:13:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257426#M43365</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-09-18T05:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257427#M43366</link>
      <description>&lt;P&gt;Not sure if below steps make 100% sense, but looks okay to me.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;******************&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 data-start="259" data-end="297"&gt;1. Decide Where to Generate the CSR&lt;/H2&gt;
&lt;P data-start="298" data-end="332"&gt;You can generate the CSR either:&lt;/P&gt;
&lt;UL data-start="333" data-end="511"&gt;
&lt;LI data-start="333" data-end="423"&gt;
&lt;P data-start="335" data-end="423"&gt;&lt;STRONG data-start="335" data-end="421"&gt;On the Check Point Security Gateway / Management Server (Gaia CLI or SmartConsole)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="424" data-end="511"&gt;
&lt;P data-start="426" data-end="511"&gt;&lt;STRONG data-start="426" data-end="456"&gt;Externally (Windows/Linux)&lt;/STRONG&gt; and then import the signed certificate + private key&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="513" data-end="648"&gt;Best practice: generate the CSR directly on the Check Point box where the private key will be used, so the key never leaves the device.&lt;/P&gt;
&lt;HR data-start="650" data-end="653" /&gt;
&lt;H2 data-start="655" data-end="698"&gt;2. Generate CSR in Gaia Portal (Easiest)&lt;/H2&gt;
&lt;OL data-start="699" data-end="1241"&gt;
&lt;LI data-start="699" data-end="764"&gt;
&lt;P data-start="702" data-end="764"&gt;Log into the &lt;STRONG data-start="715" data-end="730"&gt;Gaia Portal&lt;/STRONG&gt; (https://&amp;lt;mgmt_or_gateway_IP&amp;gt;).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="765" data-end="831"&gt;
&lt;P data-start="768" data-end="831"&gt;Go to:&lt;BR data-start="774" data-end="777" /&gt;&lt;STRONG data-start="780" data-end="829"&gt;Device &amp;gt; Certificates &amp;gt; Outgoing Certificates&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="832" data-end="894"&gt;
&lt;P data-start="835" data-end="894"&gt;Click &lt;STRONG data-start="841" data-end="891"&gt;Add &amp;gt; Create Certificate Signing Request (CSR)&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="895" data-end="1162"&gt;
&lt;P data-start="898" data-end="917"&gt;Fill in the fields:&lt;/P&gt;
&lt;UL data-start="921" data-end="1162"&gt;
&lt;LI data-start="921" data-end="1013"&gt;
&lt;P data-start="923" data-end="1013"&gt;&lt;STRONG data-start="923" data-end="944"&gt;CN (Common Name):&lt;/STRONG&gt; typically the FQDN used for outbound TLS (e.g., proxy.company.com)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1017" data-end="1085"&gt;
&lt;P data-start="1019" data-end="1085"&gt;&lt;STRONG data-start="1019" data-end="1053"&gt;O (Organization), OU, L, ST, C&lt;/STRONG&gt; as required by your CA policy&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1089" data-end="1162"&gt;
&lt;P data-start="1091" data-end="1162"&gt;&lt;STRONG data-start="1091" data-end="1106"&gt;Key length:&lt;/STRONG&gt; 2048 or 3072 bits (depending on your CA requirements)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI data-start="1163" data-end="1215"&gt;
&lt;P data-start="1166" data-end="1215"&gt;Save/Generate → This will create a &lt;CODE data-start="1201" data-end="1207"&gt;.csr&lt;/CODE&gt; file.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1216" data-end="1241"&gt;
&lt;P data-start="1219" data-end="1241"&gt;Download the CSR file.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR data-start="1243" data-end="1246" /&gt;
&lt;H2 data-start="1248" data-end="1278"&gt;3. Submit CSR to Windows CA&lt;/H2&gt;
&lt;P data-start="1279" data-end="1305"&gt;On your Windows CA server:&lt;/P&gt;
&lt;OL data-start="1306" data-end="1739"&gt;
&lt;LI data-start="1306" data-end="1348"&gt;
&lt;P data-start="1309" data-end="1348"&gt;Open &lt;STRONG data-start="1314" data-end="1345"&gt;Certification Authority MMC&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1349" data-end="1552"&gt;
&lt;P data-start="1352" data-end="1552"&gt;Right-click the CA → &lt;STRONG data-start="1373" data-end="1407"&gt;All Tasks → Submit new request&lt;/STRONG&gt;.&lt;BR data-start="1408" data-end="1411" /&gt;Or, if using web enrollment, open:&lt;BR data-start="1448" data-end="1451" /&gt;&lt;CODE data-start="1454" data-end="1481"&gt;http://&amp;lt;CAserver&amp;gt;/certsrv&lt;/CODE&gt; → Request a certificate → Advanced certificate request → Submit CSR.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1553" data-end="1663"&gt;
&lt;P data-start="1556" data-end="1663"&gt;Choose the correct &lt;STRONG data-start="1575" data-end="1599"&gt;certificate template&lt;/STRONG&gt; (e.g., Web Server, Subordinate CA, etc., depending on usage).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1664" data-end="1739"&gt;
&lt;P data-start="1667" data-end="1739"&gt;Submit and download the signed certificate (usually &lt;CODE data-start="1719" data-end="1725"&gt;.cer&lt;/CODE&gt; or &lt;CODE data-start="1729" data-end="1735"&gt;.p7b&lt;/CODE&gt;).&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR data-start="1741" data-end="1744" /&gt;
&lt;H2 data-start="1746" data-end="1792"&gt;4. Import Signed Certificate Back into Gaia&lt;/H2&gt;
&lt;OL data-start="1793" data-end="2065"&gt;
&lt;LI data-start="1793" data-end="1873"&gt;
&lt;P data-start="1796" data-end="1873"&gt;Go back to &lt;STRONG data-start="1807" data-end="1870"&gt;Gaia Portal → Device → Certificates → Outgoing Certificates&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1874" data-end="1911"&gt;
&lt;P data-start="1877" data-end="1911"&gt;Select your pending CSR request.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1912" data-end="2008"&gt;
&lt;P data-start="1915" data-end="2008"&gt;Click &lt;STRONG data-start="1921" data-end="1943"&gt;Import Certificate&lt;/STRONG&gt; and upload the &lt;CODE data-start="1959" data-end="1965"&gt;.cer&lt;/CODE&gt; (or export from CA as Base64 if needed).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2009" data-end="2065"&gt;
&lt;P data-start="2012" data-end="2065"&gt;Once imported, the status will change to &lt;STRONG data-start="2053" data-end="2062"&gt;Valid&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR data-start="2067" data-end="2070" /&gt;
&lt;H2 data-start="2072" data-end="2099"&gt;5. (Optional) CLI Method&lt;/H2&gt;
&lt;P data-start="2100" data-end="2120"&gt;If you prefer CLI:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="contain-inline-size rounded-2xl relative bg-token-sidebar-surface-primary"&gt;
&lt;DIV class="sticky top-9"&gt;
&lt;DIV class="absolute end-0 bottom-0 flex h-9 items-center pe-2"&gt;
&lt;DIV class="bg-token-bg-elevated-secondary text-token-text-secondary flex items-center gap-4 rounded-sm px-2 font-sans text-xs"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="whitespace-pre! language-bash"&gt;&lt;SPAN&gt;&lt;SPAN class="hljs-comment"&gt;# Create a new private key and CSR&lt;/SPAN&gt;
openssl req -new -newkey rsa:2048 -nodes -keyout outbound.key -out outbound.csr
&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;PRE class="overflow-visible!" data-start="2122" data-end="2248"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;UL data-start="2250" data-end="2418"&gt;
&lt;LI data-start="2250" data-end="2330"&gt;
&lt;P data-start="2252" data-end="2330"&gt;Transfer the &lt;CODE data-start="2265" data-end="2271"&gt;.csr&lt;/CODE&gt; to your Windows CA, sign it, then bring the &lt;CODE data-start="2316" data-end="2322"&gt;.cer&lt;/CODE&gt; back.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2331" data-end="2418"&gt;
&lt;P data-start="2333" data-end="2418"&gt;Import both &lt;CODE data-start="2345" data-end="2351"&gt;.key&lt;/CODE&gt; and &lt;CODE data-start="2356" data-end="2362"&gt;.cer&lt;/CODE&gt; into Check Point with &lt;CODE data-start="2385" data-end="2398"&gt;cpca_client&lt;/CODE&gt; or via Gaia Portal.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 17 Sep 2025 00:54:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257427#M43366</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-17T00:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257429#M43367</link>
      <description>&lt;P&gt;We have it documented here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk165856" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk165856&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 01:45:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257429#M43367</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-09-17T01:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257430#M43368</link>
      <description>&lt;P&gt;Perfect, even better!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 01:49:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257430#M43368</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-17T01:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257539#M43397</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;There is no such menu in Gaia GUI:&amp;nbsp;Device &amp;gt; Certificates &amp;gt; Outgoing Certificates&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 660px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31489i1D54685254EAAA56/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I will try what emmap suggested&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 18:53:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257539#M43397</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-09-17T18:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257540#M43398</link>
      <description>&lt;P&gt;Fair enough, its an official CP documentation anyway.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 18:42:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257540#M43398</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-17T18:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257562#M43402</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I followed sk165856, But instead of step 6 i used the method below (since step 6 failed and generated this error: unable to load certificates&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-Run "cpopenssl pkcs12 -export -in inspection-ca.cer -inkey inspection-key.pem -out inspection.pfx"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-After got the certificate in .pfx format, rename it to .p12 format&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-Import to smart console.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/Management/OpenSSL-latest-version-support-for-pkcs12-cert-creation/td-p/198769" target="_blank"&gt;https://community.checkpoint.com/t5/Management/OpenSSL-latest-version-support-for-pkcs12-cert-creation/td-p/198769&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 05:01:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257562#M43402</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-09-18T05:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257568#M43406</link>
      <description>&lt;P&gt;OK, you haven't included the rootCA in there, so if you have trust issues from endpoints that are trusting that root CA that might be why. Let us know how you go anyway.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 08:01:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257568#M43406</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-09-18T08:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257578#M43411</link>
      <description>&lt;P&gt;Maybe it was wrong cert extension?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 10:05:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257578#M43411</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-18T10:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257639#M43430</link>
      <description>&lt;P&gt;Thx! I'll let you know.&lt;/P&gt;&lt;P&gt;The root-ca is the internal organizational ca, so to the best of my knowledge, every domain member should trust it.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 15:47:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257639#M43430</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-09-18T15:47:19Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257641#M43432</link>
      <description>&lt;P&gt;I'm not sure. I don't believe file extensions really matter when using openssl&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 15:49:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257641#M43432</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-09-18T15:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257642#M43433</link>
      <description>&lt;P&gt;So, on step 6, since you said thats where it faisl it only gives that error unable to load certificate?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 15:49:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257642#M43433</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-18T15:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257643#M43434</link>
      <description>&lt;P&gt;I am fairly sure to import it into smart console, it would have to be .p12 extension, but I could be mistaken.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 15:51:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257643#M43434</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-18T15:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257644#M43435</link>
      <description>&lt;P&gt;Correct. And seems like I'm not the only one. But with the workaround everything seems to be working. I already made some test and the endpoint can see the certificate that the firewall issues and it is trusted as the root-ca is a trusted CA of the endpoint&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 15:52:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257644#M43435</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-09-18T15:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257645#M43436</link>
      <description>&lt;P&gt;You are correct. Smart console only looking for p12 file. That's why there is a rename extension step in the workaround I guess.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 15:54:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257645#M43436</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2025-09-18T15:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection - Create a CSR for outbound certificate for external CA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257647#M43438</link>
      <description>&lt;P&gt;Well, as long as all the relevant certs are included in truster root store on user's PC, then you are good.&lt;/P&gt;
&lt;P&gt;I made post about this as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Https-inspection-tip/m-p/219139" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Https-inspection-tip/m-p/219139&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 15:55:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-inspection-Create-a-CSR-for-an-external-CA-to-use-for-the/m-p/257647#M43438</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-18T15:55:26Z</dc:date>
    </item>
  </channel>
</rss>

