<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question about certificate chain in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Question-about-certificate-chain/m-p/282785#M47121</link>
    <description>&lt;P&gt;Hi mates,&lt;/P&gt;
&lt;P&gt;We’re trying to authenticate an internal user with CAPI, but I’m getting the following error:&lt;/P&gt;
&lt;P&gt;cannot complete certificate chain CN=xxxx CA=xxx O=xxxx&lt;/P&gt;
&lt;P&gt;As far as I understand, this might be happening because the management system only has the ICA certificate.&lt;/P&gt;
&lt;P&gt;My question is: to resolve this issue, do I need to import a new CA, or are there any other steps I need to take to complete the certificate chain?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 24 Sep 2026 17:12:25 GMT</pubDate>
    <dc:creator>RemoteUser</dc:creator>
    <dc:date>2026-09-24T17:12:25Z</dc:date>
    <item>
      <title>Question about certificate chain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-certificate-chain/m-p/282785#M47121</link>
      <description>&lt;P&gt;Hi mates,&lt;/P&gt;
&lt;P&gt;We’re trying to authenticate an internal user with CAPI, but I’m getting the following error:&lt;/P&gt;
&lt;P&gt;cannot complete certificate chain CN=xxxx CA=xxx O=xxxx&lt;/P&gt;
&lt;P&gt;As far as I understand, this might be happening because the management system only has the ICA certificate.&lt;/P&gt;
&lt;P&gt;My question is: to resolve this issue, do I need to import a new CA, or are there any other steps I need to take to complete the certificate chain?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 17:12:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-certificate-chain/m-p/282785#M47121</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-09-24T17:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: Question about certificate chain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-certificate-chain/m-p/282803#M47123</link>
      <description>&lt;P&gt;Assuming this is an ICA-generated certificate, you need to import the ICA CA certificate in Windows.&lt;BR /&gt;The public CA of the ICA in can be exported from SmartConsole in&amp;nbsp;Object Categories &amp;gt;&amp;nbsp; Servers &amp;gt; Trusted CA &amp;gt; internal_ca.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 23:11:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-certificate-chain/m-p/282803#M47123</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-09-24T23:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Question about certificate chain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-certificate-chain/m-p/282812#M47128</link>
      <description>&lt;DIV class="" data-is-intersecting="true" data-turn-id-container="c480f1cd-5217-47c7-bbd1-721685859102"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="" data-is-intersecting="true" data-turn-id-container="request-WEB:8e50b9da-266a-4253-acf0-0edc72e0c338-2"&gt;
&lt;SECTION class="text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn="assistant" data-testid="conversation-turn-6" data-turn-id-container="request-WEB:8e50b9da-266a-4253-acf0-0edc72e0c338-2" data-turn-id="request-WEB:8e50b9da-266a-4253-acf0-0edc72e0c338-2"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-8 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" data-conversation-screenshot-content=""&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 [&amp;amp;&amp;gt;div:has([data-free-thinking-preview-answer=true])+:is(.text-message,.relative:has(&amp;gt;.text-message))]:-mt-2 grow"&gt;
&lt;DIV class="PDq2pG_selectionAnchorContainer" data-message-author-role="assistant" data-message-id="733fee35-3987-41db-a8d6-7ff23e136369"&gt;
&lt;DIV&gt;
&lt;DIV class="puik-root not-prose not-markdown" data-theme="dark" data-dil-widget-copy-target=""&gt;
&lt;DIV class="pointer-events-none absolute h-px w-px overflow-hidden opacity-0" aria-hidden="true"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="fv0XaG_DilRenderer fv0XaG_DilResponseRoot J4E5kq_LegacyReveal dil-first-visible-layout w-full max-w-full" dir="auto" data-d-direction="col"&gt;
&lt;P class="w6asjq_TextBase _85PZeG_Text" data-d-component="text"&gt;HI &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="w6asjq_TextBase _85PZeG_Text" data-d-component="text"&gt;So, I need to import the customer’s CA under &lt;SPAN class="w6asjq_TextBase _85PZeG_Text" data-d-inline="" data-d-default-strong="" data-d-component="text"&gt;Server &amp;gt; Trusted CAs&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P class="w6asjq_TextBase _85PZeG_Text" data-d-component="text"&gt;Is there anything else I need to do to resolve the connection issue, or is that enough?&lt;/P&gt;
&lt;P class="w6asjq_TextBase _85PZeG_Text" data-d-component="text"&gt;Under &lt;SPAN class="w6asjq_TextBase _85PZeG_Text" data-d-inline="" data-d-default-strong="" data-d-component="text"&gt;IPsec VPN&lt;/SPAN&gt;, do I also need to add the same CA to get rid of the warning, or is that not necessary?&lt;/P&gt;
&lt;P class="w6asjq_TextBase _85PZeG_Text" data-d-component="text"&gt;Thanks!&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 25 Sep 2026 06:04:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-certificate-chain/m-p/282812#M47128</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-09-25T06:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Question about certificate chain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-certificate-chain/m-p/282872#M47138</link>
      <description>&lt;P&gt;If the certificates are generated from a third party CA, yes, the CA key needs to be imported as described and access policy needs to be installed on the gateway.&lt;BR /&gt;Note that the gateway does need to be able to reach the CRL specified in the CA key.&amp;nbsp;&lt;BR /&gt;Not sure if any other configuration is needed, but it should get you past this error.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 18:58:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-certificate-chain/m-p/282872#M47138</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-09-25T18:58:08Z</dc:date>
    </item>
  </channel>
</rss>

