<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237261#M2664</link>
    <description>&lt;P&gt;Pretty sure you need to deploy the ICA CA certificate to the mobile device as "trusted."&lt;BR /&gt;This either has to be done via MDM or manually.&lt;/P&gt;</description>
    <pubDate>Tue, 31 Dec 2024 01:25:45 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-12-31T01:25:45Z</dc:date>
    <item>
      <title>How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237158#M2661</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have deployed new remote access VPN. Where we implemented vpn Client on Mobiles (Checkpoint Capsule connect) but we are getting certificate warning to Trust and Continue. So&amp;nbsp;How to prevent Untrusted Certificate warning message on mobile Phone (checkpoint capsule connect)&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 11:57:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237158#M2661</guid>
      <dc:creator>Prasaddere</dc:creator>
      <dc:date>2024-12-30T11:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237159#M2662</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/108771"&gt;@Prasaddere&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you share a screenshot of the message?&lt;/P&gt;
&lt;P&gt;My first 2 idea for solution.&lt;/P&gt;
&lt;P&gt;1:&lt;/P&gt;
&lt;P&gt;Use 3rd party certificate. Choose one that its root is installed in the Trusted Root Certificate store on the device.&lt;BR /&gt;(eg.:DigiCert)&lt;/P&gt;
&lt;P&gt;2:&lt;/P&gt;
&lt;P&gt;Install the Check Point's root and issuer certificate onto the devices.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 12:26:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237159#M2662</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-12-30T12:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237180#M2663</link>
      <description>&lt;P&gt;I see what Akos is saying. But, first, screenshot would certainly help. Just blur out any sensitive data, please.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 14:26:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237180#M2663</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-30T14:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237261#M2664</link>
      <description>&lt;P&gt;Pretty sure you need to deploy the ICA CA certificate to the mobile device as "trusted."&lt;BR /&gt;This either has to be done via MDM or manually.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2024 01:25:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237261#M2664</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-31T01:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237280#M2665</link>
      <description>&lt;P&gt;Attached screenshot. we have already deployed certificate from internal CA for Mobile blade portal and different certificate for IPSec Client including all root and subordinate CA. Still getting the attached message for certificate trust first time which we need to avoid.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Same we had issue on Windows laptop but we solution to add fingerprint in Windows registry. which we have added. Issue is only with now on Mobile phone.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2024 09:47:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237280#M2665</guid>
      <dc:creator>Prasaddere</dc:creator>
      <dc:date>2024-12-31T09:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237281#M2666</link>
      <description>&lt;P&gt;Certificate from internal CA already added in root CA as well issuing CA. Also server certificate attahed on IPsec client. as seperate CSR generated for mobile against which we got another certificate P12 which we import on mobile portal.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2024 09:49:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237281#M2666</guid>
      <dc:creator>Prasaddere</dc:creator>
      <dc:date>2024-12-31T09:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237283#M2667</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;To be sure, when you accepted the cert and check the certificate chain, everything looks normal?&lt;/P&gt;
&lt;P&gt;If you use MDM only one certificate store exists on the device?&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2024 11:05:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237283#M2667</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-12-31T11:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237830#M2668</link>
      <description>&lt;P&gt;we have tried with the public certificate but there same trust message is coming first time when creating the site.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 12:57:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237830#M2668</guid>
      <dc:creator>Prasaddere</dc:creator>
      <dc:date>2025-01-07T12:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237832#M2669</link>
      <description>&lt;P&gt;Is it same issue if user deletes/re-creates the site?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 13:07:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237832#M2669</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-07T13:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237834#M2670</link>
      <description>&lt;P&gt;Yes, it is the same issue.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 13:09:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237834#M2670</guid>
      <dc:creator>Prasaddere</dc:creator>
      <dc:date>2025-01-07T13:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237841#M2671</link>
      <description>&lt;P&gt;Did you end up opening TAC case?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 13:29:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237841#M2671</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-07T13:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237845#M2672</link>
      <description>&lt;P&gt;You can say, yes, IND TAC seems do not have expertise, Our many case going month on month with resolutions only asking for logs. lot of delay in response.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 13:33:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237845#M2672</guid>
      <dc:creator>Prasaddere</dc:creator>
      <dc:date>2025-01-07T13:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237848#M2673</link>
      <description>&lt;P&gt;I suppose you can always get in touch with your local SE and tell them about it or ask for it to be escalated.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 13:37:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237848#M2673</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-07T13:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237905#M2674</link>
      <description>&lt;P&gt;Are you sure that:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The gateway is sending the correct certificate?&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29121iB5C351C8AF80928E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29122iDBBA7D54F89D52E5/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;The client is actually set to trust certificates signed by the relevant CA and sub-CA(s)? Please provides screenshots from the mobile client(s) showing the same certificate(s) shown in the above as trusted.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Also what mobile device(s) are you having this issue with?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 19:24:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237905#M2674</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-07T19:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237947#M2675</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;We have resolved the issue. For Certificate authetication, there was no issue as we have internal PKI certificate attached in Ipsec VPN. We had issue when creating new site in application that was giving trust message with fingerprint. For which we followed below in Mobile blade portal setting certificate.&lt;/P&gt;&lt;P&gt;we had to put the external certificate but digicert was giving only domain name cert so we had to combine this certificate with intermediate and root Certificate, then we created p12 cert which we uploaded Mobile blade portal setting, then trust warning message, gone. It is not asking while crating site.&lt;/P&gt;&lt;P&gt;Thanks all for your support.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 10:19:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237947#M2675</guid>
      <dc:creator>Prasaddere</dc:creator>
      <dc:date>2025-01-08T10:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237960#M2676</link>
      <description>&lt;P&gt;Great job, thanks for letting us know!&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 12:03:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/237960#M2676</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-08T12:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent  Untrusted Certificate warning message in checkpoint capsule connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/238025#M2677</link>
      <description>&lt;P&gt;That's pretty much standard operating procedure for anything related to certificates.&lt;BR /&gt;That means your p12 file should (also) contain root and intermediate CA(s).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 23:37:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-prevent-Untrusted-Certificate-warning-message-in/m-p/238025#M2677</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-08T23:37:17Z</dc:date>
    </item>
  </channel>
</rss>

