- Products
- Learn
- Local User Groups
- Partners
- More
Call For Papers
Your Expertise, Our Stage
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata - Securing the Agenic AI Era
AI Security Masters E3:
AI-Generated Malware
CheckMates Go:
CheckMates Fest
hi, we setup a vm and created an https inspection policy rule to allow access to "Internet" on port https/443 and set the action to inspect and to use the outbound_certificate. Before the rule was set, the vm was able to access internet sites ok. After the https inspection rule was enabled and policy installed, access to any internet website pops up with NET::ERR_CERT_AUTHORITY_INVALID error.
we use sub-CA on the gateway issued by our enterprise root CA. This sub-CA is present in the Trusted CA's of the gateway object.
root CA cert is installed on the vm under trusted root ca. I have also exported the sub-CA cert from the https inspection tab of the gateway and imported it under root ca of the vm (tried it under intermediate ca and third party ca as well).
checkpoint logs show http validation == untrusted certificate. reboot of the vm did not help either.
using version r81.10
not sure what am i missing.. any suggestions please. Thank you in advance.
Maybe https://support.checkpoint.com/results/sk/sk112722 ?
Tried this, same error.
I would suggest to contact CP TAC to get this resolved !
I agree with Guenther, please work with TAC to get this solved, might be much faster via remote session.
Andy
If its under trusted root, that sounds right. Here is how customer I worked with on this issue last year fixed it, maybe you can confirm this. Also, make sure that automatic update is checked in https legacy dashboard (its under blades tab in smart console)
Andy
automatic updates already checked in the legacy dashboard.
Viewing the cert from the url bar gives - Issued by - Common name = Untrusted.
I have fully working https inspection lab, will check later.
Andy
I have fully working https inspection lab, will check later.
Andy
Btw, just checked and that error might not be cert issue necessarily. Do you get this for any given browser and on every machine or you just tested on one?
Andy
https://www.hostinger.com/tutorials/err_cert_authority_invalid
When using a sub-CA root cert, make sure the whole chain is included and can be validated through CLRs. If not, the actual certificate will be shown as untrusted.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 42 | |
| 25 | |
| 14 | |
| 12 | |
| 8 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 6 |
Thu 26 Feb 2026 @ 05:00 PM (CET)
AI Security Masters Session 4: Introducing Cyata, Securing the Agentic AI EraTue 03 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Introduction to Maestro Hyperscale FirewallsTue 03 Mar 2026 @ 03:00 PM (EST)
Maestro Masters Americas: Introduction to Maestro Hyperscale FirewallsThu 26 Feb 2026 @ 05:00 PM (CET)
AI Security Masters Session 4: Introducing Cyata, Securing the Agentic AI EraTue 03 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Introduction to Maestro Hyperscale FirewallsTue 03 Mar 2026 @ 03:00 PM (EST)
Maestro Masters Americas: Introduction to Maestro Hyperscale FirewallsFri 06 Mar 2026 @ 08:00 AM (COT)
Check Point R82 Hands‑On Bootcamp – Comunidad DOJO PanamáAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY