- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hello Guys, I need your help regarding https.
We have a checkpoint deployment and want to enable https inspection but need a trusted certificate.
Please do advice on how/where to get this trusted certificates and types with details on how to make filtering sub https pages.
Thanks
Regards
Ewane,
In order to implement HTTPS inspection, you need to either use Root or sub-CA.
The easiest way to get this to work is to issue a self-signed certificate on your Check Point gateway and distribute it to PCs and servers in your organization via GPO, (or installed manually or scripted).
Alternatively, if you have an established PKI in your organization, you can create certificate in there and import it in Check Point gateways.
If you were thinking about using host certificate purchased from one of the vendors such as Comodo, GoDaddy, etc, this will not work.
I strongly suggest reading HTTPS Inspection FAQ and HTTPS inspection with 3rd party certificate shows browser error .
If you were thinking about using host certificate purchased from one of the vendors such as Comodo, GoDaddy, etc, this will not work.
Using such sub-CA keys for HTTPS Inspection purposes is explicitly against the Terms of Service of public CAs.
You can watch this short video that illustrates the process using manual root CA certificate installation process:
I found that when using https inspection that if an sub-https page is called for certificate exchange - in the client hello SNI field that the exchange will fail as the firewall detects the first packet is not a syn. The way I have bypassed this is downloading the "Application Control Signature Tool" from Checkpoint. You build your own app from the contents of the SNI field as if it were a Checkpoint built app. (Unfortunately you cannot add custom categories so I just use Government.) In my https inspection policies I bypass Government. It not perfect but it is allowing https inspection to run for all applications. Of course I have to build an app any time something fails.
Hello John,
It is possible to create a custom category and include all your self-signed build app instead of using Checkpoint already assigned category.
How?
Go to the application tab
click on application/sites
click on new and select category
add a name and click finish
Now when you are creating your application use that category new.

However, the custom categories do not appear in the list using the ACST.exe tool. Only Checkpoints standard categories. I am using ACST_v1.3.1.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 15 | |
| 9 | |
| 7 | |
| 7 | |
| 7 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 |
Thu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY