Assuming your R80.x Management was upgraded from R77.x, your Internal CA is still probably using SHA1 certificates.
A fresh install of R80.x would result in a SHA256 ICA.
If you want to change your ICA to SHA256, see:
https😕/, if you're managing older gateways, this will break your ability to manage them.
The SK above lists the versions that supports a SHA256 ICA.
sk103839 relates to how the gateway and management fetches updates from Check Point and isn't related to the ICA.