- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I'm in the process of "rebuilding" a system, and one element that I need to re-enable is HTTPS inspection. This was working previously, but has been bypassed for the last several months (by a rule in the policy)
The existing certificate is 5 years old with a 10 year life, and at present is NOT installed on the users machines due to them being rebuilt (and group policy being reset too!), its also created on the management server using the company's name as the issuing authority (www.mycompany,co,uk), but this is a local certificate and nothing to do with the actual real domain by that name. So the cert shows issued by and issued to, both as www.mycompany.co.uk, which is a little confusing for people.
So my thought is to generate a new certificate on the management server, using a more generic or obvious name with a full 10 years on it, then deploy this with via a GPO, however I can't see a way to do this.
I'm assuming that there is a way to do this but so far I've not found anything helpful (everything seems to discuss creating it when you turn on HTTPS inspection, but as it's already on this isn't an option), so I was wondering if anyone could advise me?
Hey Steve,
I had that happen with customer once and TAC provided below sk to follow.
Andy
https://support.checkpoint.com/results/sk/sk92870
Hey Steve,
I had that happen with customer once and TAC provided below sk to follow.
Andy
https://support.checkpoint.com/results/sk/sk92870
Hi Andy,
This doesn't mention R81.20, but it does mention R81.10 so I figured that as long as I do a snapshot first it's definitely worth a try!
Worked like a dream, resetting the HTTPS as if it's never been enabled before, and allowed me to create a new certificate which was exactly what was required!
Perfect, thanks!
Steve
Great job! Glad we can help.
Andy
Hi,
If you want to renew the ICA, maybe this sk helps
https://support.checkpoint.com/results/sk/sk158096
Or do you want to make an intermediate (issuer) Ca?
Akos
If you want to create manually a new cert for eg to your GW maybe you can follow this sk
https://support.checkpoint.com/results/sk/sk30501
After you create the user to access the ICA managament you will see this screen:
Then you will be able to create a new cert as you want.
Akos
Totally forgot about that, I see I had it set up in my lab as well, great tool!
Andy
Can be done via Smart Dashboard -> https://support.checkpoint.com/results/sk/sk108641
Or with cpopen ssl on CLI (Check points version of openSSL)
Or any other system with openSSL.
Would do it via SmartDashboard, everything you need to do you can do over there.
My customer did it also that way couple days ago and added to the client and works great.
If something is wrong about the certificate clients will get warning in browser.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 14 | |
| 12 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY