- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All,
Recently, i just found out my client's security management ICA will be expired on next year July. With this item, i wonder if the ICA will be automatically renewed by the security management? If yes, when it will automatically renewed ( 1 month before expired)?
I appreciate if someone able to advise me on this.
Thank you.
Please refer: sk158096: How to renew an Internal Certificate Authority (ICA) certificate
As prerequisite to updating your internal CA Certificate, please verify that your Security Management and Gateways are installed with the below versions, or higher:
• R81 Jumbo Hotfix Accumulator Take 25 or higher
• R80.40 Jumbo Hotfix Accumulator Take 114 or higher
• R80.30 Jumbo Hotfix Accumulator Take 235 or higher
• R80.20 Jumbo Hotfix Accumulator Take 202 or higher
• R80.10 Jumbo Hotfix Accumulator Take 290 or higher
Hi,
Thanks for your reply to my post. I have a question would like to ask you, what if my security gateway doesn't meet the jumbo hotfix requirement but I don't wish to jumbo hotfix it because reboot required? What is the potential impact if i do so?
Thank you.
Thank you.
SIC might be lost with the Gateways.
Hopefully in the next 12-months you can find a window, this should be feasible especially for a cluster.
With that said the minimal gateway level should be at least:
• R81 or higher
• R80.40 Jumbo Hotfix Accumulator Take 69 or higher
• R80.30 Jumbo Hotfix Accumulator Take 163 or higher
• R80.20 Jumbo Hotfix Accumulator Take 129 or higher
• R80.10 Jumbo Hotfix Accumulator Take 262 or higher
Hi,
With your description, that's mean:
the security management with R8040 jumbo hotfix 156, and security gateway with R8040 jumbo hotfix 102 should be enough to fulfill the pre-requisite.
Yes, you should be able to complete the procedure without concern prior to expiry.
Hi Chris,
Good day to you and i hope you are doing fine.
I have a concern would like to seek for your help to clarify it.
If the management server's internal certificate being renewed, may i know is the capsule connect/vpn user's certificate (signed by old management server certificate) need to be renewed manually via re-enroll?
Thank you.
The finger print will change, to help avoid pop-ups on the end user side you can distribute an updated registry key via GPO or similar following the renewal process.
As the renewal process involves TAC assistance I suggest engaging them to advise further on considerations for your specific scenario / deployment.
Hi,
Noted on your suggestion and i will open a case to ask TAC regarding my question. I will update at here if have any update.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 17 | |
| 12 | |
| 11 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY