The wording using "outbound" is what i believe unfortunate.
Just confirmed with TAC via a SR now. After they have checked, they have confirmed this is the correct import button.
Probably the SK should have either the full button label, or the label should be shortened.
Issue is fixed. For some reason the default Check Point trusted list of Root CA's is not complete. Microsoft looks like it trusts this particular cert chain out of the box. Error for " untrusted" Certificate Chain has dissapeared and has been repalced with invalid (OSCP cannot connect) but the traffic works this time.
Untrusted is automatically blocked, while invalid is allowed.