- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello everyone,
I'm trying to create a self-signed certificate using OpenSSL, but I keep running into an issue where the certificate is recognized as invalid.
I followed these steps to create the certificate:
Generating the Private Key
openssl genrsa -out my_private.key 2048
Creating the Certificate Signing Request (CSR)
openssl req -new -key my_private.key -out my_request.csr
I filled in the required details like Common Name (CN), organization, and location.
Creating the Self-Signed Certificate
openssl x509 -req -in my_request.csr -signkey my_private.key -out my_certificate.crt -days 365 -sha256
Converting to PFX for Import
openssl pkcs12 -export -out my_certificate.pfx -inkey my_private.key -in my_certificate.crt -passout pass:MySecurePassword
Everything seems to be correct, but when I try to use the certificate, my system or application says it is invalid.
I checked the certificate details with:
openssl x509 -in my_certificate.crt -noout -text
The output seems fine, but it still doesn’t work.
Could the issue be related to a missing CA certificate, incorrect signing, or something else in my OpenSSL setup?
I’d really appreciate any help or advice on what could be causing this. Has anyone else experienced this problem?
Thanks in advance!
Rafael
Maybe it is a stupid comment. But for me it is normal an application / browser will give a warning because it is self-signed.
And with system you mean a Check Point device? Because I don't see how it is related yet.
Sry.
I want to upload the self-signed certificate to my 1600 appliance. But i get from the appliance web interface the error message: "Invalid Certificate or Password is Wrong". But the Password is correct!
Maybe wrong cert extension?
Andy
Reason @LM-Rafael why I asked last question about extension of the cert is because whenever you try to upload any sort of cert, regardless if its for the fw or anything else, it will always come up with predefined (for the lack of the better word) extension, so say if you see .p12 there, then certificate HAS TO be in that format, nothing else would work.
Hope that helps.
Andy
I think you have to upload a .p12
Atleast in SmartConsole it is always a .p12. I assume this is locally managed?
I think so too Lesley. Thats the only extension I ever see when trying to upload fw cert.
Andy
Hi @LM-Rafael
I usually user XCA to handle certificates.
This is really good tool
Akos
How to get a .p12 certificate can be found in https://support.checkpoint.com/results/sk/sk170395
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY