- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi All,
Just had to renew a HTTPS certificate that expired yesterday and caused an outage this morning.
I cant see any warning in the policy install, audit logs or logs and there is no mention in the ARTG etc.
I know better warnings about VPN Cert expiry has been added.
Am I missing something obvious?
Hi @StackCap43382,
Thanks for your valued feedback.
We introduced a new HealthCheck Point (HCP) test to verify the expiration date of the HTTPS Inspection outbound certificate.
The test will be included in an upcoming release of HCP.
The possible results for the test are as follows:
# SUCCESS - No issues detected. The certificate is valid and will not expire in the next 60 days.
# WARNING - The certificate will expire within the next 60 days.
# ERROR - Issues detected that need immediate action. The certificate is either expired or not yet valid.
Thanks,
Matan
sk173629 - How to update Trusted CAs automatically
sk108641: How to renew, import, or export a new HTTPS Inspection certificate
I don't see anything there about HTTPS Certificate expiration warnings.
Im almost positive you dont get warning for that, at least I never seen it in any customer's environment or in multiple labs where I had it enabled (R80.30, R80.40, R81.10 and R81.20). You can certainly confirm with TAC, but Im 99.99% sure there is no warning pop-up for inspection cert.
I know, it would make total sense to receive it, but guess not there.
Andy
I've also not seen anything going back to r77.30.
I've opened a case with TAC to be 100% sure.
I have noticed there is a API command in the latest 1.9.1 version of the MGMT API that appears you can extract HTTPS certificate details.
mgmt_cli show outbound-inspection-certificate
https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-outbound-inspection-certificate...
Correct, this is just in my lab, which also matches below screwenshot in legacy https inspection smart console. I believe max validity is 15 years.
Andy
valid-from: "14-Sep-23"
valid-to: "31-Dec-37"
I had the same problem, my certificate expired after 5 years. No warnings either. I had to renew and set a long expiration date.
Makes sense...I hope someone from Israel sees this post and they make that change, as I agree 100%, it would be very convenient to have warning at least 6 months in advance, thats more than enough time.
Andy
Ticket Raised with TAC.
Confirmed no current method to monitor.
Requested to raise RFE.
In case anyone wants to use API to pull Cert Experation:
https://sc1.checkpoint.com/documents/latest/APIs/#cli/show-outbound-inspection-certificate~v1.9%20
I had been super busy with other more pressing CP issues, but still working on this, not giving up.
Andy
Hi @StackCap43382,
Thanks for your valued feedback.
We introduced a new HealthCheck Point (HCP) test to verify the expiration date of the HTTPS Inspection outbound certificate.
The test will be included in an upcoming release of HCP.
The possible results for the test are as follows:
# SUCCESS - No issues detected. The certificate is valid and will not expire in the next 60 days.
# WARNING - The certificate will expire within the next 60 days.
# ERROR - Issues detected that need immediate action. The certificate is either expired or not yet valid.
Thanks,
Matan
Thank you @the_rock 😍
Thank you for adding this to the HCP tool.
The issue is that I still consider HCP a power user tool as the vast majority of customers either don't know its there or run it often enough to pick up on this before its too late.
The alert/notification should require no manual action from the administrator (run the script) and should be a management notification.
There are several functions/faults that generate a popup on Smart Console login, this should be one of them.
I really love the fact that web version was possible for HCP starting in R81.10
Below is what it looks like in my R81.20
Andy
We are working to integrate the hcp alert into the Mgmt/SmartConsole. This is planned for next version.
Great news @Izhar_Shoshani_
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
11 | |
6 | |
5 | |
5 | |
5 | |
4 | |
3 | |
3 | |
3 |
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY