- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
the Nessus scanner shows vulnerabilities on to the gateways because they use self-signed certificates at the web gaia level.
I want to import certificates signed with our certifications authority, but I am not sure of the impact it will have on the infrastructure, for example at SIC level ...
Thanks a lot
To change the Gaia portal cert: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
To my knowledge, you cannot change ICA to use a third party CA.
Most portals exposed to users (as well as VPN) can be configured to use a certificate signed by a different CA.
It is only vulnerability if you do not know who signed those certificates. No actual issue here
Thank you for you response
What is the impact if i import certificates signed with our certifications authority on the infrastructure( at SIC level ...)
First, you do not want to change SIC certs, neither root, nor those issued. If you try, you will have to re-do all SIC with all GWs, not a good idea.
If your concern is SSL certs only, identify which exact portals are in need to be changed.
Thanks for your rwply.
All what i want to do is changing certs on gaia portal level and really don't want that to impact any other things like sic communication or cluster communication . If there is any doubt about that i will not do any change .
To change the Gaia portal cert: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
To my knowledge, you cannot change ICA to use a third party CA.
Most portals exposed to users (as well as VPN) can be configured to use a certificate signed by a different CA.
Hello @PhoneBoy
Thank you very much for you reply,
I have one more question please, If i changed the Certificate used by platform portal, should i changed it for all other portals , since all portals on the same Security Gateway IP address use the same certificate ( https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_MobileAccess_AdminGuide/h... )
You should be able to do that, yes.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 20 | |
| 16 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY