Solved: HTTPS inspection - Create a CSR for an external CA... - Check Point CheckMates

HTTPS inspection - Create a CSR for an external CA to use for the outbound certificate

How can I create a new CSR  (Certificate Signing Request)  for outbound certificate for external CA ? The CA is a windows CA server.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

1 Solution

Accepted Solutions

emmap

MVP Gold CHKP

‎2025-09-1606:45 PM

Show option menu

Jump to solution

We have it documented here: https://support.checkpoint.com/results/sk/sk165856

View solution in original post

3\ \ \ Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

15 Replies

the_rock

MVP Diamond

‎2025-09-1605:54 PM

Jump to solution

Not sure if below steps make 100% sense, but looks okay to me.

Andy

\\\****************

1. Decide Where to Generate the CSR

You can generate the CSR either:

Best practice: generate the CSR directly on the Check Point box where the private key will be used, so the key never leaves the device.


2. Generate CSR in Gaia Portal (Easiest)

  1. Log into the Gaia Portal (https://<mgmt_or_gateway_IP>).

  2. Go to:

Device > Certificates > Outgoing Certificates

  1. Click Add > Create Certificate Signing Request (CSR).

  2. Fill in the fields:

    • CN (Common Name): typically the FQDN used for outbound TLS (e.g., proxy.company.com)
  1. Save/Generate → This will create a .csr file.

  2. Download the CSR file.


3. Submit CSR to Windows CA

On your Windows CA server:

  1. Open Certification Authority MMC.

  2. Right-click the CA → All Tasks → Submit new request.

Or, if using web enrollment, open:

http://<CAserver>/certsrv → Request a certificate → Advanced certificate request → Submit CSR.

  1. Choose the correct certificate template (e.g., Web Server, Subordinate CA, etc., depending on usage).

  2. Submit and download the signed certificate (usually .cer or .p7b).


4. Import Signed Certificate Back into Gaia

  1. Go back to Gaia Portal → Device → Certificates → Outgoing Certificates.

  2. Select your pending CSR request.

  3. Click Import Certificate and upload the .cer (or export from CA as Base64 if needed).

  4. Once imported, the status will change to Valid.


5. (Optional) CLI Method

If you prefer CLI:

# Create a new private key and CSR openssl req -new -newkey rsa:2048 -nodes -keyout outbound.key -out outbound.csr


Best,

Andy

"Have a great day and if its not, change it"

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Emil_T

Collaborator

‎2025-09-1711:39 AM

In response to the_rock

Jump to solution

Hi

There is no such menu in Gaia GUI: Device > Certificates > Outgoing Certificates

I will try what emmap suggested

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

the_rock

MVP Diamond

‎2025-09-1711:42 AM

In response to Emil_T

Jump to solution

Fair enough, its an official CP documentation anyway.

Andy

Best,

Andy

"Have a great day and if its not, change it"

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

emmap

MVP Gold CHKP

‎2025-09-1606:45 PM

Jump to solution

We have it documented here: https://support.checkpoint.com/results/sk/sk165856

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

the_rock

MVP Diamond

‎2025-09-1606:49 PM

In response to emmap

Jump to solution

Perfect, even better!

Andy

Best,

Andy

"Have a great day and if its not, change it"

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Emil_T

Collaborator

‎2025-09-1710:01 PM

Jump to solution

I followed sk165856, But instead of step 6 i used the method below (since step 6 failed and generated this error: unable to load certificates

-Run "cpopenssl pkcs12 -export -in inspection-ca.cer -inkey inspection-key.pem -out inspection.pfx"

-After got the certificate in .pfx format, rename it to .p12 format

-Import to smart console.

https://community.checkpoint.com/t5/Management/OpenSSL-latest-version-support-for-pkcs12-cert-creati...

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

emmap

MVP Gold CHKP

‎2025-09-1801:01 AM

In response to Emil_T

Jump to solution

OK, you haven't included the rootCA in there, so if you have trust issues from endpoints that are trusting that root CA that might be why. Let us know how you go anyway.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Emil_T

Collaborator

‎2025-09-1808:47 AM

In response to emmap

Jump to solution

Thx! I'll let you know.

The root-ca is the internal organizational ca, so to the best of my knowledge, every domain member should trust it.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

the_rock

MVP Diamond

‎2025-09-1803:05 AM

Jump to solution

Maybe it was wrong cert extension?

Best,

Andy

"Have a great day and if its not, change it"

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Emil_T

Collaborator

‎2025-09-1808:49 AM

In response to the_rock

Jump to solution

I'm not sure. I don't believe file extensions really matter when using openssl

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

the_rock

MVP Diamond

‎2025-09-1808:51 AM

In response to Emil_T

Jump to solution

I am fairly sure to import it into smart console, it would have to be .p12 extension, but I could be mistaken.

Andy

Best,

Andy

"Have a great day and if its not, change it"

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Emil_T

Collaborator

‎2025-09-1808:54 AM

In response to the_rock

Jump to solution

You are correct. Smart console only looking for p12 file. That's why there is a rename extension step in the workaround I guess.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

the_rock

MVP Diamond

‎2025-09-1808:49 AM

Jump to solution

So, on step 6, since you said thats where it faisl it only gives that error unable to load certificate?

Andy

Best,

Andy

"Have a great day and if its not, change it"

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Emil_T

Collaborator

‎2025-09-1808:52 AM

In response to the_rock

Jump to solution

Correct. And seems like I'm not the only one. But with the workaround everything seems to be working. I already made some test and the endpoint can see the certificate that the firewall issues and it is trusted as the root-ca is a trusted CA of the endpoint

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

the_rock

MVP Diamond

‎2025-09-1808:55 AM

In response to Emil_T

Jump to solution

Well, as long as all the relevant certs are included in truster root store on user's PC, then you are good.

I made post about this as well.

Andy

https://community.checkpoint.com/t5/Security-Gateways/Https-inspection-tip/m-p/219139

Best,

Andy

"Have a great day and if its not, change it"

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Post Reply

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

User Count

israelfds95
13

HeikoAnkenbrand
7

simonemantovani
5

emmap
3

Steffen_Appel
2

Kaspars_Zibarts
1

Alex-
1

Danny
1

Bob_Zimmerman
1

DH
1

View All ≫

Trending Discussions

Five Habits That Improved My Check Point Deployments

Automatically Renew VPN Certificates

Snapshot and /boot disk space full

Upcoming Events

Sort by:

Virtual

Tue 28 Jul 2026 @ 11:00 AM (EDT)

Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats

Virtual

Wed 29 Jul 2026 @ 12:00 PM (SGT)

The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT

Virtual

Wed 29 Jul 2026 @ 02:00 PM (IDT)

The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER

Virtual

Wed 29 Jul 2026 @ 03:00 PM (CEST)

The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA

Virtual

Wed 29 Jul 2026 @ 11:00 AM (EDT)

TechTalk: On-Premise SD-WAN Management

Thu 30 Jul 2026 @ 11:30 AM (CDT)

CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On

Virtual

Tue 28 Jul 2026 @ 11:00 AM (EDT)

Virtual

Wed 29 Jul 2026 @ 12:00 PM (SGT)

Virtual

Wed 29 Jul 2026 @ 02:00 PM (IDT)

Virtual

Wed 29 Jul 2026 @ 03:00 PM (CEST)

Virtual

Wed 29 Jul 2026 @ 11:00 AM (EDT)

TechTalk: On-Premise SD-WAN Management

Virtual

Thu 30 Jul 2026 @ 10:00 AM (PDT)

AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway

In-Person

Tue 11 Aug 2026 @ 11:30 AM (EDT)

New York City: Agentic AI Security Deep Dive & Hands-On

In-Person

Thu 13 Aug 2026 @ 11:30 AM (EDT)

Waltham, MA: Agentic AI Security Deep Dive & Hands-On

In-Person

Thu 20 Aug 2026 @ 08:30 AM (COT)

Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA

In-Person

Thu 20 Aug 2026 @ 06:00 PM (COT)

Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad

In-Person

Thu 27 Aug 2026 @ 09:00 AM (CEST)

Check Point Hands-On SASE and Cloud Workshop - Zurich

In-Person

Wed 21 Oct 2026 @ 09:00 AM (BST)

AI Security Workshop - Glasgow

CheckMates Events

Top

About CheckMates

Learn Check Point

Advanced Learning

Resources

Non-English Discussions

YOU DESERVE THE BEST SECURITY

We’re Social. Follow Us CheckMates on LinkedIn Check Point on YouTube CheckMates on Facebook CheckMates on Instagram

©1994-2026 Check Point Software Technologies Ltd. All rights reserved. Copyright Privacy Policy About Us UserCenter

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.