Solved: HTTPS inspection - Create a CSR for an external CA... - Check Point CheckMates
HTTPS inspection - Create a CSR for an external CA to use for the outbound certificate
How can I create a new CSR (Certificate Signing Request) for outbound certificate for external CA ? The CA is a windows CA server.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
1 Solution
Accepted Solutions
MVP Gold CHKP
2025-09-1606:45 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have it documented here: https://support.checkpoint.com/results/sk/sk165856
View solution in original post
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
15 Replies
MVP Diamond
2025-09-1605:54 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not sure if below steps make 100% sense, but looks okay to me.
Andy
\\\****************
1. Decide Where to Generate the CSR
You can generate the CSR either:
On the Check Point Security Gateway / Management Server (Gaia CLI or SmartConsole)
Externally (Windows/Linux) and then import the signed certificate + private key
Best practice: generate the CSR directly on the Check Point box where the private key will be used, so the key never leaves the device.
2. Generate CSR in Gaia Portal (Easiest)
Log into the Gaia Portal (https://<mgmt_or_gateway_IP>).
Go to:
Device > Certificates > Outgoing Certificates
Click Add > Create Certificate Signing Request (CSR).
Fill in the fields:
- CN (Common Name): typically the FQDN used for outbound TLS (e.g., proxy.company.com)
O (Organization), OU, L, ST, C as required by your CA policy
Key length: 2048 or 3072 bits (depending on your CA requirements)
Save/Generate → This will create a
.csrfile.Download the CSR file.
3. Submit CSR to Windows CA
On your Windows CA server:
Open Certification Authority MMC.
Right-click the CA → All Tasks → Submit new request.
Or, if using web enrollment, open:
http://<CAserver>/certsrv → Request a certificate → Advanced certificate request → Submit CSR.
Choose the correct certificate template (e.g., Web Server, Subordinate CA, etc., depending on usage).
Submit and download the signed certificate (usually
.ceror.p7b).
4. Import Signed Certificate Back into Gaia
Go back to Gaia Portal → Device → Certificates → Outgoing Certificates.
Select your pending CSR request.
Click Import Certificate and upload the
.cer(or export from CA as Base64 if needed).Once imported, the status will change to Valid.
5. (Optional) CLI Method
If you prefer CLI:
# Create a new private key and CSR openssl req -new -newkey rsa:2048 -nodes -keyout outbound.key -out outbound.csr
Transfer the
.csrto your Windows CA, sign it, then bring the.cerback.Import both
.keyand.cerinto Check Point withcpca_clientor via Gaia Portal.
Best,
Andy
"Have a great day and if its not, change it"
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Collaborator
2025-09-1711:39 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
There is no such menu in Gaia GUI: Device > Certificates > Outgoing Certificates
I will try what emmap suggested
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
MVP Diamond
2025-09-1711:42 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fair enough, its an official CP documentation anyway.
Andy
Best,
Andy
"Have a great day and if its not, change it"
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
MVP Gold CHKP
2025-09-1606:45 PM
We have it documented here: https://support.checkpoint.com/results/sk/sk165856
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
MVP Diamond
2025-09-1606:49 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Perfect, even better!
Andy
Best,
Andy
"Have a great day and if its not, change it"
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Collaborator
2025-09-1710:01 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I followed sk165856, But instead of step 6 i used the method below (since step 6 failed and generated this error: unable to load certificates
-Run "cpopenssl pkcs12 -export -in inspection-ca.cer -inkey inspection-key.pem -out inspection.pfx"
-After got the certificate in .pfx format, rename it to .p12 format
-Import to smart console.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
MVP Gold CHKP
2025-09-1801:01 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
OK, you haven't included the rootCA in there, so if you have trust issues from endpoints that are trusting that root CA that might be why. Let us know how you go anyway.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Collaborator
2025-09-1808:47 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thx! I'll let you know.
The root-ca is the internal organizational ca, so to the best of my knowledge, every domain member should trust it.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
MVP Diamond
2025-09-1803:05 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Maybe it was wrong cert extension?
Best,
Andy
"Have a great day and if its not, change it"
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Collaborator
2025-09-1808:49 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm not sure. I don't believe file extensions really matter when using openssl
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
MVP Diamond
2025-09-1808:51 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am fairly sure to import it into smart console, it would have to be .p12 extension, but I could be mistaken.
Andy
Best,
Andy
"Have a great day and if its not, change it"
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Collaborator
2025-09-1808:54 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You are correct. Smart console only looking for p12 file. That's why there is a rename extension step in the workaround I guess.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
MVP Diamond
2025-09-1808:49 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So, on step 6, since you said thats where it faisl it only gives that error unable to load certificate?
Andy
Best,
Andy
"Have a great day and if its not, change it"
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Collaborator
2025-09-1808:52 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Correct. And seems like I'm not the only one. But with the workaround everything seems to be working. I already made some test and the endpoint can see the certificate that the firewall issues and it is trusted as the root-ca is a trusted CA of the endpoint
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
MVP Diamond
2025-09-1808:55 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Well, as long as all the relevant certs are included in truster root store on user's PC, then you are good.
I made post about this as well.
Andy
https://community.checkpoint.com/t5/Security-Gateways/Https-inspection-tip/m-p/219139
Best,
Andy
"Have a great day and if its not, change it"
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Post Reply
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
israelfds95 |
13 |
HeikoAnkenbrand |
7 |
simonemantovani |
5 |
emmap |
3 |
Steffen_Appel |
2 |
Kaspars_Zibarts |
1 |
Alex- |
1 |
Danny |
1 |
Bob_Zimmerman |
1 |
DH |
1 |
Trending Discussions
Five Habits That Improved My Check Point Deployments
Automatically Renew VPN Certificates
Snapshot and /boot disk space full
Upcoming Events
Sort by:
Tue 28 Jul 2026 @ 11:00 AM (EDT)
Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats
Wed 29 Jul 2026 @ 12:00 PM (SGT)
The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT
Wed 29 Jul 2026 @ 02:00 PM (IDT)
The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER
Wed 29 Jul 2026 @ 03:00 PM (CEST)
The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA
Wed 29 Jul 2026 @ 11:00 AM (EDT)
TechTalk: On-Premise SD-WAN Management
Thu 30 Jul 2026 @ 11:30 AM (CDT)
CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On
Tue 28 Jul 2026 @ 11:00 AM (EDT)
Wed 29 Jul 2026 @ 12:00 PM (SGT)
Wed 29 Jul 2026 @ 02:00 PM (IDT)
Wed 29 Jul 2026 @ 03:00 PM (CEST)
Wed 29 Jul 2026 @ 11:00 AM (EDT)
TechTalk: On-Premise SD-WAN Management
Thu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway
Tue 11 Aug 2026 @ 11:30 AM (EDT)
New York City: Agentic AI Security Deep Dive & Hands-On
Thu 13 Aug 2026 @ 11:30 AM (EDT)
Waltham, MA: Agentic AI Security Deep Dive & Hands-On
Thu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA
Thu 20 Aug 2026 @ 06:00 PM (COT)
Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad
Thu 27 Aug 2026 @ 09:00 AM (CEST)
Check Point Hands-On SASE and Cloud Workshop - Zurich
Wed 21 Oct 2026 @ 09:00 AM (BST)
AI Security Workshop - Glasgow
About CheckMates
Learn Check Point
Advanced Learning
Resources
Non-English Discussions
YOU DESERVE THE BEST SECURITY
We’re Social. Follow Us CheckMates on LinkedIn Check Point on YouTube CheckMates on Facebook CheckMates on Instagram
©1994-2026 Check Point Software Technologies Ltd. All rights reserved. Copyright Privacy Policy About Us UserCenter
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.