Solved: Reverting back to self-signed certificate for HTTP... - Check Point CheckMates
Reverting back to self-signed certificate for HTTPS Inspection
Hello all,
Thank you for taking time to read this. I performed the following on an R80.40 install:
- Enabled the HTTPS Inspection blade
- Generated a CSR, had a third-party sign the CSR,
- Installed the signed certificate
However, HTTPS Inspection failed because I used a server certificate, instead of a CA certificate. So now, I want to revert back to using the self-signed certificate which does generate a CA certificate, but this option is no longer available. From the SmartConsole -> Gateways & Servers -> Gateway Object -> HTTPS Inspection window, I can only view or export the existing certificate:
From Security Policies ->HTTPS Inspection -> HTTPS Tools -> Additional Settings (SmartDashboard) -> HTTPS Inspection -> Gateways , the only option is to Renew or Import:
I've tried disabling HTTPS Inspection, but that did not help either. I've also opened a ticket with CheckPoint and they recommended restoring from backup which unfortunately I do not have or performing a fresh install. They also recommended engaging Professional services.
Before I go this route has anybody encountered this issue or have a recommendation on how to generate the self-signed CA certificate?
Tags:
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
1 Solution
Accepted Solutions
Participant
2021-09-1612:30 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
TAC has not responded whether the above solution is appropriate or not, but I found the "easier" solution. The renew certificate button in the SmartDashboard is meant for the self-signed certificate that was initially created when HTTPS Inspection was activated.
Once you renew the certificate, you can immediately export this certificate from the SmartDashboard, even without pushing a policy.
After you push the policy, do not export the certificate from the SmartConsole. The SmartConsole will export the old certificate. What you have to do is close the SmartConsole and relaunch it. After relaunch, the export from the SmartConsole is the correct, current certificate.
This may be a bug or maybe it's by design -- I'm not sure, but that's how you revert back to the self-signed certificate from a third party certificate.
View solution in original post
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
7 Replies
Employee
2021-09-1007:53 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I’d have to check this one out in my lab to see if there is a way to clear out the external certificate.
Do you have a private CA in your environment? The self-signed cert doesn’t have to be the one you generated on the gateway.
I’ve seen a number of deployments where customers who use ADCS will use the same root CA that was used for 802.1x etc. since it is already deployed to their endpoints.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Participant
2021-09-1008:11 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi mcatanzaro,
Thanks for responding.
No, we don't have a private CA in our environment. If I understand correctly
- I can generate the self-sign on say, a linux box
- Create a private CA, sign the CSR
- Convert signed-certificate to .p12
- Import the .p12 file
That sounds doable and I actually tried something similar on the gateway, but I am not sure how to set up the CA:
cpopenssl ca -startdate 2109100000000 -enddate 2909090000000 -in fw_cert.csr -out fw_cert.crt -config $CPDIR/conf/openssl.cnf
Using configuration from /opt/CPshrd-R80.30/conf/openssl.cnf
Error opening CA private key ./demoCA/private/cakey.pem
4158678668:error:02001002:system library:fopen:No such file or directory:bss_file.c:413:fopen('./demoCA/private/cakey.pem','r')
4158678668:error:20074002:BIO routines:FILE_CTRL:system lib:bss_file.c:415:
unable to load CA private key
I'm actually reading up on how to set up the CA. Would it be okay to do this on the gateway?
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Employee
2021-09-1010:47 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sounds like you have done your research.
Regarding the question of using cpopenssl to accomplish this, in my mind I don’t see why it wouldn’t work since it is a port of openssl.
However, I would pose this solution in your TAC case so we can verify the proper syntax and level of support from the appropriate internal resources.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Participant
2021-09-1010:53 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi mcatanzaro,
This is what worked for me:
- Configure the active gateway to be a CA
- Sign the CSR
- Deploy signed certificate to end host
- Export signed certificate in .p12 format
Import .p12 certificate in SmartDashboard -> HTTPS Inspection -> CA Certificate
More detailed:
# Create CA directories and files. With Trail and Error and looking at the openssl.cnf file, these are the directories/files needed
mkdir ca_certificate
cd ca_certificate
mkdir demoCA
cd demoCA
mkdir {certs,crl,newcerts,private,crl,conf}
touch {index.txt,serial}
# Serial numbers are in hex and here we are starting with 1
echo "01" > serial
# Create private key for CA
cpopenssl genrsa -aes256 -out private/cakey.pem 4096
# Copy CheckPoint openssl configuration file to local configuration directory
cp $CPDIR/conf/openssl.cnf conf/
# Modify openssl.cnf
- In the [ req_distinguished_name ] section, change the default values to your appropriate environment
- In the [ usr_cert ] section, change the value for basicConstraint from FALSE to TRUE
# Create a certificate for this local CA
cpopenssl req -new -x509 -days 3650 -key private/cakey.pem -out cacert.pem -config config/openssl.cnf
# Generate a CSR on active gateway
cpopenssl req -new -newkey rsa:4096 -sha256 -out gw.csr -keyout gw.key -config
# Sign the CSR
cpopenssl ca -startdate 210910000000Z -enddate 290909000000Z -in gw.csr -out gw.crt -config conf/openssl.cnf
# Deploy certificate to end host
# Export the signed certificate in .p12 format
cpopenssl pkcs12 -export -out gw.p12 -in gw.crt -inkey gw.key
# Import the .p12 certificate from the SmartDashboard -> HTTPS Inspection -> CA certificate
# Push the policy
I submitted the above steps to the TAC. I probably won't here back until Monday, but it seems to work so far. Still testing...
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Employee
2021-09-1011:13 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Great to hear and good job.
Report back TAC’s findings from the case here or message me with them.
Would be nice to have this process documented if the product owners say it is supported.
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Participant
2021-09-1612:30 PM
Once you renew the certificate, you can immediately export this certificate from the SmartDashboard, even without pushing a policy.
This may be a bug or maybe it's by design -- I'm not sure, but that's how you revert back to the self-signed certificate from a third party certificate.
0
Kudos
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Admin
2021-09-1712:32 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Most probably SmartConsole cache issue.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Post Reply
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
israelfds95 |
13 |
HeikoAnkenbrand |
7 |
simonemantovani |
5 |
emmap |
3 |
Steffen_Appel |
2 |
Kaspars_Zibarts |
1 |
Alex- |
1 |
Danny |
1 |
Bob_Zimmerman |
1 |
DH |
1 |
Trending Discussions
Five Habits That Improved My Check Point Deployments
Automatically Renew VPN Certificates
Snapshot and /boot disk space full
Upcoming Events
Sort by:
Tue 28 Jul 2026 @ 11:00 AM (EDT)
Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats
Wed 29 Jul 2026 @ 12:00 PM (SGT)
The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT
Wed 29 Jul 2026 @ 02:00 PM (IDT)
The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER
Wed 29 Jul 2026 @ 03:00 PM (CEST)
The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA
Wed 29 Jul 2026 @ 11:00 AM (EDT)
TechTalk: On-Premise SD-WAN Management
Thu 30 Jul 2026 @ 11:30 AM (CDT)
CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On
Tue 28 Jul 2026 @ 11:00 AM (EDT)
Wed 29 Jul 2026 @ 12:00 PM (SGT)
Wed 29 Jul 2026 @ 02:00 PM (IDT)
Wed 29 Jul 2026 @ 03:00 PM (CEST)
Wed 29 Jul 2026 @ 11:00 AM (EDT)
TechTalk: On-Premise SD-WAN Management
Thu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway
Tue 11 Aug 2026 @ 11:30 AM (EDT)
New York City: Agentic AI Security Deep Dive & Hands-On
Thu 13 Aug 2026 @ 11:30 AM (EDT)
Waltham, MA: Agentic AI Security Deep Dive & Hands-On
Thu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA
Thu 20 Aug 2026 @ 06:00 PM (COT)
Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad
Thu 27 Aug 2026 @ 09:00 AM (CEST)
Check Point Hands-On SASE and Cloud Workshop - Zurich
Wed 21 Oct 2026 @ 09:00 AM (BST)
AI Security Workshop - Glasgow
About CheckMates
Learn Check Point
Advanced Learning
Resources
Non-English Discussions
YOU DESERVE THE BEST SECURITY
We’re Social. Follow Us CheckMates on LinkedIn Check Point on YouTube CheckMates on Facebook CheckMates on Instagram
©1994-2026 Check Point Software Technologies Ltd. All rights reserved. Copyright Privacy Policy About Us UserCenter
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.