Solved: Reverting back to self-signed certificate for HTTP... - Check Point CheckMates

Reverting back to self-signed certificate for HTTPS Inspection

Hello all,

Thank you for taking time to read this.  I performed the following on an R80.40 install:

However, HTTPS Inspection failed because I used a server certificate, instead of a CA certificate.  So now, I want to revert back to using the self-signed certificate which does generate a CA certificate, but this option is no longer available.  From the SmartConsole -> Gateways & Servers -> Gateway Object -> HTTPS Inspection window, I can only view or export the existing certificate:

From Security Policies ->HTTPS Inspection -> HTTPS Tools -> Additional Settings (SmartDashboard) -> HTTPS Inspection -> Gateways , the only option is to Renew or Import:

I've tried disabling HTTPS Inspection, but that did not help either.  I've also opened a  ticket with CheckPoint and they recommended restoring from backup which unfortunately I do not have or performing a fresh install.  They also recommended engaging Professional services.

Before I go this route has anybody encountered this issue or have a recommendation on how to generate the self-signed CA certificate?

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

1 Solution

Accepted Solutions

cpuser1

Participant

‎2021-09-1612:30 PM

Show option menu

In response to mcatanzaro

Jump to solution

TAC has not responded whether the above solution is appropriate or not, but I found the "easier" solution.  The renew certificate button in the SmartDashboard is meant for the self-signed certificate that was initially created when HTTPS Inspection was activated.

Once you renew the certificate, you can immediately export this certificate from the SmartDashboard, even without pushing a policy.

After you push the policy, do not export the certificate from the SmartConsole.  The SmartConsole will export the old certificate.  What you have to do is close the SmartConsole and relaunch it.  After relaunch, the export from the SmartConsole is the correct, current certificate.

This may be a bug or maybe it's by design -- I'm not sure, but that's how you revert back to the self-signed certificate from a third party certificate.

View solution in original post

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

7 Replies

mcatanzaro

Employee

‎2021-09-1007:53 PM

Jump to solution

I’d have to check this one out in my lab to see if there is a way to clear out the external certificate.

Do you have a private CA in your environment? The self-signed cert doesn’t have to be the one you generated on the gateway.

I’ve seen a number of deployments where customers who use ADCS will use the same root CA that was used for 802.1x etc. since it is already deployed to their endpoints.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

cpuser1

Participant

‎2021-09-1008:11 PM

In response to mcatanzaro

Jump to solution

Hi mcatanzaro,

Thanks for responding.

No, we don't have a private CA in our environment.  If I understand correctly

That sounds doable and I actually tried something similar on the gateway, but I am not sure how to set up the CA:

cpopenssl ca -startdate 2109100000000 -enddate 2909090000000 -in fw_cert.csr -out fw_cert.crt -config $CPDIR/conf/openssl.cnf

Using configuration from /opt/CPshrd-R80.30/conf/openssl.cnf

Error opening CA private key ./demoCA/private/cakey.pem

4158678668:error:02001002:system library:fopen:No such file or directory:bss_file.c:413:fopen('./demoCA/private/cakey.pem','r')

4158678668:error:20074002:BIO routines:FILE_CTRL:system lib:bss_file.c:415:

unable to load CA private key

I'm actually reading up on how to set up the CA.  Would it be okay to do this on the gateway?

1\ \ \ Kudo

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

mcatanzaro

Employee

‎2021-09-1010:47 PM

In response to cpuser1

Jump to solution

Sounds like you have done your research.

Regarding the question of using cpopenssl to accomplish this, in my mind I don’t see why it wouldn’t work since it is a port of openssl.

However, I would pose this solution in your TAC case so we can verify the proper syntax and level of support from the appropriate internal resources.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

cpuser1

Participant

‎2021-09-1010:53 PM

In response to mcatanzaro

Jump to solution

Hi mcatanzaro,

This is what worked for me:

Import .p12 certificate in SmartDashboard -> HTTPS Inspection -> CA Certificate

More detailed:

# Create CA directories and files. With Trail and Error and looking at the openssl.cnf file, these are the directories/files needed

mkdir ca_certificate

cd ca_certificate

mkdir demoCA

cd demoCA

mkdir {certs,crl,newcerts,private,crl,conf}

touch {index.txt,serial}

# Serial numbers are in hex and here we are starting with 1

echo "01" > serial

# Create private key for CA

cpopenssl genrsa -aes256 -out private/cakey.pem 4096

# Copy CheckPoint openssl configuration file to local configuration directory

cp $CPDIR/conf/openssl.cnf conf/

# Modify openssl.cnf

- In the [ req_distinguished_name ] section, change the default values to your appropriate environment

- In the [ usr_cert ] section, change the value for basicConstraint from FALSE to TRUE

# Create a certificate for this local CA

cpopenssl req -new -x509 -days 3650 -key private/cakey.pem -out cacert.pem -config config/openssl.cnf

# Generate a CSR on active gateway

cpopenssl req -new -newkey rsa:4096 -sha256 -out gw.csr -keyout gw.key -config

# Sign the CSR

cpopenssl ca -startdate 210910000000Z -enddate 290909000000Z -in gw.csr -out gw.crt -config conf/openssl.cnf

# Deploy certificate to end host

# Export the signed certificate in .p12 format

cpopenssl pkcs12 -export -out gw.p12 -in gw.crt -inkey gw.key

# Import the .p12 certificate from the SmartDashboard -> HTTPS Inspection -> CA certificate

# Push the policy

I submitted the above steps to the TAC.  I probably won't here back until Monday, but it seems to work so far.  Still testing...

1\ \ \ Kudo

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

mcatanzaro

Employee

‎2021-09-1011:13 PM

In response to cpuser1

Jump to solution

Great to hear and good job.

Report back TAC’s findings from the case here or message me with them.

Would be nice to have this process documented if the product owners say it is supported.

1\ \ \ Kudo

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

cpuser1

Participant

‎2021-09-1612:30 PM

Jump to solution

Once you renew the certificate, you can immediately export this certificate from the SmartDashboard, even without pushing a policy.

This may be a bug or maybe it's by design -- I'm not sure, but that's how you revert back to the self-signed certificate from a third party certificate.

0

Kudos

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

_Val_

Admin

‎2021-09-1712:32 AM

In response to cpuser1

Jump to solution

Most probably SmartConsole cache issue.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Post Reply

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

User Count

israelfds95
13

HeikoAnkenbrand
7

simonemantovani
5

emmap
3

Steffen_Appel
2

Kaspars_Zibarts
1

Alex-
1

Danny
1

Bob_Zimmerman
1

DH
1

View All ≫

Trending Discussions

Five Habits That Improved My Check Point Deployments

Automatically Renew VPN Certificates

Snapshot and /boot disk space full

Upcoming Events

Sort by:

Virtual

Tue 28 Jul 2026 @ 11:00 AM (EDT)

Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats

Virtual

Wed 29 Jul 2026 @ 12:00 PM (SGT)

The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT

Virtual

Wed 29 Jul 2026 @ 02:00 PM (IDT)

The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER

Virtual

Wed 29 Jul 2026 @ 03:00 PM (CEST)

The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA

Virtual

Wed 29 Jul 2026 @ 11:00 AM (EDT)

TechTalk: On-Premise SD-WAN Management

Thu 30 Jul 2026 @ 11:30 AM (CDT)

CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On

Virtual

Tue 28 Jul 2026 @ 11:00 AM (EDT)

Virtual

Wed 29 Jul 2026 @ 12:00 PM (SGT)

Virtual

Wed 29 Jul 2026 @ 02:00 PM (IDT)

Virtual

Wed 29 Jul 2026 @ 03:00 PM (CEST)

Virtual

Wed 29 Jul 2026 @ 11:00 AM (EDT)

TechTalk: On-Premise SD-WAN Management

Virtual

Thu 30 Jul 2026 @ 10:00 AM (PDT)

AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway

In-Person

Tue 11 Aug 2026 @ 11:30 AM (EDT)

New York City: Agentic AI Security Deep Dive & Hands-On

In-Person

Thu 13 Aug 2026 @ 11:30 AM (EDT)

Waltham, MA: Agentic AI Security Deep Dive & Hands-On

In-Person

Thu 20 Aug 2026 @ 08:30 AM (COT)

Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA

In-Person

Thu 20 Aug 2026 @ 06:00 PM (COT)

Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad

In-Person

Thu 27 Aug 2026 @ 09:00 AM (CEST)

Check Point Hands-On SASE and Cloud Workshop - Zurich

In-Person

Wed 21 Oct 2026 @ 09:00 AM (BST)

AI Security Workshop - Glasgow

CheckMates Events

Top

About CheckMates

Learn Check Point

Advanced Learning

Resources

Non-English Discussions

YOU DESERVE THE BEST SECURITY

We’re Social. Follow Us CheckMates on LinkedIn Check Point on YouTube CheckMates on Facebook CheckMates on Instagram

©1994-2026 Check Point Software Technologies Ltd. All rights reserved. Copyright Privacy Policy About Us UserCenter

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.