sk172188 - Public Cloud CA Bundle for Cloud Firewall Release Updates

Public Cloud CA Bundle for Cloud Firewall Release Updates

Product: Cloud Firewall
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
OS: Gaia
Last Modified: 2026-03-29

Solution

Introduction | Prerequisites | Availability | Manual Installation | Installation Troubleshooting | List of Resolved Issues

Introduction

Public Cloud CA for Cloud Firewall (formerly known as CloudGuard) Bundle contains certificates of root certificate authorities that are used to sign the public keys of the API servers of public cloud providers.

The certificates allow API clients in Check Point solutions to validate the authenticity of API servers of cloud platforms such as AWS (Amazon Web Services), Azure, GCP (Google Cloud Platform), and more.

You can install public Cloud CA Bundle on Security Management Server, Multi-Domain Management Server, Security Gateways, Standalone deployed in cloud platforms or on-premises machines.

Important: It is essential to keep Public Cloud CA Bundle up to date with Automatic Updates.

The Public Cloud CA package is installed automatically on all relevant Check Point devices when Automatic Update downloads are enabled (see sk175504, section 2-B).

If Automatic Updates are disabled, you must first manually install the latest AutoUpdater Take and then install the Public Cloud CA package manually using the steps below, in the Manual Installation section.

Prerequisites

Public Cloud CA Bundle requires Jumbo Hotfix Accumulator installed with the minimum version:

Version Required
R81.10 and higher It is not required to install Jumbo Hotfix Accumulator
R81 R81 Jumbo Hotfix Accumulator Take 45
R80.40 R80.40 Jumbo Hotfix Accumulator Take 132
R80.30 R80.30 Jumbo Hotfix Accumulator Take 241
R80.30 Security Gateway Gaia 3.10 R80.30 Jumbo Hotfix Accumulator Take 241
R80.20 R80.20 Jumbo Hotfix Accumulator Take 204
R80.20 Security Gateway Gaia 3.10 R80.20 Jumbo Hotfix Accumulator with Gaia 3.10 Take 44

Availability

Take # Release Date Offload Package Link
Recommended Take Take 21 30 Jun 2024 (TAR)

Manual Installation (Offline)

Instructions:

  1. Log in to the Check Point machine via SSH.

  2. Transfer the offline package to the machine.

  3. From Expert mode, run:

    autoupdatercli install <FULL PATH TO PUBLIC CLOUD CA BUNDLE PACKAGE>.tar

Example: autoupdatercli install /home/admin/_Check_Point_ PUBLIC CLOUD CA BUNDLE _AUTOUPDATE_Bundle_T14_AutoUpdate.tar

On the Scalable Platform Security Group:
g_all autoupdatercli install <full path to TAR file>
4. Validate the installation passed successfully by checking the /opt/CPInstLog/AutoUpdateLogs/public_cloud_ca_bundle log.

Installation Troubleshooting

These issues can arise when running the installation package:

If your issue is not resolved by one of the above solutions, contact Check Point Support and attach the log files from /opt/CPInstLog/AutoUpdateLogs/PUBLIC_CLOUD_CA_BUNDLE

List of Resolved Issues and New Features per Public Cloud CA Bundle Update

ID Description
Take 21 (30 Jun 2024)
VSECPC-7604 Enhancement: Removed expired Google Cloud Platform (GCP) certificates from the ca_bundle_public_cloud.crt file.
Note: Adding permissions for others to access this file does not reduce security confidence. This is because the public-cloud folder contains only CA bundles with public certificates, which are not considered sensitive data.
Take 20 (24 Jul 2023)
VSECPC-6785 Enhancement: PUBLIC_CLOUD_CA_BUNDLE DDR conditions-set now blocks installation on Maestro machines.
Take 19 (06 Sep 2022)
PMTR-85947 Enhancement: Added support for Log Server.
Take 18 (20 Mar 2022)
VSECPC-5597 Enhancement: Added a new Azure certificate for the Storage service.
Take 14 (09 Feb 2022)
- First release of Public Cloud CA Bundle Update.