sk172188 - Public Cloud CA Bundle for Cloud Firewall Release Updates
Public Cloud CA Bundle for Cloud Firewall Release Updates
Product: Cloud Firewall
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
OS: Gaia
Last Modified: 2026-03-29
Solution
Introduction | Prerequisites | Availability | Manual Installation | Installation Troubleshooting | List of Resolved Issues
Introduction
Public Cloud CA for Cloud Firewall (formerly known as CloudGuard) Bundle contains certificates of root certificate authorities that are used to sign the public keys of the API servers of public cloud providers.
The certificates allow API clients in Check Point solutions to validate the authenticity of API servers of cloud platforms such as AWS (Amazon Web Services), Azure, GCP (Google Cloud Platform), and more.
You can install public Cloud CA Bundle on Security Management Server, Multi-Domain Management Server, Security Gateways, Standalone deployed in cloud platforms or on-premises machines.
Important: It is essential to keep Public Cloud CA Bundle up to date with Automatic Updates.
The Public Cloud CA package is installed automatically on all relevant Check Point devices when Automatic Update downloads are enabled (see sk175504, section 2-B).
If Automatic Updates are disabled, you must first manually install the latest AutoUpdater Take and then install the Public Cloud CA package manually using the steps below, in the Manual Installation section.
Prerequisites
Public Cloud CA Bundle requires Jumbo Hotfix Accumulator installed with the minimum version:
| Version | Required |
| R81.10 and higher | It is not required to install Jumbo Hotfix Accumulator |
| R81 | R81 Jumbo Hotfix Accumulator Take 45 |
| R80.40 | R80.40 Jumbo Hotfix Accumulator Take 132 |
| R80.30 | R80.30 Jumbo Hotfix Accumulator Take 241 |
| R80.30 Security Gateway Gaia 3.10 | R80.30 Jumbo Hotfix Accumulator Take 241 |
| R80.20 | R80.20 Jumbo Hotfix Accumulator Take 204 |
| R80.20 Security Gateway Gaia 3.10 | R80.20 Jumbo Hotfix Accumulator with Gaia 3.10 Take 44 |
Availability
| Take # | Release Date | Offload Package Link | |
|---|---|---|---|
| Recommended Take | Take 21 | 30 Jun 2024 | (TAR) |
Manual Installation (Offline)
Instructions:
Log in to the Check Point machine via SSH.
Transfer the offline package to the machine.
From Expert mode, run:
autoupdatercli install <FULL PATH TO PUBLIC CLOUD CA BUNDLE PACKAGE>.tar
Example: autoupdatercli install /home/admin/_Check_Point_ PUBLIC CLOUD CA BUNDLE _AUTOUPDATE_Bundle_T14_AutoUpdate.tar
On the Scalable Platform Security Group:
g_all autoupdatercli install <full path to TAR file>
4. Validate the installation passed successfully by checking the /opt/CPInstLog/AutoUpdateLogs/public_cloud_ca_bundle log.
Installation Troubleshooting
These issues can arise when running the installation package:
Issue 1: "Failed to download latest Public Cloud CA Bundle."
-- Solution: If you have no internet access, follow the instructions for "Offline Package Installation Procedure" in the Installation Instructions section above.Issue 2: "A version of Public Cloud CA bundle is already installed via AutoUpdater"
-- Solution: Public Cloud CA Bundle has already been installed for the first time and is configured to receive updates automatically. If you have no internet access, follow the instructions for "Offline Package Installation Procedure" in the Installation Instructions section above.Issue 3: You want to return to the previous version of the Public Cloud CA bundle
-- Solution: It is highly recommended that you use the latest take of Public Cloud CA bundle.
If you still want to revert to the previous take, run the following command in Expert mode:autoupdatercli revert public_cloud_ca_bundleThe revert takes up to 1 minute. To make sure Public Cloud CA Bundle was reverted to the previous take, run this command in the Expert mode:
cpinfo -y CPUpdates 2>&1 | grep PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATEThe take number in the output must be the one to which you reverted. Notes:
- Public Cloud CA Bundle is upgraded automatically each time a new take is released.
- You can revert only to the previous version. A revert to older versions reverts Public Cloud CA Bundle completely and removes it from the machine.
Issue 4: You want to totally remove Public Cloud CA bundle
-- Solution: Run the following command in Expert mode:autoupdatercli revert-completely public_cloud_ca_bundleThe revert takes up to 1 minute.
To make sure Public Cloud CA Bundle was reverted completely, run this command in the Expert mode:cpinfo -y CPUpdates 2>&1 | grep PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATEIf you also wish to stop receiving future updates of Public Cloud CA Bundle after the removal, run the following command in Expert mode:
autoupdatercli disable public_cloud_ca_bundleThe output must show "0".
If your issue is not resolved by one of the above solutions, contact Check Point Support and attach the log files from /opt/CPInstLog/AutoUpdateLogs/PUBLIC_CLOUD_CA_BUNDLE
List of Resolved Issues and New Features per Public Cloud CA Bundle Update
| ID | Description |
| Take 21 (30 Jun 2024) | |
| VSECPC-7604 | Enhancement: Removed expired Google Cloud Platform (GCP) certificates from the ca_bundle_public_cloud.crt file. Note: Adding permissions for others to access this file does not reduce security confidence. This is because the public-cloud folder contains only CA bundles with public certificates, which are not considered sensitive data. |
| Take 20 (24 Jul 2023) | |
| VSECPC-6785 | Enhancement: PUBLIC_CLOUD_CA_BUNDLE DDR conditions-set now blocks installation on Maestro machines. |
| Take 19 (06 Sep 2022) | |
| PMTR-85947 | Enhancement: Added support for Log Server. |
| Take 18 (20 Mar 2022) | |
| VSECPC-5597 | Enhancement: Added a new Azure certificate for the Storage service. |
| Take 14 (09 Feb 2022) | |
| - | First release of Public Cloud CA Bundle Update. |