sk184273 - HTTPS Connections from Python scripts, CI/CD pipelines, and the OpenSSL command-line tool to the Security Gateway fail

HTTPS Connections from Python scripts, CI/CD pipelines, and the OpenSSL command-line tool to the Security Gateway fail

Product

Security Gateways

Version

R81.20, R82, R82.10

Last Modified

2026-06-02

Symptoms

Cause

The Security Gateway's HTTPS Inspection feature generated certificates without the X509v3 AKI extension. Modern Python libraries and OpenSSL enforce strict RFC5280 compliance, which requires the AKI for proper validation. The missing AKI extension caused certificate verification failures and disrupted business-critical automation CI/CD pipelines.

Solution

Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
For faster resolution and verification, collect these files:

  1. CPinfo file from the Management Server involved in the case.
  2. CPinfo file from the Security Gateway / each Cluster Member / Security Group involved in the case.

Hotfix installation instructions: Refer to sk168597 - How to install a Hotfix.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2025-11-11
Last Modified: 2026-06-02