sk184273 - HTTPS Connections from Python scripts, CI/CD pipelines, and the OpenSSL command-line tool to the Security Gateway fail
HTTPS Connections from Python scripts, CI/CD pipelines, and the OpenSSL command-line tool to the Security Gateway fail
Product
Security Gateways
Version
R81.20, R82, R82.10
Last Modified
2026-06-02
Symptoms
- Connections from Python scripts, CI/CD pipelines, or the OpenSSL command-line tool to the Security Gateway fail with error: " verify error:num=85:Missing Authority Key Identifier".
- Although the CA chain includes the Authority Key Identifier (AKI), it is missing from certificates generated by the Security Gateway for SSL inspection.
Cause
The Security Gateway's HTTPS Inspection feature generated certificates without the X509v3 AKI extension. Modern Python libraries and OpenSSL enforce strict RFC5280 compliance, which requires the AKI for proper validation. The missing AKI extension caused certificate verification failures and disrupted business-critical automation CI/CD pipelines.
Solution
Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
For faster resolution and verification, collect these files:
- CPinfo file from the Management Server involved in the case.
- CPinfo file from the Security Gateway / each Cluster Member / Security Group involved in the case.
Hotfix installation instructions: Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2025-11-11
Last Modified: 2026-06-02