> Source: [sk103885](https://support.checkpoint.com/results/sk/sk103885)

# sk103885 - How to change the certificate presented by Security Gateway to Remote Access clients

| Property | Value |
|----------|-------|
| Solution ID | sk103885 |
| Date Created | 2014-12-24 |
| Last Modified | 2025-04-14 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS) |

## Solution

**Note: There is limitation for macOS Remote Access clients when using 3rd party CA with more than two certificates in a chain. On initial connect, they show only the Fingerprint of the certificate next to the Peer certificate in a chain. For example, in case of 3 certificates in a chain: CA , SubCA and Peer, the SubCA's fingerprint will be shown.**   

By design, if there are at least two certificates including the ICA certificate in IPsec repository, Security Gateway presents the ICA certificate, even though a 3rd party certificate exists in IPsec repository.

Follow these steps to configure the Security Gateway to present a 3rd party certificate to Remote Access clients:

1. Connect with SmartDashboard to Security Management Server / Domain Management Server.   

2. Open the object of relevant Security Gateway.   

3. Click on '`VPN Clients`' pane.   

4. In the drop-down menu "*This gateway authenticates with this certificate* ", select the required certificate.
   * **Note: The 3rd party certificate will also be used as the default certificate for multi-portals with this configuration.**
5. Remove the ICA issued certificate from the IPsec repository.  

6. Click on OK.   

7. Install policy on this Security Gateway.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
