> Source: [sk108191](https://support.checkpoint.com/results/sk/sk108191)

# sk108191 - Login failures for Apple devices when HTTPS Inspection is enabled on the Security Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk108191 |
| Date Created | 2016-02-18 |
| Last Modified | 2021-10-25 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * After an Apple device is upgraded to iOS 9, it is no longer able to access Apple services and resources (Xcode, iCloud,or software upgrade using iTunes App Store) when HTTPS Inspection is enabled on the Security Gateway. **Note**: This behavior is also observed when bypassing HTTPS Inspection.
* SmartView Tracker logs shows: `Certificate Chain is not signed by a Trusted CA. Certificate DN: 'C=US,O=Apple Inc.,OU=IS&T,CN=gsa.apple.com' Requested Server Name: gsa.apple.com.`

## Cause

Newer authentication which uses Apple Root CA is not included in the Security Gateway's HTTPS Inspection Trusted CAs.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
