> Source: [sk110533](https://support.checkpoint.com/results/sk/sk110533)

# sk110533 - "The site's security certificate is not trusted" when creating a VPN site in an Endpoint Security VPN client

| Property | Value |
|----------|-------|
| Solution ID | sk110533 |
| Date Created | 2016-03-25 |
| Last Modified | 2026-01-30 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed), Endpoint Security |
| Versions | R82.00.X, R81.10.X, Cloud, E89.X, E88.X |

## Solution

This article describes different scenarios in which a popup message appears that says "`The site's security certificate is not trusted!`" in an Endpoint Security VPN Client.  

<br />

<br />

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk110533/Security Cert Not Trusted (REDACTED)202207111501151.png)

**Table of Contents:**

* Scenario 1 - Creating a VPN Site in an Endpoint Security VPN Client
* Scenario 2 - Creating a New Site for a Remote Access VPN
* Scenario 3 - Creating a New Site in an Endpoint Security VPN with a Wildcard Certificate  

Scenario 1 - Creating a VPN Site in an Endpoint Security VPN Client {#Scenario 1}
---------------------------------------------------------------------------------

### Symptoms

* The popup message that says "*The site's security certificate is not trusted!*" appears when creating a VPN site in a Check Point Endpoint Security VPN client.
* The VPN site does not send 3rd party installed certificates when it identifies itself.

### Root Cause

Two possible causes are:

* The Quantum Spark Appliance always presents its internal VPN certificate when it tries to establish a connection between the client endpoint and the site. The client host does not have this certificate installed.
* The VPN site certificate changed.

### Solution

This is expected behavior.  

To prevent this message from appearing, you can add the certificate to the registry of the endpoint computer before you ask the user to connect to the Security Gateway. For more information, see [sk66263](https://support.checkpoint.com/results/sk/sk66263).  

Locally Managed Quantum Spark (SMB) appliances do not support internal certificate administration. These appliances always present their own VPN certificate, even if there are other certificates installed on the appliances.  

**Note -** You can verify the internal certificate in the appliance WebUI: **Device** \> **Certificates (Internal Certificate)**. This page shows two certificates: Internal CA Certificate and Internal VPN Certificate.

Scenario 2 - Creating a new Site for a Remote Access VPN {#Scenario 2}
----------------------------------------------------------------------

### Symptoms

* When creating a new site for a remote access VPN, a popup appears to verify the certificate of the Security Gateway. The fingerprint presented does not match the IPSec VPN certificate fingerprint.

### Solution

This is expected behavior. The certificate that appears has the fingerprint of the internal Certificate Authority.

To view the internal CA fingerprint in SmartConsole:

1. In the right panel **Objects** , go to **Servers** \> **Trusted CA**.
2. Double-click the **internal_ca** object.
3. Go to the **Local Security Management Server** tab.
4. Click the **View** button.
5. Scroll to the lines **MD5 Fingerprint** and **SHA-1 Fingerprints**.

Scenario 3 - Creating a New Site in an Endpoint Security VPN client with a Wildcard Certificate {#Scenario 3}
-------------------------------------------------------------------------------------------------------------

### Symptoms

* The popup message "*The site's security certificate is not trusted!*" appears when creating a new VPN site in a Check Point Endpoint Security VPN client using a wildcard certificate.

### Root Cause

The computer with the Endpoint Security VPN client installed is not familiar with the issuer of the Security Gateway's certificate and therefore does not trust the site.

### Solution

Support for a wildcard certificate is not included in the Endpoint Security VPN client. If you need it, please submit a [Request for Enhancement](https://usercenter.checkpoint.com/ucapps/rfe/).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
