> Source: [sk130892](https://support.checkpoint.com/results/sk/sk130892)

# sk130892 - Vulnerability scanner shows a self-signed ICA certificate for the Security Management Server and reports it as a vulnerability 

| Property | Value |
|----------|-------|
| Solution ID | sk130892 |
| Date Created | 2018-07-03 |
| Last Modified | 2018-07-14 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20, R82.20 |

## Symptoms

- A vulnerability scanner shows a self-signed ICA certificate for the Security Management Server and reports this as a vulnerability.

## Cause

The ICA (Internal Certificate Authority) is created on the Security Management Server when you configure it for the first time. The ICA issues and delivers a certificate to the Security Management Server.

The ICA issues these certificates for authentication:

* **Secure Internal Communication** (SIC) - Authenticates communication between Security Management Servers, and between Gateways and Security Management Servers.
* **VPN Certificates for Gateways** - Authentication between members of the VPN community, to create the VPN tunnel.
* **Users** - Strong method for authenticating user access according to authorization and permissions.

The ICA is self-signed by design, and a third-party ICA cannot be used. This includes the SIC certificates on the Security Management Servers and Security Gateways.

Since the authentication is by Check Point parties and not generic applications such as browsers that come with a set of trusted CAs - this is a false positive and there is no reason for the CA to be one of the well-known ones.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
