> Source: [sk159692](https://support.checkpoint.com/results/sk/sk159692)

# sk159692 - When accessing an HTTPS website that requires the certificate critical extension "Name Constraints" (2.5.29.30), an SSL error appears in the web browser

| Property | Value |
|----------|-------|
| Solution ID | sk159692 |
| Date Created | 2019-08-04 |
| Last Modified | 2025-01-22 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * When accessing an HTTPS website (through the Check Point Security Gateway with HTTPS Inspection enabled and configured to "Inspect") that requires the certificate critical extension "Name Constraints" (2.5.29.30), the web browser shows an SSL error, although the server's certificate is valid.

  For example, when accessing `https://www.hnd.bayern.de`, the web browser shows:

  `NET::ERR_CERT_AUTHORITY_INVALID`
* Debug of the WSTLSD daemon on the Security Gateway shows this line:

  `fwValidateCert: there are unhandled critical extension`

## Cause

The server's certificate contains the certificate extension called "Name Constraints" (2.5.29.30).

Check Point HTTPS Inspection does not **yet** support this certificate extension.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
