> Source: [sk163932](https://support.checkpoint.com/results/sk/sk163932)

# sk163932 - After installing macOS 10.15 (Catalina), users may be unable to access sites via HTTPS inspection gateway

| Property | Value |
|----------|-------|
| Solution ID | sk163932 |
| Date Created | 2019-12-05 |
| Last Modified | 2022-05-18 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- After installing macOS 10.15 (Catalina), users are unable to access sites via HTTPS inspection gateway. The error in Safari is:  
Safari Can't Open the Page  
Safari can't open the page "https://example.com" because Safari can't establish a secure connection to the server "example.com".

## Cause

**Environment:** SSL inspection CA certificate signing algorithm is SHA1

All TLS server certificates must comply with these new security requirements in iOS 13 and macOS 10.15:

1. TLS server certificates and issuing CAs using RSA keys must use key sizes greater than or equal to 2048 bits. Certificates using RSA key sizes smaller than 2048 bits are no longer trusted for TLS.TLS server certificates and issuing CAs using RSA keys.
2. CAs must use a hash algorithm from the SHA-2 family in the signature algorithm. **SHA-1 signed certificates are no longer trusted for TLS.**

## Solution

This problem was fixed. The fix is included in:

* [Check Point R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk160736)
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) since Take 163
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) since Take 149
* [Jumbo Hotfix Accumulator for R80.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116380) since Take 270

Check Point recommends to always upgrade to the most recent version ([upgrade Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=435) / [upgrade Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=184) / [upgrade Multi-Domain Security Management](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=166)).

If you do not wish to upgrade, review the HTTPS inspection CA certificate, open the HTTPS inspection tab in Gateway Properties and chose to "View certificate".

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk163932/httpsi_cert1912040202.PNG)

If the Signature hash algorithm is SHA-1 (as in the example above), follow the procedure in [sk115894 - How to change HTTPS Inspection certificate from SHA-1 to SHA-256](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115894).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
