> Source: [sk170697](https://support.checkpoint.com/results/sk/sk170697)

# sk170697 - How to deploy a certificate to iOS for SSL inspection on a Locally Managed Gaia Embedded device

| Property | Value |
|----------|-------|
| Solution ID | sk170697 |
| Date Created | 2020-12-03 |
| Last Modified | 2022-07-13 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1500, 1600, 1800, 910 |

## Solution

### Background

On a Locally Managed Gaia Embedded device: After the user imports a Security Gateway's certificate to an iOS device, it does not show up in the list of Certificate Trust Settings.   

This occurs because Apple made changes that require a CN be included in the Issuer field. SMB devices, which use an internal CA, cannot include this in the Issuer field as it would break other functions, e.g., SIC.   

### Instructions

Replace the internal CA of the Security Gateway instead of using the Security Gateway's internal CA.  

Here are some general steps from Server 2016. It is assumed that you already added the Certificate Authority role on the server.  

1. Go to **Start** \> Search for **Manage computer certificates** \> **Personal** \> **Certificates** .   

2. Right-click on the CA where the Intended Purpose is **\<All\>** \> **All Tasks** \> **Export...**   
![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1606418581499/1202011261454541.png)

3. The Certificate Export Wizard now pops up:  

* Next
* Yes, export the private key, Next
* Personal Information Exchange - PKCS #12 (.PFX)
* Check only Include all certificates in the certification path if possible, Next
* Check Password and enter password and confirm, Next
* Save file to desktop and give it a name, Next
* Finish

4. Replace the Internal CA on the Security Gateway. Go to**Device** \> **Internal Certificate** \> **Replace Internal CA** .   

![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk170697/cert202011261506031.png)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
