> Source: [sk172188](https://support.checkpoint.com/results/sk/sk172188)

# sk172188 - Public Cloud CA Bundle for Cloud Firewall Release Updates

| Property | Value |
|----------|-------|
| Solution ID | sk172188 |
| Date Created | 2021-10-25 |
| Last Modified | 2026-03-29 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R82.10, R81 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |

## Solution

**Introduction \| Prerequisites \| Availability \| Manual Installation \| Installation Troubleshooting \| List of Resolved Issues**

<br />

Introduction {#Introduction}
----------------------------

<br />

**Public Cloud CA** **for Cloud Firewall** (formerly known as CloudGuard) Bundle contains certificates of root certificate authorities that are used to sign the public keys of the API servers of public cloud providers.

The certificates allow API clients in Check Point solutions to validate the authenticity of API servers of cloud platforms such as AWS (Amazon Web Services), Azure, GCP (Google Cloud Platform), and more.

You can install public Cloud CA Bundle on Security Management Server, Multi-Domain Management Server, Security Gateways, Standalone deployed in cloud platforms or on-premises machines.

**Important:**It is essential to keep Public Cloud CA Bundle up to date with Automatic Updates.

The Public Cloud CA package is installed automatically on all relevant Check Point devices when Automatic Update downloads are enabled (see [sk175504](https://support.checkpoint.com/results/sk/sk175504), section 2-B).

If Automatic Updates are disabled, you must first manually install the latest [AutoUpdater](https://support.checkpoint.com/results/sk/sk165653) Take and then install the Public Cloud CA package manually using the steps below, in the Manual Installation section.

Prerequisites {#Prerequisites}
------------------------------

Public Cloud CA Bundle requires Jumbo Hotfix Accumulator installed with the minimum version:

|-----------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Version                           | Required                                                                                                                                                                     |
| R81.10 and higher                 | It is not required to install Jumbo Hotfix Accumulator                                                                                                                       |
| R81                               | [R81 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) Take 45                                                                       |
| R80.40                            | [R80.40 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) Take 132                                                                |
| R80.30                            | [R80.30 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.30/Default.htm) Take 241                                                                |
| R80.30 Security Gateway Gaia 3.10 | [R80.30 Jumbo Hotfix Accumulator](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) Take 241               |
| R80.20                            | [R80.20 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.20/Default.htm) Take 204                                                                |
| R80.20 Security Gateway Gaia 3.10 | [R80.20 Jumbo Hotfix Accumulator with Gaia 3.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk146212) Take 44 |

<br />

<br />

Availability {#Availability}
----------------------------

|------------------|---------|--------------|----------------------------------------------------------------------------------------------------------------------------------------------------------|
|                  | Take #  | Release Date | Offload Package Link                                                                                                                                     |
| Recommended Take | Take 21 | 30 Jun 2024  | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk172188/download202202081243441.png)](https://support.checkpoint.com/results/download/133130) (TAR) |

<br />

Manual Installation (Offline) {#Manual Installation}
----------------------------------------------------

### Instructions:

1. Log in to the Check Point machine via SSH.

2. Transfer the offline package to the machine.

3. From Expert mode, run:

   `autoupdatercli install <FULL PATH TO PUBLIC CLOUD CA BUNDLE PACKAGE>.tar`

   Example: `autoupdatercli install /home/admin/_Check_Point_ PUBLIC CLOUD CA BUNDLE _AUTOUPDATE_Bundle_T14_AutoUpdate.tar`  
   On the Scalable Platform Security Group:  
   `g_all autoupdatercli install <full path to TAR file>`
4. Validate the installation passed successfully by checking the */opt/CPInstLog/AutoUpdateLogs/public_cloud_ca_bundle* log.

Installation Troubleshooting {#Installation Troubleshooting}
------------------------------------------------------------

These issues can rise when running the installation package:

* **Issue 1: "Failed to download latest Public Cloud CA Bundle."**  
  > Solution: If you have no internet access, follow the instructions for "Offline Package Installation Procedure" in the Installation Instructions section above.

  <br />

* **Issue 2: "A version of Public Cloud CA bundle is already installed via AutoUpdater"**  
  > Solution: Public Cloud CA Bundle has already been installed for the first time and is configured to receive updates automatically. If you have no internet access, follow the instructions for "Offline Package Installation Procedure" in the Installation Instructions section above.

  <br />

* **Issue 3: You want to return to previous version of Public Cloud CA bundle**  
  > Solution: It is highly recommended that you use the latest take of Public Cloud CA bundle.
  >
  > If you still want to revert to the previous take, run the following command in Expert mode:
  >
  > `autoupdatercli revert public_cloud_ca_bundle`
  >
  > The revert takes up to 1 minute.
  >
  > To make sure Public Cloud CA Bundle was reverted to the previous take, run this command in the Expert mode:
  >
  > `cpinfo -y CPUpdates 2>&1 | grep PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE`
  >
  > The take number in the output must be the one to which you reverted.
  >
  > Notes:
  > * Public Cloud CA Bundle is upgraded automatically each time a new take is released.
  >
  > * You can revert only to the previous version. A revert to older versions reverts Public Cloud CA Bundle completely and removes it from the machine.

  <br />

  <br />

* **Issue 4: You want to totally remove Public Cloud CA bundle**  
  > Solution: Run the following command in Expert mode:
  >
  > `autoupdatercli revert-completely public_cloud_ca_bundle`
  >
  > The revert takes up to 1 minute.
  >
  > To make sure Public Cloud CA Bundle was reverted completely, run this command in the Expert mode:
  >
  > `cpinfo -y CPUpdates 2>&1 | grep PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE`
  >
  > If you also wish to stop receiving future updates of Public Cloud CA Bundle after the removal, run the following command in Expert mode:
  >
  > `autoupdatercli disable public_cloud_ca_bundle`
  >
  > The output must show "0".

<br />

If your issue is not resolved by one of the above solutions, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) and attach the log files from */opt/CPInstLog/AutoUpdateLogs/PUBLIC_CLOUD_CA_BUNDLE*

List of Resolved Issues and New Features per Public Cloud CA Bundle Update {#List of Rresolved Issues}
------------------------------------------------------------------------------------------------------

|-------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ID          | Description                                                                                                                                                                                                                                                                                                                                        |
| **Take 21 (30 Jun 2024)**                                                                                                                                                                                                                                                                                                                                       ||
| VSECPC-7604 | Enhancement: Removed expired Google Cloud Platform (GCP) certificates from the *ca_bundle_public_cloud.crt* file. Note: Adding permissions for others to access this file does not reduce security confidence. This is because the public-cloud folder contains only CA bundles with public certificates, which are not considered sensitive data. |
| **Take 20 (24 Jul 2023)**                                                                                                                                                                                                                                                                                                                                       ||
| VSECPC-6785 | Enhancement: *PUBLIC_CLOUD_CA_BUNDLE DDR conditions-set* now blocks installation on Maestro machines.                                                                                                                                                                                                                                              |
| **Take 19 (06 Sep 2022)**                                                                                                                                                                                                                                                                                                                                       ||
| PMTR-85947  | Enhancement: Added support for Log Server.                                                                                                                                                                                                                                                                                                         |
| **Take 18 (20 Mar 2022)**                                                                                                                                                                                                                                                                                                                                       ||
| VSECPC-5597 | Enhancement: Added a new Azure certificate for the Storage service.                                                                                                                                                                                                                                                                                |
| **Take 14 (09 Feb 2022)**                                                                                                                                                                                                                                                                                                                                       ||
| -           | First release of Public Cloud CA Bundle Update.                                                                                                                                                                                                                                                                                                    |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
