> Source: [sk174604](https://support.checkpoint.com/results/sk/sk174604)

# sk174604 - Personal Certificate not recognized when On-device Network Protection (ONP) is enabled

| Property | Value |
|----------|-------|
| Solution ID | sk174604 |
| Date Created | 2021-08-05 |
| Last Modified | 2021-08-09 |
| Technical Level | General |
| Products | Mobile Security |
| Versions | Cloud |
| OS | Android, iOS |

## Symptoms

- Web Pages that require Personal Certificate are blocked when ONP is enabled.

## Cause

ONP uses an ONP certificate only for SSL inspection.

The use of Client Certificates is a rare requirement on SSL websites.

ONP does not currently support the use of Client Certificates for the SSL option.

## Solution

As a **workaround** you can exclude domains from SSL inspection or ONP service in general.

**Important Note:**Use this step at your own risk. Bypassing the ONP inspection may cause a security risk in case the domain is not trusted.

To exclude ONP:

1. Log into the portal
2. Navigate to Policy \>On-Device Network protection \> Whitelisted Locations
3. Add the domain to the Whitelist

To exclude from SSL inspection only:

1. Log into portal
2. Navigate to Policy\> WIFI Network \> SSL Certificates Whitelist.
3. Add domain to the Whitelist

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
