> Source: [sk179944](https://support.checkpoint.com/results/sk/sk179944)

# sk179944 - SmartConsole shows an "Untrusted Certificate" log with "Certificate Chain is not signed by a Trusted CA"

| Property | Value |
|----------|-------|
| Solution ID | sk179944 |
| Date Created | 2022-09-11 |
| Last Modified | 2026-04-13 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- SmartConsole shows an "*Untrusted Certificate* " log with the "*Certificate Chain is not signed by a Trusted CA. See sk179944.* " message in the "*Description*" field.

## Cause

The Security Gateway that generated this log tried to inspect an outbound HTTPS connection to a server with a certificate chain that is not connected to a Certificate Authority in the Check Point trust store.

For more details, see the [Security Management Administration Guide](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=documents&product=184) for your version \> chapter "HTTPS Inspection" \> section "HTTPS Inspection Policy" \> section "Adding Trusted CAs for Outbound HTTPS Inspection".

This error is justified most of the time, as most non-reputable and malicious sites are untrusted. However, if you believe this is a mistake, and the Root certificate authority should be added to the Trusted CA bundle, do the instructions below.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
