> Source: [sk64521](https://support.checkpoint.com/results/sk/sk64521)

# sk64521 - How to update the Trusted Certificate Authorities (CAs) list for HTTPS Inspection and HTTPS Categorization

| Property | Value |
|----------|-------|
| Solution ID | sk64521 |
| Date Created | 2011-08-07 |
| Last Modified | 2026-01-21 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

### Background

> An important part of HTTPS Inspection is the validation of the server's certificates from a signing Certificate Authority (CA).
>
> A Security Gateway with enabled HTTPS Inspection uses a built-in predefined list of Trusted CAs, based on the Microsoft recommended list of Trusted CAs.
>
> Updates to the Check Point predefined list of Trusted CAs are released based on changes in the Microsoft recommended list of Trusted CAs.

### Check Point features that use the Trusted CAs list

|-----------------------------------------------------------------------------------------------------------|-------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Feature                                                                                                   | Versions          | Notes                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| HTTPS Inspection                                                                                          | All versions      | Security Gateway uses the Trusted CAs list (described in this article) when it connects to HTTPS servers on behalf of internal clients (specifically, the `$FWDIR/database/ca_bundle.pem` file and the `$FWDIR/database/ssl_inspection.C` file). See the Threat Prevention Administration Guide for your version.                                                                                                                                                                                                                                                                                                                                                                                         |
| External Network Feeds                                                                                    | R81.20 and higher | Security Gateway uses the Trusted CAs list (described in this article) when it connects to external HTTPS servers to download the Network feed. For other connections, the Security Gateway uses the `$FWDIR/database/ca_bundle.pem` bundle from the Management Server. This bundle file includes the default CA bundle. See the Security Management Administration Guide for your version.                                                                                                                                                                                                                                                                                                               |
| External Custom Intelligence (IoC) Feeds ([sk132193](https://support.checkpoint.com/results/sk/sk132193)) | R81 and higher    | Security Gateway uses the Trusted CAs list (described in this article) when it connects to external HTTPS servers to download the IoC feed. For other connections, the Security Gateway uses the `$FWDIR/database/ca_bundle.pem` bundle from the Management Server. This bundle file includes the default CA bundle. See the Threat Prevention Administration Guide for your version.                                                                                                                                                                                                                                                                                                                     |
| URL Filtering                                                                                             | All versions      | Security Gateways uses the Trusted CAs list when you enable the "Categorize HTTPS websites" feature (also known as "Light SSL"): 1. In SmartConsole, on the left navigation panel, click the "Manage \& Settings" view. 2. In the top panel, click the "Blades" page. 3. In the "Application Control \& URL Filtering" section, click the "Advanced Settings" button. 4. In the left panel, click the "General" page. 5. I the "URL Filtering" section, select "Categorize HTTPS websites". 6. Click OK. 7. Install the Access Control policy. For other connections, the Security Gateways uses the `$CPDIR/conf/ca-bundle.crt` file. See the Security Management Administration Guide for your version. |

### Important Notes

* On a Multi-Domain Security Management Server, it is **not** necessary to update the Trusted CAs package in the MDS context - only in the context of each Domain Management Server.
* On SmartEvent Servers and Log Servers, it is **not** necessary to update the Trusted CAs package.

### Performing a *manual* update of the Trusted CAs list on a Management Server

1. Download the [Trusted CAs package](https://support.checkpoint.com/results/download/141273) (ZIP archive).

   *[Software Subscription or Active Support plan](https://www.checkpoint.com/support-services/support-plans/) is required to download this package.*
2. Upload the Trusted CAs package to the Management Server.

   On a Management Server versions R82 and higher:
   > Show / Hide this section  
   > 1. Connect with SmartConsole to the Security Management Server / Domain Management Server.
   >
   > 2. From the left navigation panel, click **Security Policies**.
   >
   > 3. In the top panel, click the **HTTPS Inspection** section.
   >
   > 4. In the bottom panel **HTTPS Inspection** , click **Trusted Certificates**.
   >
   > 5. In the left panel, click the **Trusted CAs Package** page.
   >
   > 6. In the top right section **Update Trusted CAs Package** , select the option **Manually**.
   >
   > 7. Perform the applicable manual update:
   >
   >    * To update the package from the Check Point cloud, click the **Update now** button
   >
   >    * To import the offline package:
   >
   >      1. On the right side of the **Update now** button, click the downward arrow and click **Import Trusted CAs Package**.
   >
   >      2. Browse to the offline ZIP package and select it.
   >
   >      3. Click **Open**.
   >
   > 8. Click **Close** to close the **Trusted Certificates** window.
   >
   > 9. Install the Access Control Policy.

   On a Management Server versions R80 - R81.20:
   > Show / Hide this section  
   > 1. Connect with SmartConsole to the Security Management Server / Domain Management Server.
   >
   > 2. From the left navigation panel, click **Manage \& Setting**.
   >
   > 3. Click **Blades**.
   >
   > 4. Below **Configure HTTPs Inspection** , click **Configure in SmartDashboard**.
   >
   > 5. Click the **Trusted CAs** section.
   >
   > 6. At the top, click **Actions** \> select **Update certificate list...** \> browse for and select the ZIP archive with certificates you downloaded in the previous step \> click **Open**.
   >
   >    <br />
   >
   > 7. Save the changes and close SmartDashboard.
   >
   > 8. In SmartConsole, install the Access Control Policy on the Security Gateways.

### Enabling *automatic* update checks for the Trusted CAs list on a Management Server

> On a Management Server with the versions R82 and higher:
> > Show / Hide this section  
> > 1. Connect with SmartConsole to the Security Management Server / Domain Management Server.
> >
> > 2. From the left navigation panel, click **Security Policies**.
> >
> > 3. In the top panel, click the **HTTPS Inspection** section.
> >
> > 4. In the bottom panel **HTTPS Inspection** , click **Trusted Certificates**.
> >
> > 5. In the left panel, click the **Trusted CAs Package** page.
> >
> > 6. In the top right section **Update Trusted CAs** Package, select the option **Automatically**.
> >
> >    **Important** - This option only updates the Trusted CAs package on the Management Server. You must install the Access Control policy manually.
> > 7. Click **Close** to close the **Trusted Certificates** window.
> >
> > 8. Install the Access Control Policy.
>
> On a Management Server with the versions R80 - R81.20:
> > Show / Hide this section  
> > 1. Connect with SmartConsole to Security Management Server / Domain Management Server.
> >
> > 2. From the left navigation panel, click **Manage \& Setting**.
> >
> > 3. Click **Blades**.
> >
> > 4. Below **Configure HTTPs Inspection** , click **Configure in SmartDashboard**.
> >
> > 5. Click the **Trusted CAs** section.
> >
> > 6. At the bottom of this page, in the **Automatic Updates** section, select:
> >
> >    * In versions R81.20 and R81.10:
> >
> >      Select the option that is applicable in your environment.
> >      * **Download updates automatically and notify when an update file is available for installation**
> >
> >        **Important** - This option only updates the Trusted CAs package on the Management Server. You must install the Access Control policy manually.
> >      * **Download and install updates automatically**
> >
> >    * In versions R81 / R80.40 / R80.30 / R80.20 / R80.10 / R80:
> >
> >      **Notify when a Trusted CA and Blacklist update file is available for installation**
> >
> >      **Important** - This only enables the automatic check for updated Trusted CAs. You must install the update manually.
> >
> >    If there is an available update, then this message appears in the **Automatic Updates** section with the button **Install Now**:
> >
> >    `A Trusted CA and Blacklist update has been downloaded`
> >
> >    Example from SmartDashboard R81:
> >
> >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk64521/Install_now202212251716251.png)
> > 7. Save the changes (diskette icon on the top toolbar) and close SmartDashboard.
> >
> > 8. In SmartConsole, install the Access Control Policy on the Security Gateways.

### Enabling *automatic* update of Trusted CAs list on Security Gateways with HTTPS Inspection or "Categorize HTTPS websites" enabled

> To configure a Management Server to update the Trusted CAs automatically on the supported Security Gateways, follow [sk173629 - How to update Trusted CAs automatically](https://support.checkpoint.com/results/sk/sk173629).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
