Renewing a Central CA Certificate Across Policies

This section describes the CA certificate renewal procedure if you are using a centralized CA certificate across policies.

  1. In the Mobile Security Administrator Portal, go to Settings > Privacy/Security.
  2. In the Central HTTPS Inspection Root CA section, click Revoke Certificate.

  3. Click Yes in the confirmation box.

    The system deletes the current central CA certificate.

  4. To generate a new central CA certificate, do one of these:

    • To generate a CA certificate issued by Check Point, click Generate CA Certificate.

      The system generates a certificate valid for one year from the generation date, as shown in Expiration date.

    • To use a self-signed or a third-party CA certificate, click Upload CA Certificate.

      1. In the pop-up window, upload the certificate.

        Note:

        For the Transport Layer Security (TLS) certificate to be valid:

        • The certificate must have a lifecycle of at least 30 days and not longer than 390 days.

        • The certificate must be valid for more than 30 days from the time it is uploaded to the Mobile Security Administrator Portal.

      2. Enter the certificate password.

      3. Click Verify.

      4. If there are no errors, click Add.

  5. If you have generated a CA certificate by Check Point, click Download Certificate.

    The system downloads the certificate to your computer.

  6. Upload the new certificate to the UEM.

    For more information, see CA certificate deployment using the UEM section for the relevant UEM in Mobile Security Integration Guide.