Appendix E - Renewing a CA Certificate

A certificate trusted by a Certificate Authority (CA) is required for the On-device Network Protection (ONP) to inspect the HTTPS traffic on the end-user device. When the CA certificate expires, you must renew the certificate and deploy it on the device through the Unified Endpoint Manager (UEMClosed Unified Endpoint Management. An architecture and approach that controls different types of devices such as computers, smartphones and IoT devices from a centralized command point.). We recommend you renew the CA certificate at least two weeks before the expiration date.

Note - The SSLClosed Secure Sockets Layer. The standard security technology for establishing an encrypted link between a web server and a browser. inspection for the device is disabled during this process.

Updating Policy to Disable Device Alerts

To update your policy to avoid device alerts while renewing the certificate:

  1. In the Mobile Security Administrator Portal, go to Policy and select a policy profile.

  2. Click any one of these:

    • Device

    • Application

    • File

    • Network

  3. Go to Network Protection > HTTPS Settings and set Network Protection TLS not installed risk level as Medium (No Device Alert).

    Otherwise, the device receives these alerts:

    Android:

    iOS

  4. Click Save.

Renewing a Central CA Certificate Across Policies

If you are using a centralized CA certificate across policies:

  1. In the Mobile Security Administrator Portal, go to Settings > Privacy/Security.

  2. In the Central HTTPS Inspection Root CA section, click Revoke Certificate.

  3. Click Yes in the confirmation box.

    The system deletes the current central CA certificate.

  4. To generate a new central CA certificate, do one of these:

    • To generate a CA certificate issued by Check Point, click Generate CA Certificate.

      The system generates a certificate valid for one year from the generation date, as shown in Expiration date.

    • To use a self-signed or a third-party CA certificate, click Upload CA Certificate.

      1. In the pop-up window, upload the certificate.

        Notes:

        For the Transport Layer Security (TLSClosed Transport Layer Security. A security protocol designed to facilitate privacy and data security for communications over the Internet.) certificate to be valid:

        • The certificate must have a lifecycle of at least 30 days and not longer than 390 days.

        • The certificate must be valid for more than 30 days from the time it is uploaded to the Mobile Security Administrator Portal.

      2. Enter the certificate password.

      3. Click Verify.

      4. If there are no errors, click Add.

  5. If you have generated a CA certificate by Check Point, click Download Certificate.

    The system downloads the certificate to your computer.

  6. Upload the new certificate to the UEM.

    For more information, see CA certificate deployment using the UEM section for the relevant UEM in Mobile Security Integration Guide.

Renewing a CA Certificate Per Policy

If you are using a CA certificate per policy:

  1. In the Mobile Security Administrator Portal, go to Policy and select a policy profile.

  2. Click any one of these:

    • Device

    • Application

    • File

    • Network

  3. Click Network Protection and go to HTTPS Settings.

  4. In the Inspection CA section, select CA Certificate per policy.

  5. Click Revoke Certificate.

  6. Click Yes in the confirmation box.

    The system deletes the current central CA certificate.

  7. To generate a new CA certificate per policy, do one of these:

    • To generate a CA certificate issued by Check Point, click Generate CA Certificate.

      The system generates a certificate valid for one year from the generation date, as shown in Expiration date.

    • To use a self-signed or a third-party CA certificate, click Upload CA Certificate.

      1. In the pop-up window, upload the certificate.

        Notes:

        For the Transport Layer Security (TLS) certificate to be valid:

        • The certificate must have a lifecycle of at least 30 days and not longer than 390 days.

        • The certificate must be valid for more than 30 days from the time it is uploaded to the Mobile Security Administrator Portal.

      2. Enter the certificate password.

      3. Click Verify.

      4. If there are no errors, click Add.

  8. If you have generated a CA certificate by Check Point, click Download Certificate.

    The system downloads the certificate to your computer.

  9. Upload the new certificate to the UEM.

    For more information, see CA certificate deployment using the UEM section for the relevant UEM in Mobile Security Integration Guide.

Verifying CA Certificate Renewal

To verify whether all devices have installed the renewed CA certificate:

  1. Go to Forensics > Events & Alerts.

  2. Filter the Threat Factor column for Network Protection (TLS) to view the list of devices that have not installed the renewed certificate.

  3. Make sure that all devices have installed the renewed certificate.

  4. If all devices have installed the renewed certificate, then go to Network Protection > HTTPS Settings and revert the risk level of Network Protection TLS not installed to the original value.

  5. Click Save.