Skip to main content

Check Point Security Gateway HTTPS Inspection

This document describes how to integrate Securosys Primus HSM or CloudHSM with Check Point Security Gateway. This integration enables you to keep the CA private keys used by HTTPS Inspection securely inside an HSM.

How it works

Check Point HTTPS Inspection enables the Security Gateway to decrypt and inspect HTTPS traffic for security threats and policy enforcement. The Security Gateway terminates the TLS connection, inspects the decrypted traffic, and establishes a new TLS connection to the destination server. Key features include granular inspection policies, URL and category-based rules, integration with Threat Prevention and traffic logging.

During HTTPS inspection, the Security Gateway uses an intermediate Certificate Authority (CA). The CA certificate needs to be allowlisted by the clients. The Security Gateway then generates server keys and short-lived server certificates to decrypt the TLS traffic. The server certificates are signed by the CA private key, thus, clients will trust it. The Security Gateway terminates the client-side TLS session, decrypts and inspects the traffic, and establishes a separate TLS session with the destination server before forwarding the traffic.

By generating and storing the HTTPS Inspection CA private keys within Securosys HSM, they remain protected and are not exposed outside the HSM boundary. This reduces the risk of key compromise and strengthening the overall security architecture. It also reduces the risk of a malicious actor gaining access to the CA private key, which could be used to maliciously intercept traffic from clients.

The integration between the Check Point Security Gateway enterprise firewall and Securosys HSMs is facilitated by the Primus PKCS#11 Provider.

Check Point integration with Securosys Primus HSM

Benefits

  • Secure Key Generation and Storage: Ensuring the security of cryptographic keys is critical for any organization. Securosys Primus HSM and CloudHSM provide certified, high-entropy, hardware-based true random number generation and a tamper-resistant environment. Keys stay in the HSM and cannot be accidentally exposed.

  • Compliance with Security Standards: Being compliant with regulatory requirements demands rigorous control over cryptographic key management. Integrating Check Point Security Gateway with Securosys HSMs enables centralized key management on FIPS 140-2 Level 3 and Common Criteria EAL4+ certified hardware.

    This integration helps mitigate risks associated with key compromise and mismanagement, ensuring adherence to these stringent regulations.

Next Steps

Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?