<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate and CRL validation fails from March 1, 2026 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272323#M103735</link>
    <description>&lt;P&gt;I can also confirm this issue. I have the same problem on the 3 Gateways where I have installed the Hotfix. I have one gateway pending to be updated that still works fine.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Mar 2026 07:57:54 GMT</pubDate>
    <dc:creator>Alejandro_Lansa</dc:creator>
    <dc:date>2026-03-03T07:57:54Z</dc:date>
    <item>
      <title>Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272201#M103696</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;accidentally, for the firewall infrastructure of a customer we ran into the issue reported in following SK:&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk184766#" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk184766#&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For the specific customer we planned to install the suggested hotfix.&lt;/P&gt;&lt;P&gt;Hope it could be useful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 10:38:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272201#M103696</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-03-02T10:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272203#M103697</link>
      <description>&lt;P&gt;We ran into this bug too, the hotfix worked for us. It seems (by the workaround in the SK), that CP added an extra day (incorrect leap year) into the calculation.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 11:03:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272203#M103697</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2026-03-02T11:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272209#M103698</link>
      <description>&lt;P&gt;Please follow the Sk instruction. There is a workaround that can be applied right away.&lt;/P&gt;
&lt;P&gt;Also, it is important to say that the issue mentioned in the SK is limited and may only happen with R82 and R82.10 versions.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 11:36:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272209#M103698</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2026-03-02T11:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272216#M103700</link>
      <description>&lt;P&gt;Limited to specific versions yes, limited in the effect no. We had several hundred of remote workers, who could not connect.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 12:12:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272216#M103700</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2026-03-02T12:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272219#M103703</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10477"&gt;@Steffen_Appel&lt;/a&gt;&amp;nbsp;I think you misread my comment.&lt;/P&gt;
&lt;P&gt;Just to be clear, "limited" means it does not happen to every GW or a user. S2S VPN tunners are affected only if X509 certs are in use. Users are affected only if cert-based auth is used. An additional limitation is about new certificates or newly generated CRLs.&lt;BR /&gt;&lt;BR /&gt;That said, yes, if you are affected, it can be painful.&lt;BR /&gt;&lt;BR /&gt;I want to assure you and everybody else that we are working on fixing the issue as soon as possible. The workaround mentioned in the SK is also very effective and does not require an HF installation, to buy you time for HF installation.&lt;BR /&gt;&lt;BR /&gt;Please do not hesitate to reach out to TAC if you need any additional assistance.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 12:33:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272219#M103703</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2026-03-02T12:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272229#M103708</link>
      <description>&lt;P&gt;Does the hotfix require a reboot?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 13:43:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272229#M103708</guid>
      <dc:creator>Mattias_Jansson</dc:creator>
      <dc:date>2026-03-02T13:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272230#M103709</link>
      <description>&lt;P&gt;Quite important information - does anybody can reply?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 13:53:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272230#M103709</guid>
      <dc:creator>AndrzejAdamczyk</dc:creator>
      <dc:date>2026-03-02T13:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272231#M103710</link>
      <description>&lt;P&gt;Hotfix yes, workaround - no&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 14:02:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272231#M103710</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2026-03-02T14:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272232#M103711</link>
      <description>&lt;P&gt;As I wrote we installed the HF and it fixes the issue for us.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 14:16:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272232#M103711</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2026-03-02T14:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272233#M103712</link>
      <description>&lt;P&gt;Happy to hear that&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 14:40:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272233#M103712</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2026-03-02T14:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272237#M103714</link>
      <description>&lt;P&gt;Does the HF install on MDS require a reboot?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 15:18:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272237#M103714</guid>
      <dc:creator>Robert_Yohn</dc:creator>
      <dc:date>2026-03-02T15:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272238#M103715</link>
      <description>&lt;P&gt;February 29 is a leap day that occurs only every four years in the Gregorian calendar to compensate for the difference between the calendar year and the solar year.&lt;/P&gt;
&lt;P&gt;The year 2026 is not a leap year; the next February 29 will be in 2028.&lt;/P&gt;
&lt;P&gt;If you take a closer look at the firewall code in R82, you will see that there is a small programming error. As a result, the certificates were no longer valid from March 1 onwards &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 15:21:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272238#M103715</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2026-03-02T15:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272240#M103717</link>
      <description>&lt;P&gt;That was my thought is morning (see above) &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 15:37:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272240#M103717</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2026-03-02T15:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272241#M103718</link>
      <description>&lt;P&gt;In my case, after installing the hotfix Gaia Software Updates can no longer access the Check Point Download Center.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cannot establish connection with the Check Point cloud.&amp;nbsp;Connection Error, FDT - Unexpected error code.&amp;nbsp;Make sure that 1. Proxy, DNS and routing are configured properly. 2. Firewall does not block traffic originating from this machine to Check Point servers (checkpoint.com and akamaitechnologies.com over HTTP and HTTPS).&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 16:02:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272241#M103718</guid>
      <dc:creator>Alex_Lewis</dc:creator>
      <dc:date>2026-03-02T16:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272243#M103720</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7612"&gt;@Alex_Lewis&lt;/a&gt;&amp;nbsp;I can confirm the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 16:13:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272243#M103720</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2026-03-02T16:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272244#M103721</link>
      <description>&lt;P&gt;&lt;STRONG&gt;URGENT WARNING!&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;While the article seems to indicate this only applies to R82 gateways and above the only thing needed is a R82 or above management.&lt;/P&gt;
&lt;P&gt;I just fixed a VPN issue where the customer runs R82 MDS with R81.20 gateways and R81.10 spark applances.&lt;/P&gt;
&lt;P&gt;The VPN certificate expire date/time was March 3, 2026 13:44 and today (March 2) at exactly 13:44 the VPN went down.&lt;/P&gt;
&lt;P&gt;Applied the workaround from the SK and did a renewal after that to resolve the issue.&lt;/P&gt;
&lt;P&gt;The error on the Spark appliance was an "internal error" which I tried to solve based on&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk170141" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk170141&lt;/A&gt;&amp;nbsp;but then I verified the exact time when the outage began and it was exactly 24 before expiration.&lt;/P&gt;
&lt;P&gt;So I urge everyone to considere all gateways regardless of the version as impacted by this SK if your Management system is on R82 or above.&lt;/P&gt;
&lt;P&gt;And the certificate was issued in 2021.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 16:45:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272244#M103721</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2026-03-02T16:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272293#M103729</link>
      <description>&lt;P&gt;So I have to install the fix on all gateways that I have r82 and above?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 21:07:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272293#M103729</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-02T21:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272305#M103731</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7612"&gt;@Alex_Lewis&lt;/a&gt;&amp;nbsp;I am experiencing the same issue across multiple installations.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 02:07:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272305#M103731</guid>
      <dc:creator>hvf3000</dc:creator>
      <dc:date>2026-03-03T02:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272318#M103732</link>
      <description>&lt;P&gt;yes you have and on the management&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 06:19:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272318#M103732</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2026-03-03T06:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate and CRL validation fails from March 1, 2026</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272320#M103733</link>
      <description>&lt;P&gt;The HF for the 3900 cannot be installed on a freshly installed GW with take 464.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;/P&gt;
&lt;DIV class="verification-result-section"&gt;&lt;SPAN class="title"&gt;Verification results&lt;/SPAN&gt;
&lt;DIV class="verification-details"&gt;&lt;SPAN&gt;1 Errors | &lt;/SPAN&gt;&lt;SPAN&gt;Installation is not allowed&lt;/SPAN&gt;
&lt;DIV style="display: block;"&gt;&lt;SPAN class="verification-error-title"&gt;Verification errors:&lt;/SPAN&gt;
&lt;DIV&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;Installed hotfixes are missing from this package.&lt;/SPAN&gt;"&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 06:49:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Certificate-and-CRL-validation-fails-from-March-1-2026/m-p/272320#M103733</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2026-03-03T06:49:27Z</dc:date>
    </item>
  </channel>
</rss>

