<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CRL Timeout in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/105269#M10962</link>
    <description>&lt;P&gt;Out of interest is OCSP traffic allowed by your policy?&lt;/P&gt;</description>
    <pubDate>Sun, 13 Dec 2020 10:35:34 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2020-12-13T10:35:34Z</dc:date>
    <item>
      <title>CRL Timeout</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/89918#M10955</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We are facing weird issue, few of the users are able to access a particular URL and few are not. In Tracker i see the below Detect Message.&lt;/P&gt;&lt;P&gt;Failed to fetch CRL. Make sure the security gateway has an outgoing http access, and that the proxy and DNS servers are well configured.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Certificate Validation: CRL Timeout&amp;nbsp;&lt;/P&gt;&lt;P&gt;We upgraded the firewalls to R80.30 Take 196 2 days back, is that causing the issue? Or what is the solution for this please help.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 14:29:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/89918#M10955</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2020-06-26T14:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: CRL Timeout</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/90442#M10956</link>
      <description>Are the sites HTTPS by chance?&lt;BR /&gt;Is HTTPS Inspection enabled?&lt;BR /&gt;I could see this happening if both are true since SNI is validated out of band and that does involve checking the cert and CRL.</description>
      <pubDate>Thu, 02 Jul 2020 21:41:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/90442#M10956</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-02T21:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: CRL Timeout</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/90636#M10957</link>
      <description>&lt;P&gt;Is there an open SR for this issue?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 08:09:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/90636#M10957</guid>
      <dc:creator>Nasrat</dc:creator>
      <dc:date>2020-07-06T08:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: CRL Timeout</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/91449#M10958</link>
      <description>&lt;P&gt;Yes those are https sites and https Inspection blade was enabled.&lt;/P&gt;&lt;P&gt;The issue was resolved after rebooting the server which was hosting the site. Thank you for your help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 11:57:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/91449#M10958</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2020-07-14T11:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: CRL Timeout</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/104500#M10959</link>
      <description>&lt;P&gt;I'm seeing this in our logs,&amp;nbsp; we are not running https inspection but I see lots of entries related to "Failed to fetch CRL from the following URL"&lt;/P&gt;&lt;P&gt;I know the gateway can access the internet.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 12:49:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/104500#M10959</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2020-12-07T12:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: CRL Timeout</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/104583#M10960</link>
      <description>&lt;P&gt;Even without HTTPS Inspection, SNI verification is done on HTTPS sites from R80.30+.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 20:42:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/104583#M10960</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-07T20:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: CRL Timeout</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/105267#M10961</link>
      <description>&lt;P&gt;Is there something I need to ensure the GW can retrieve these? or is the correct behaviour as a result of SNI verification?&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 10:04:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/105267#M10961</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2020-12-13T10:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: CRL Timeout</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/105269#M10962</link>
      <description>&lt;P&gt;Out of interest is OCSP traffic allowed by your policy?&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 10:35:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CRL-Timeout/m-p/105269#M10962</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-12-13T10:35:34Z</dc:date>
    </item>
  </channel>
</rss>

