<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection - Chain Errors in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49283#M57993</link>
    <description>&lt;P&gt;It’s impossible for a gateway to be running R80.20.M2 because that’s a Management-only release. What is the gateway actually running here? Also, is this happening consistently for specific sites or at&amp;nbsp;random?&lt;/P&gt;</description>
    <pubDate>Sat, 30 Mar 2019 16:03:19 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-03-30T16:03:19Z</dc:date>
    <item>
      <title>HTTPS Inspection - Chain Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49217#M57992</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have a gateway running 80.20 M2 and I recently enabled SSL Inspection for a small group. It is working correctly (I see our cert in the browser and no warnings), but I see some strange errors in the logs and sometimes in the browser about the "certificate chain not signed by a trusted CA".&lt;/P&gt;&lt;P&gt;When I look at the certificate, it seems to be missing the original CA and didn't insert our CA/cert.&lt;/P&gt;&lt;P&gt;For example, normal certs look like: DigicertCA--&amp;gt;&lt;A href="http://www.CDWG.com" target="_blank"&gt;www.CDWG.com&lt;/A&gt;&lt;BR /&gt;Inspection working: MYEnterpriseCA--&amp;gt;&lt;A href="http://www.CDWG.com" target="_blank"&gt;www.CDWG.com&lt;/A&gt;&lt;BR /&gt;When I see errors it looks like: &lt;A href="http://www.CDWG.com" target="_blank"&gt;www.CDWG.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Am I missing something?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;--Ben&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Firewall log" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/537i881FE0E0F8F14247/image-size/large?v=v2&amp;amp;px=999" role="button" title="2019-03-29 12_45_01-csd8-management - Remote Desktop Connection Manager v2.7.png" alt="2019-03-29 12_45_01-csd8-management - Remote Desktop Connection Manager v2.7.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Browser cert" style="width: 552px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/538i30C2E6AB1910C805/image-size/large?v=v2&amp;amp;px=999" role="button" title="2019-03-29 12_54_01-Certificate Viewer_ “www.cdwg.com”.png" alt="2019-03-29 12_54_01-Certificate Viewer_ “www.cdwg.com”.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 16:54:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49217#M57992</guid>
      <dc:creator>Benjamin_Lamber</dc:creator>
      <dc:date>2019-03-29T16:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Chain Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49283#M57993</link>
      <description>&lt;P&gt;It’s impossible for a gateway to be running R80.20.M2 because that’s a Management-only release. What is the gateway actually running here? Also, is this happening consistently for specific sites or at&amp;nbsp;random?&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2019 16:03:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49283#M57993</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-30T16:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Chain Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49286#M57995</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/6068" target="_blank"&gt;@Benjamin_Lamber&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the DigiCert certificate is not in R80.20 root certificate store.&lt;/P&gt;
&lt;P&gt;So you get a certificate chain error.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2019 17:14:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49286#M57995</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-30T17:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Chain Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49287#M57996</link>
      <description>&lt;P&gt;Look at this sk:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114679&amp;amp;partition=Advanced&amp;amp;product=HTTPS" target="_self"&gt;sk114679 - HTTPS Bypass (with Site Category) not working for Servers with Self-Signed Certificate&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2019 17:20:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49287#M57996</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-30T17:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Chain Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49290#M57997</link>
      <description>&lt;P&gt;Here the root certificate. &lt;FONT color="#FF0000"&gt;This certificate is not in the root certificate store.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20190330-180412_Chrome.jpg" style="width: 470px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/545i3823D0F82A5661CB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_20190330-180412_Chrome.jpg" alt="Screenshot_20190330-180412_Chrome.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2019 17:39:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49290#M57997</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-30T17:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Chain Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49293#M57998</link>
      <description>&lt;P&gt;Here the intermediate certificate:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20190330-183202_Chrome.jpg" style="width: 445px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/547i25C8F1BA40AB55D9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_20190330-183202_Chrome.jpg" alt="Screenshot_20190330-183202_Chrome.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2019 17:32:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49293#M57998</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-30T17:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Chain Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49296#M57999</link>
      <description>&lt;P&gt;And here the web server certificate:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20190330-182852_Chrome.jpg" style="width: 453px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/548iE23254D0A31BA2F5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_20190330-182852_Chrome.jpg" alt="Screenshot_20190330-182852_Chrome.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2019 17:34:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49296#M57999</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-30T17:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Chain Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49297#M58000</link>
      <description>&lt;P&gt;Sorry for the german names in the pictures.&amp;nbsp;I write on a samsung tab s4 and I cannot change the browser to english.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2019 17:37:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49297#M58000</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-30T17:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection - Chain Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49472#M58001</link>
      <description>&lt;P&gt;Thank you, this was ultimately the issue. For some reason Check Point did not have Digicert Global Root G2/G3 in the certificate store. I was able to download them from their support site and add them.&lt;/P&gt;&lt;P&gt;Is there a way to ensure that the Check Point cert store is being automatically updated, apart from checking the box?&lt;/P&gt;&lt;P&gt;Thank you very much!&lt;/P&gt;&lt;P&gt;--Ben&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 14:37:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Chain-Errors/m-p/49472#M58001</guid>
      <dc:creator>Benjamin_Lamber</dc:creator>
      <dc:date>2019-04-01T14:37:25Z</dc:date>
    </item>
  </channel>
</rss>

