<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection errors in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21949#M58508</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I suspect the outbound certificate to be the root cause.&lt;/P&gt;&lt;P&gt;Is it really a CA or intermediate CA certificate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share a screenshot of the chain as well&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 24 Aug 2018 13:15:18 GMT</pubDate>
    <dc:creator>cstueckrath</dc:creator>
    <dc:date>2018-08-24T13:15:18Z</dc:date>
    <item>
      <title>HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21948#M58507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the HTTPs inspcetion created the outbound certifcate installed on the machines as well however from time to time legit HTTPs pages says the website is not safe , looking at log I see only empty_ssl_conn and nothing further. Also there are some desktop bank APPs that also cant connect saying error with the certificates&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I`m attaching a screenshot of the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tried to clear cache on browser&lt;/P&gt;&lt;P&gt;update broswers (IE, FireFox, Chrome)&lt;/P&gt;&lt;P&gt;running r80.10 take 91 and take 103&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issues has been happening since R77.X&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 12:24:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21948#M58507</guid>
      <dc:creator>Felipe_Muraska</dc:creator>
      <dc:date>2018-08-24T12:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21949#M58508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I suspect the outbound certificate to be the root cause.&lt;/P&gt;&lt;P&gt;Is it really a CA or intermediate CA certificate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share a screenshot of the chain as well&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 13:15:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21949#M58508</guid>
      <dc:creator>cstueckrath</dc:creator>
      <dc:date>2018-08-24T13:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21950#M58509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Christian&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is a CA that was created. not all of the users report errors&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find attached some details&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 13:24:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21950#M58509</guid>
      <dc:creator>Felipe_Muraska</dc:creator>
      <dc:date>2018-08-24T13:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21951#M58510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Felipe,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please hit F12 on your browser, go to "Security" tab and check what errors the browser found.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post them here so we can further help you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 13:26:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21951#M58510</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-08-24T13:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21952#M58511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also, do I need to upload that certificate to the Trusted CA tabs on HTTPS inspcetion ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 13:26:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21952#M58511</guid>
      <dc:creator>Felipe_Muraska</dc:creator>
      <dc:date>2018-08-24T13:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21953#M58512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see the root ca certificate as not trusted. You have to import it to your computer's trusted root CAs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 13:27:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21953#M58512</guid>
      <dc:creator>cstueckrath</dc:creator>
      <dc:date>2018-08-24T13:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21954#M58513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;its been imported already on customer network, the screenshot was just from my computer ( not part of customer network). but still errors are generated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 13:29:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21954#M58513</guid>
      <dc:creator>Felipe_Muraska</dc:creator>
      <dc:date>2018-08-24T13:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21955#M58514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pedro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I`m trying to get a testing machine on customer`s environment to begin testing to replicate the issue, just wanted to see if anyone else had this problem and how they solved since the issue does not appear to all customers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 13:30:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21955#M58514</guid>
      <dc:creator>Felipe_Muraska</dc:creator>
      <dc:date>2018-08-24T13:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21956#M58515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;find an affected client and look at the certificate chain of the failing certificate.&lt;/P&gt;&lt;P&gt;Figure out, if the root ca cert is&lt;/P&gt;&lt;OL style="list-style-type: lower-alpha;"&gt;&lt;LI&gt;displayed&lt;/LI&gt;&lt;LI&gt;trusted&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;If it is not trusted, look at the trusted store. Figure out, why it is not there or why it doesn't match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, try to find out if all https sites fail or just some (might be related to sk104717)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 13:36:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21956#M58515</guid>
      <dc:creator>cstueckrath</dc:creator>
      <dc:date>2018-08-24T13:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21957#M58516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, will check on that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, do I need to upload that certificate to the Trusted CA tabs on HTTPS inspcetion ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 13:46:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21957#M58516</guid>
      <dc:creator>Felipe_Muraska</dc:creator>
      <dc:date>2018-08-24T13:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21958#M58517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It should be not needed , did you select in the https policy the right certificate that you have uploaded to the management?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 15:47:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21958#M58517</guid>
      <dc:creator>Marco_Valenti</dc:creator>
      <dc:date>2018-08-24T15:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21959#M58518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the issue does not appear to all&amp;nbsp;users it might be a failure to deploy the CA certificate to all costumers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the screeshots you sent it seems to be a simple issue of untrusted CA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should hit F12 and check the Security tab, where the browser will tell you exactly why the connection is not safe.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 19:40:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21959#M58518</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-08-24T19:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21960#M58519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Crhis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to replicate the issue in the lab and sk104717 was spot on for the bank APPs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the browser Im thinking its a issue on the deployment, since it on my lab worked fine using the CP certificate to all URLs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 19:44:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21960#M58519</guid>
      <dc:creator>Felipe_Muraska</dc:creator>
      <dc:date>2018-08-24T19:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21961#M58520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another thing came up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I enabled the enhanced_ssl_inspection for non browser APPS would work and worked great, however I stopped servind my ceritificate to the users, is there a way to fix that ? non browser APPs work and as well my certificate is delivered to end user ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Aug 2018 21:33:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21961#M58520</guid>
      <dc:creator>Felipe_Muraska</dc:creator>
      <dc:date>2018-08-27T21:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21962#M58521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you mean&amp;nbsp;by&amp;nbsp;"stopped serving the certificate to the end user"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some apps use their own CA certificates repository, not the repository of the system. For instance, Firefox browser does not read the certificates installed in Windows, you have to install it again to the Firefox repository.&amp;nbsp;Check if&amp;nbsp;any of your Apps or browsers have this problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Aug 2018 16:23:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-errors/m-p/21962#M58521</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-08-29T16:23:08Z</dc:date>
    </item>
  </channel>
</rss>

