<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ckpSSL ssl lib error in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31117#M92242</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yikes, that brings back some memories &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Oct 2018 15:59:39 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-10-03T15:59:39Z</dc:date>
    <item>
      <title>ckpSSL ssl lib error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31108#M92233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was wondering whether anybody has either seen the error below before or know how to fix it.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71031_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;I have already consulted sk97691 but it doesn't seem to cover the error above.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Many thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 10:49:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31108#M92233</guid>
      <dc:creator>Nick_Doropoulos</dc:creator>
      <dc:date>2018-09-28T10:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: ckpSSL ssl lib error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31109#M92234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A couple questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What version of Management is this? Assuming it was upgraded at some point, what version from?&lt;/LI&gt;&lt;LI&gt;What version of Gateway are you attempting to manage?&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 17:31:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31109#M92234</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-28T17:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: ckpSSL ssl lib error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31110#M92235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for responding Dameon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both questions are valid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Management version is 80.20 while the gateway's version is R70.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It goes without saying that the above deployment is not recommended by any means but my team and I were interested in figuring out whether such an implementation would be feasible. The work I've done so far took place in a virtualized environment. Please see the steps taken below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Connectivity between the server and the gateway is successful.&lt;/LI&gt;&lt;LI&gt;Time is set the same on both endpoints.&lt;/LI&gt;&lt;LI&gt;License has been installed on&amp;nbsp;both machines.&lt;/LI&gt;&lt;LI&gt;The gateway has been configured with the right settings as far as I can see:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71093_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The gateway’s initial policy has been uninstalled (with fw unloadlocal).&lt;/LI&gt;&lt;LI&gt;The gateway is listening on port 18191 (with netstat -nap | grep 18191).&lt;/LI&gt;&lt;LI&gt;Captured SIC traffic with the following:&lt;/LI&gt;&lt;LI&gt;Tcpdump -i eth0 port 18191 -w SIC_traffic.pcap&lt;/LI&gt;&lt;LI&gt;Clicked on “Test SIC status” button to capture the interesting traffic.&lt;/LI&gt;&lt;LI&gt;Upon opening the captured traffic on Wireshark, the 3-way TCP handshake is visible, along with the Client/Server hello packets but it ends with a decrypt error:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71094_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Due to the “packet size limited during capture” messages seen on Wireshark, I re-run tcpdump with the following syntax to capture the full packet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tcpdump -vvvi eth0 port 18191 -s0 -w SIC_entirepacket.pcap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The result is the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71095_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;The TLS-handshake is now more detailed but again the gateway resets the connection as it can’t decrypt the packet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Any help or insight would be much appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2018 10:50:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31110#M92235</guid>
      <dc:creator>Nick_Doropoulos</dc:creator>
      <dc:date>2018-10-01T10:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: ckpSSL ssl lib error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31111#M92236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Backwards compatibility for an R80.20 SMS only extends back to gateway version R75.20, so having your SMS attempt to communicate with an R70 gateway is not supported.&amp;nbsp; Is there some special reason you are using a version of software on the gateway that has not been supported for several years?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2018 12:14:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31111#M92236</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-10-01T12:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: ckpSSL ssl lib error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31112#M92237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We only considered it due to a certain customer's production network though we were almost certain that the experiment wouldn't work anyway....&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From a closer technical perspective however, would you say that it is the newer TLS ciphers that a gateway as old as R70 wouldn't support, hence being unable to decrypt the SIC traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2018 12:28:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31112#M92237</guid>
      <dc:creator>Nick_Doropoulos</dc:creator>
      <dc:date>2018-10-01T12:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: ckpSSL ssl lib error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31113#M92238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Possibly, a gateway that old will try to use 3DES instead of AES for SIC encryption, and may also try to use the deprecated SHA-1 algorithm instead of SHA-256 which the R80.20 SMS will definitely not like.&amp;nbsp; A gateway that old may also try to use the deprecated SSL protocol instead of TLS.&amp;nbsp; Just because you can set the version on the gateway object to something that old prior to R75.20 doesn't mean everything will still work.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2018 12:38:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31113#M92238</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-10-01T12:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: ckpSSL ssl lib error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31114#M92239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;True, thanks very much for your input!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2018 12:40:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31114#M92239</guid>
      <dc:creator>Nick_Doropoulos</dc:creator>
      <dc:date>2018-10-01T12:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: ckpSSL ssl lib error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31115#M92240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What you're seeing is expected behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default hash used for certificates generated by the ICA is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Releases prior to R80: SHA1&lt;/LI&gt;&lt;LI&gt;R80 and above: SHA256&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;R71 was the first release to support SHA256 certificates.&lt;/P&gt;&lt;P&gt;That means for any R80+ manager trying to gateway prior to R71, if you attempt to establish SIC, it will surely fail.&amp;nbsp;&lt;/P&gt;&lt;P&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103840" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103840"&gt;SHA-1 and SHA-256 certificates in Check Point Internal CA (ICA)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, if you were managing the gateway in R77.30 and then upgraded that manager to R80+, you could still push policy to the gateway.&lt;/P&gt;&lt;P&gt;In fact, I tested this myself by upgrading an R77.30 Manager to R80.10 and pushing policy to an R65 gateway.&lt;/P&gt;&lt;P&gt;While completely and totally unsupported, it worked.&amp;nbsp;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;However, if I ever regenerate the SIC certificate for this gateway, SIC would likely start failing because of this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2018 16:16:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31115#M92240</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-01T16:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: ckpSSL ssl lib error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31116#M92241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmmm. Maybe you can help me with a block on rule 995 in my R65 gateway &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2018 14:14:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31116#M92241</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2018-10-03T14:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: ckpSSL ssl lib error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31117#M92242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yikes, that brings back some memories &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2018 15:59:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ckpSSL-ssl-lib-error/m-p/31117#M92242</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-03T15:59:39Z</dc:date>
    </item>
  </channel>
</rss>

