<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;The server certificate chain is incomplete&amp;quot; SSL Labs VPN validation in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/quot-The-server-certificate-chain-is-incomplete-quot-SSL-Labs/m-p/92199#M18361</link>
    <description>&lt;P&gt;What you upload to SmartDashboard should include the relevant certificate as well as all the intermediate certificates.&lt;BR /&gt;This is also necessary for some clients as well.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jul 2020 22:15:05 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-07-22T22:15:05Z</dc:date>
    <item>
      <title>"The server certificate chain is incomplete" SSL Labs VPN validation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/quot-The-server-certificate-chain-is-incomplete-quot-SSL-Labs/m-p/92151#M18346</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We use a wildcard certificate purchased from a well known CA for our SSL-VPN portal.&lt;/P&gt;&lt;P&gt;When browsing to our VPN site everything's seems OK with the cert and the cert path.&lt;/P&gt;&lt;P&gt;When using SSL-Labs to check our VPN site it gives a score B due to "The server certificate chain is incomplete".&lt;/P&gt;&lt;P&gt;In the certificate path it shows:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="ssllabs.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7345i0BD928978A05F79E/image-size/large?v=v2&amp;amp;px=999" role="button" title="ssllabs.JPG" alt="ssllabs.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the "Extra Download" means that that part of the chain isn't in the FW's trusted root?&lt;/P&gt;&lt;P&gt;How should I approach this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 10:54:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/quot-The-server-certificate-chain-is-incomplete-quot-SSL-Labs/m-p/92151#M18346</guid>
      <dc:creator>Arnon_Azmon</dc:creator>
      <dc:date>2020-07-22T10:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: "The server certificate chain is incomplete" SSL Labs VPN validation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/quot-The-server-certificate-chain-is-incomplete-quot-SSL-Labs/m-p/92159#M18350</link>
      <description>&lt;P&gt;You need to provide to SSL Labs the whole chain of certificates. The certificate file shall include one after another: Root CA cert + Intermediate certs (if any) +&amp;nbsp; SSL VPN cert. Don't think the order is important...&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 13:17:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/quot-The-server-certificate-chain-is-incomplete-quot-SSL-Labs/m-p/92159#M18350</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-07-22T13:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: "The server certificate chain is incomplete" SSL Labs VPN validation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/quot-The-server-certificate-chain-is-incomplete-quot-SSL-Labs/m-p/92161#M18351</link>
      <description>&lt;P&gt;If I understand you correctly, you mean that the certificate I uploaded to SmartDashboard and use for the VPN portal doesn't include the intermediate cert, which doesn't bother the FW nor the users' browsers, but it does bother the SSL Labs' test?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 13:58:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/quot-The-server-certificate-chain-is-incomplete-quot-SSL-Labs/m-p/92161#M18351</guid>
      <dc:creator>Arnon_Azmon</dc:creator>
      <dc:date>2020-07-22T13:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: "The server certificate chain is incomplete" SSL Labs VPN validation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/quot-The-server-certificate-chain-is-incomplete-quot-SSL-Labs/m-p/92199#M18361</link>
      <description>&lt;P&gt;What you upload to SmartDashboard should include the relevant certificate as well as all the intermediate certificates.&lt;BR /&gt;This is also necessary for some clients as well.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 22:15:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/quot-The-server-certificate-chain-is-incomplete-quot-SSL-Labs/m-p/92199#M18361</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-22T22:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: "The server certificate chain is incomplete" SSL Labs VPN validation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/quot-The-server-certificate-chain-is-incomplete-quot-SSL-Labs/m-p/92206#M18363</link>
      <description>&lt;P&gt;( I am sorry for the late reply I am not getting notifications from CheckMates lately for some reason. )&lt;/P&gt;
&lt;P&gt;To your question... Yes, what PhoneBoy said, it is best to pack all the chain and upload it to SmartConsole.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 03:32:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/quot-The-server-certificate-chain-is-incomplete-quot-SSL-Labs/m-p/92206#M18363</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-07-23T03:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: "The server certificate chain is incomplete" SSL Labs VPN validation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/quot-The-server-certificate-chain-is-incomplete-quot-SSL-Labs/m-p/92211#M18365</link>
      <description>&lt;P&gt;OK, thank you both, I'll give it a try and update&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 05:16:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/quot-The-server-certificate-chain-is-incomplete-quot-SSL-Labs/m-p/92211#M18365</guid>
      <dc:creator>Arnon_Azmon</dc:creator>
      <dc:date>2020-07-23T05:16:24Z</dc:date>
    </item>
  </channel>
</rss>

