<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTPS Inspection: &amp;quot;Certificate chain is inconsistent&amp;quot; for wildcard domain? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-quot-Certificate-chain-is-inconsistent-quot-for/m-p/168793#M28077</link>
    <description>&lt;P&gt;Browsing to a website such as &lt;A href="http://www.thisdomain.io" target="_blank" rel="noopener"&gt;www.thisdomain.io&lt;/A&gt; which uses a *.thisdomain.io wildcard certificate and the firewall blocks it saying&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;"Certificate chain is inconsistent. Certificate DN: 'CN=*.thisdomain.io' Requested Server Name: &lt;A href="http://www.thisdomain.io" target="_blank" rel="noopener"&gt;www.thisdomain.io&lt;/A&gt; See sk159872"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Everything in sk article checks out and I'm not seeing any issues. What's odd is the example in the sk even shows a wildcard. Is it having an issue with the .io TLD?&lt;/P&gt;&lt;P&gt;What's even odder is that the website works sporadically. No issues if browsing the website off-premise (i.e. not going through a cpfw). R81.10 latest JHF.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jan 2023 18:11:32 GMT</pubDate>
    <dc:creator>B_P</dc:creator>
    <dc:date>2023-01-23T18:11:32Z</dc:date>
    <item>
      <title>HTTPS Inspection: "Certificate chain is inconsistent" for wildcard domain?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-quot-Certificate-chain-is-inconsistent-quot-for/m-p/168793#M28077</link>
      <description>&lt;P&gt;Browsing to a website such as &lt;A href="http://www.thisdomain.io" target="_blank" rel="noopener"&gt;www.thisdomain.io&lt;/A&gt; which uses a *.thisdomain.io wildcard certificate and the firewall blocks it saying&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;"Certificate chain is inconsistent. Certificate DN: 'CN=*.thisdomain.io' Requested Server Name: &lt;A href="http://www.thisdomain.io" target="_blank" rel="noopener"&gt;www.thisdomain.io&lt;/A&gt; See sk159872"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Everything in sk article checks out and I'm not seeing any issues. What's odd is the example in the sk even shows a wildcard. Is it having an issue with the .io TLD?&lt;/P&gt;&lt;P&gt;What's even odder is that the website works sporadically. No issues if browsing the website off-premise (i.e. not going through a cpfw). R81.10 latest JHF.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 18:11:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-quot-Certificate-chain-is-inconsistent-quot-for/m-p/168793#M28077</guid>
      <dc:creator>B_P</dc:creator>
      <dc:date>2023-01-23T18:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection: "Certificate chain is inconsistent" for wildcard domain?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-quot-Certificate-chain-is-inconsistent-quot-for/m-p/168812#M28086</link>
      <description>&lt;P&gt;See if below helps:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/HTTPS-Certificate-validation-SK159872/td-p/131158" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/HTTPS-Certificate-validation-SK159872/td-p/131158&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Btw, I dont think TLD matters here at all.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 21:49:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-quot-Certificate-chain-is-inconsistent-quot-for/m-p/168812#M28086</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-23T21:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection: "Certificate chain is inconsistent" for wildcard domain?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-quot-Certificate-chain-is-inconsistent-quot-for/m-p/168840#M28092</link>
      <description>&lt;P&gt;This is most likely a side effect of SNI Verification and something on the remote end that isn't configured correctly...perhaps on only on one server in a pool of them.&lt;BR /&gt;You might need the TAC to assist in debugging this.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 04:28:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-quot-Certificate-chain-is-inconsistent-quot-for/m-p/168840#M28092</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-24T04:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection: "Certificate chain is inconsistent" for wildcard domain?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-quot-Certificate-chain-is-inconsistent-quot-for/m-p/168861#M28097</link>
      <description>&lt;P&gt;You could check &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105559&amp;amp;partition=Advanced&amp;amp;product=HTTPS" target="_blank" rel="noopener"&gt;sk105559 -&amp;nbsp;&lt;/A&gt;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105559&amp;amp;partition=Advanced&amp;amp;product=HTTPS" target="_blank" rel="noopener"&gt;How to debug the WSTLSD daemon&lt;/A&gt; also.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 09:05:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-quot-Certificate-chain-is-inconsistent-quot-for/m-p/168861#M28097</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-01-24T09:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection: "Certificate chain is inconsistent" for wildcard domain?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-quot-Certificate-chain-is-inconsistent-quot-for/m-p/169944#M28255</link>
      <description>&lt;P&gt;Looks like there's no issues:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;WSTLSD log:&lt;BR /&gt;&lt;P&gt;[1 Feb 9:39:12] fwCert_cache::val_free: free fwCert from Cache. refCount: 0, CN=*.thisdomain.io&lt;BR /&gt;[1 Feb 9:39:12] fwCert_cache::Put: added fwCert 0xab10200 to cache&lt;BR /&gt;[1 Feb 9:39:12] fwCert_cache::Get: added new cert object to cache: *.thisdomain.io&lt;BR /&gt;[1 Feb 9:39:12] fwCert_cache::Get: cache hit for : 16&lt;BR /&gt;[1 Feb 9:39:12] cpSRSA_imp::Verify: Entering...&lt;BR /&gt;[1 Feb 9:39:12] kmsg_read_local: 9 kmsgs handled&lt;/P&gt;&lt;P&gt;[1 Feb 9:39:12] Comparing SNI &lt;A href="http://www.thisdomain.io" target="_blank"&gt;www.thisdomain.io&lt;/A&gt; against 2 alternative names&lt;BR /&gt;[1 Feb 9:39:12] SNI matches alternate name *.thisdomain.io&lt;BR /&gt;[1 Feb 9:39:12] Comparing SNI &lt;A href="http://www.thisdomain.io" target="_blank"&gt;www.thisdomain.io&lt;/A&gt; against 2 alternative names&lt;BR /&gt;[1 Feb 9:39:12] SNI matches alternate name *.thisdomain.io&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 15:49:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-quot-Certificate-chain-is-inconsistent-quot-for/m-p/169944#M28255</guid>
      <dc:creator>B_P</dc:creator>
      <dc:date>2023-02-01T15:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection: "Certificate chain is inconsistent" for wildcard domain?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-quot-Certificate-chain-is-inconsistent-quot-for/m-p/169949#M28256</link>
      <description>&lt;P&gt;I scanned it with Qualys and it got a B grade as it has chain, alternative name and SNI issues...... I guess I'll reach out to them.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 16:03:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-quot-Certificate-chain-is-inconsistent-quot-for/m-p/169949#M28256</guid>
      <dc:creator>B_P</dc:creator>
      <dc:date>2023-02-01T16:03:45Z</dc:date>
    </item>
  </channel>
</rss>

