<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Gateways fail to download IoC feed - peer certificate cannot be authenticated with given CA certific in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Gateways-fail-to-download-IoC-feed-peer-certificate-cannot-be/m-p/215561#M35625</link>
    <description>&lt;P&gt;I am running R81.10 with GA Jumbo take 139 installed.&lt;/P&gt;
&lt;P&gt;I have a custom IoC feed set to use the Talos blacklist and noticed in my logs the list is failing to update -&lt;/P&gt;
&lt;P&gt;"External IOC - External Indicators processing failed&lt;BR /&gt;Talos_blacklist: Failed to fetch feed. Resource: &lt;A href="https://www.talosintelligence.com/documents/ip-blacklist" target="_blank"&gt;https://www.talosintelligence.com/documents/ip-blacklist&lt;/A&gt;, Reason: Peer certificate cannot be authenticated with given CA certificates"&lt;/P&gt;
&lt;P&gt;I have followed&amp;nbsp;&lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;sk169919 and added the websites certificate as well as it's root certificate in the "Trusted CAs" portion of SmartDashboard's HTTPS Inspection, saved my changes, installed access control policy, and the IoC feed still fails to update for the same reason.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;I am adding the certificates by going to Actions &amp;gt; "Import outbound Certificate".&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;I don't know what I am missing to make this work?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="css-96coje"&gt;&lt;HR /&gt;&lt;/DIV&gt;
&lt;DIV class="css-1giyqeu"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Wed, 29 May 2024 19:01:28 GMT</pubDate>
    <dc:creator>Mike_Jensen</dc:creator>
    <dc:date>2024-05-29T19:01:28Z</dc:date>
    <item>
      <title>Gateways fail to download IoC feed - peer certificate cannot be authenticated with given CA certific</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Gateways-fail-to-download-IoC-feed-peer-certificate-cannot-be/m-p/215561#M35625</link>
      <description>&lt;P&gt;I am running R81.10 with GA Jumbo take 139 installed.&lt;/P&gt;
&lt;P&gt;I have a custom IoC feed set to use the Talos blacklist and noticed in my logs the list is failing to update -&lt;/P&gt;
&lt;P&gt;"External IOC - External Indicators processing failed&lt;BR /&gt;Talos_blacklist: Failed to fetch feed. Resource: &lt;A href="https://www.talosintelligence.com/documents/ip-blacklist" target="_blank"&gt;https://www.talosintelligence.com/documents/ip-blacklist&lt;/A&gt;, Reason: Peer certificate cannot be authenticated with given CA certificates"&lt;/P&gt;
&lt;P&gt;I have followed&amp;nbsp;&lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;sk169919 and added the websites certificate as well as it's root certificate in the "Trusted CAs" portion of SmartDashboard's HTTPS Inspection, saved my changes, installed access control policy, and the IoC feed still fails to update for the same reason.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;I am adding the certificates by going to Actions &amp;gt; "Import outbound Certificate".&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;I don't know what I am missing to make this work?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="css-96coje"&gt;&lt;HR /&gt;&lt;/DIV&gt;
&lt;DIV class="css-1giyqeu"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 29 May 2024 19:01:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Gateways-fail-to-download-IoC-feed-peer-certificate-cannot-be/m-p/215561#M35625</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2024-05-29T19:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways fail to download IoC feed - peer certificate cannot be authenticated with given CA cert</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Gateways-fail-to-download-IoC-feed-peer-certificate-cannot-be/m-p/215562#M35626</link>
      <description>&lt;P&gt;Did you choose the right format?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 19:07:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Gateways-fail-to-download-IoC-feed-peer-certificate-cannot-be/m-p/215562#M35626</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-29T19:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways fail to download IoC feed - peer certificate cannot be authenticated with given CA cert</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Gateways-fail-to-download-IoC-feed-peer-certificate-cannot-be/m-p/215575#M35632</link>
      <description>&lt;P&gt;Do you include all the intermediate CAs that are needed to validate the cert?&lt;BR /&gt;You might also try the workaround in:&amp;nbsp; &lt;A href="https://support.checkpoint.com/results/sk/sk169919" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk169919&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 20:06:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Gateways-fail-to-download-IoC-feed-peer-certificate-cannot-be/m-p/215575#M35632</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-29T20:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways fail to download IoC feed - peer certificate cannot be authenticated with given CA cert</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Gateways-fail-to-download-IoC-feed-peer-certificate-cannot-be/m-p/215578#M35635</link>
      <description>&lt;P&gt;I ended up manually updating the trusted CA's list by downloading the .zip from the link in&amp;nbsp;&lt;SPAN&gt;sk64521, then I followed the rest of that sk to install on my SMS, installed access control policy, and the IoC feed update is now successful.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 20:14:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Gateways-fail-to-download-IoC-feed-peer-certificate-cannot-be/m-p/215578#M35635</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2024-05-29T20:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Gateways fail to download IoC feed - peer certificate cannot be authenticated with given CA cert</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Gateways-fail-to-download-IoC-feed-peer-certificate-cannot-be/m-p/215579#M35636</link>
      <description>&lt;P&gt;I must have been missing the intermediate CA's.&amp;nbsp; Fortunately the latest Check Point updated CA&amp;nbsp; list has all of the certs I needed.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 20:16:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Gateways-fail-to-download-IoC-feed-peer-certificate-cannot-be/m-p/215579#M35636</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2024-05-29T20:16:25Z</dc:date>
    </item>
  </channel>
</rss>

