<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256433#M43192</link>
    <description>&lt;P&gt;If you are just doing straight VPN RAS connectivity (not SAML) then the first time you connect (unless you pre-populate the registry, which is what you do for a enterprise deployment) you get prompted to trust the fingerprint of the&amp;nbsp;&lt;EM&gt;CA certificate&lt;/EM&gt; for the CA that signed the gateway's VPN RAS certificate. So if you just use the SmartCenter issued gateway certificate you're trusting the ICA certificate, if you use an external CA you are trusting that. It doesn't use OCSP/CRL.&lt;/P&gt;
&lt;P&gt;Things are a bit different with SAML because the VPN client uses a browser to make the connection so it can handle the IDP authentication - in this case the browser or OS certificate store needs to trust the gateway's certificate and it would use OCSP/CRL - but it is the browser doing it, not the VPN client itself. And browsers would have moved to a current protocol a long time ago.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Sep 2025 20:59:39 GMT</pubDate>
    <dc:creator>Paul_Hagyard</dc:creator>
    <dc:date>2025-09-02T20:59:39Z</dc:date>
    <item>
      <title>IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2025</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256210#M43136</link>
      <description>&lt;P&gt;Hi CheckMates!&lt;/P&gt;
&lt;P&gt;This message is relevant &lt;STRONG&gt;only&lt;/STRONG&gt; for customers using VPN Site-to-Site and Remote Access VPN Security Gateways &lt;STRONG&gt;using certificates issued by DigiCert External CA&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;No action is required if DigiCert External CA is not deployed on your Security Gateways.&amp;nbsp;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;To check if your VPN/Remote Access Security Gateways use DigiCert External CA, follow these simple steps &lt;A contenteditable="false" href="https://support.checkpoint.com/results/sk/sk183884" target="_blank" rel="noopener"&gt;in the sk183884&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;On September 8, 2025, DigiCert will &lt;A contenteditable="false" href="https://docs.digicert.com/en/whats-new/change-log/certcentral-change-log.html#digicert-ending-support-for-http-1-0-connections-for-ocsp-and-crl-certificate-status-verification-checks-619426" target="_blank" rel="noopener"&gt;stop supporting HTTP/1.0&lt;/A&gt;&amp;nbsp;for OCSP and CRL checks. Without upgrading protocol support, DigiCert certificate validation may fail, and will affect Site-to-Site and Remote Access VPNs on Check Point gateways.&lt;/P&gt;
&lt;P&gt;To maintain VPN continuity, a tool has been provided to identify VPN/Remote Access gateways using the DigiCert External Certificate, followed by a hotfix update to be applied on the gateway, upgrading communication to HTTP 1.1.&lt;/P&gt;
&lt;P&gt;All information regarding affected Security Gateways, using the discovery tool, and the hotfix is available &lt;A contenteditable="false" href="https://support.checkpoint.com/results/sk/sk183884" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Support services are available for questions or assistance at &lt;A title="https://protect.checkpoint.com/v2/r02/___https://click.checkpoint.com/NzUwLURRSC01MjgAAAGclSoW5GA2_ezUd6Ml0sNfcH-7YUQdTUtbNuUv8mDTpzTqUPusbKyXVnDoMct0UqVr23TPHR8=___.YzJlOmNwYWxsOmM6bzoxNzYxYWZlZWU1ZTEyZjFmOTZlMGYwMjQzMWQyOTZkZDo3OmUxYmE6ZjNjNjg3YmE0ZTY1M2ZmNzUzOTMyYTg0ZTNjMzc5OWU1MWY0MzBjYjljN2Y5MzRmOTUxZDU4MWNhMmRjOGYwODpoOlQ6Tg" contenteditable="false" href="https://protect.checkpoint.com/v2/r02/___https://click.checkpoint.com/NzUwLURRSC01MjgAAAGclSoW5GA2_ezUd6Ml0sNfcH-7YUQdTUtbNuUv8mDTpzTqUPusbKyXVnDoMct0UqVr23TPHR8=___.YzJlOmNwYWxsOmM6bzoxNzYxYWZlZWU1ZTEyZjFmOTZlMGYwMjQzMWQyOTZkZDo3OmUxYmE6ZjNjNjg3YmE0ZTY1M2ZmNzUzOTMyYTg0ZTNjMzc5OWU1MWY0MzBjYjljN2Y5MzRmOTUxZDU4MWNhMmRjOGYwODpoOlQ6Tg" target="_blank" rel="noopener"&gt;https://www.checkpoint.com/support-services/contact-support/&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;UPDATE&lt;/STRONG&gt;:&amp;nbsp;&lt;STRONG&gt;The SK now has all hotfixes you might need directly linked, as we al the scripts and verification steps to make sure you might need them&lt;/STRONG&gt;&lt;/H4&gt;
&lt;H4&gt;&lt;STRONG&gt;UPDATE 2: For those with outbound HTTPS Inspection, there is another SK available:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk183887" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk183887&lt;/A&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;H4&gt;&lt;STRONG&gt;UPDATE 3:&amp;nbsp;DigiCert Certificate Expiration Mitigated&lt;/STRONG&gt; &amp;nbsp;&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;We are pleased to share that we have successfully mitigated the DigiCert certificate issue together with DigiCert’s engineering team. There is no need to urgently install a Hotfix on the Security Gateways. &amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Your Check Point Security Gateways using Site-to-Site VPN, Remote Access VPN, and Outbound HTTPS Inspection will continue to operate smoothly beyond the September 8, 2025 timeline, even without applying the hotfix in advance.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;That said, our latest Jumbo Hotfix Accumulator changes the communication method from HTTP/1.0 to HTTP/1.1, ensuring long-term compatibility with all certificate authority services. We strongly recommend that you install it at your convenience. More details can be found here.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;As always, we remain at your service and are here to support you with this or any other issue.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2025 09:03:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256210#M43136</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-09-04T09:03:49Z</dc:date>
    </item>
    <item>
      <title>DigiCert HTTP 1.0 Deprecation sk183884</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256204#M43137</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;We were just alerted to this which requires action in the next week. Looking at the SK it says the remediation for gateways is to open a ticket with support&lt;/P&gt;
&lt;P&gt;Is there a better way?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 14:02:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256204#M43137</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2025-08-29T14:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert HTTP 1.0 Deprecation sk183884</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256206#M43138</link>
      <description>&lt;P&gt;The mentioned SK is still a work in progress. All required hotfixes and also a script to check whether you even need them should be available in the SK quite soon.&lt;BR /&gt;&lt;BR /&gt;The better way is to wait till it is finalized and all tools to get everything under control are available there.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 14:20:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256206#M43138</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-08-29T14:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert HTTP 1.0 Deprecation sk183884</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256207#M43139</link>
      <description>&lt;P&gt;ok, thanks&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 14:23:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256207#M43139</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2025-08-29T14:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: DigiCert HTTP 1.0 Deprecation sk183884</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256208#M43140</link>
      <description>&lt;P&gt;Once everything is in place, we will create a post and merge all related discussions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 14:33:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256208#M43140</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-08-29T14:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256213#M43141</link>
      <description>&lt;P&gt;Thanks for that Val.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 15:48:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256213#M43141</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-29T15:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256218#M43142</link>
      <description>&lt;P&gt;I contacted Digicert support, and this affects all Digicert brands, which include GeoTrust and RapidSSL. The discovery tool provided in the SK only checks for a string provide on the command line so it should be run three times for each CA string:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&amp;nbsp;./DigiCert_CA_search.sh DigiCert&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;./DigiCert_CA_search.sh GeoTrust&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;./DigiCert_CA_search.sh RapidSSL&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 18:11:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256218#M43142</guid>
      <dc:creator>Alex_Lewis</dc:creator>
      <dc:date>2025-08-29T18:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256220#M43143</link>
      <description>&lt;P&gt;Thanks for that&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7612"&gt;@Alex_Lewis&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 18:25:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256220#M43143</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-29T18:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256229#M43146</link>
      <description>&lt;P&gt;While there may be some additional updates to the SK, including the script that tests whether a hotfix is needed,&amp;nbsp;we now have patches that can be deployed on top of the most recent JHF for releases going back to R80.40 as well as updated firmware for Quantum Spark appliances.&lt;BR /&gt;This fix will be rolled into Jumbo Hotfixes also.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 20:38:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256229#M43146</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-08-29T20:38:58Z</dc:date>
    </item>
    <item>
      <title>VPN Site-to-Site and Remote Access VPN Security Gateways using certificates issued by DigiCert</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256233#M43148</link>
      <description>&lt;P&gt;how to check this via cli if firewalls have site to site and remote access and digicert. i only have 2 firewalls i am literally new to checkpoint and i wamt to check this manually i also dont have smart console.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Aug 2025 02:24:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256233#M43148</guid>
      <dc:creator>baby79</dc:creator>
      <dc:date>2025-08-30T02:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site-to-Site and Remote Access VPN Security Gateways using certificates issued by DigiCert</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256241#M43149</link>
      <description>&lt;P&gt;Read&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk183884," target="_blank"&gt;https://support.checkpoint.com/results/sk/sk183884,&lt;/A&gt;&amp;nbsp;it has all the information you need.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Aug 2025 07:49:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256241#M43149</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-08-30T07:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256272#M43152</link>
      <description>&lt;P&gt;The SK article is not that clear... I just posted the following under "was this page helpful":&lt;/P&gt;
&lt;P&gt;"The SK article mentions a hotfix to fix issues with site-to-site VPNs or remote access VPNs with user certificates signed by Digicert, but it then discusses checking the GATEWAY certificate to see if it is signed by Digicert. Is the issue with VPN RAS user certs, gateway certs, or both?"&lt;/P&gt;
&lt;P&gt;We have a customer using a Digicert certificate on the gateway side in conjunction with SAML for VPN RAS. In such a scenario it should only be the client doing OCSP/CRL checks, not the gateway. Endpoint Security simply trusts the site's CA certificate fingerprint (which always seemed inadequate), but with SAML the client launches a browser (OS now by default I think) to connect so THAT should handle the OCSP/CRL check.&lt;/P&gt;
&lt;P&gt;It sounds like it should only be an issue for the gateway if it is doing checks itself - for site-to-site VPNs or with user certificates, correct?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 00:41:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256272#M43152</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2025-09-01T00:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256273#M43153</link>
      <description>&lt;P&gt;I believe those scripts mentioned should verify that.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 01:13:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256273#M43153</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-01T01:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256276#M43154</link>
      <description>&lt;P&gt;Where are the scripts mentioned? Looking through&amp;nbsp;sk183884 I can only see CLI commands like "enabled_blades"&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 02:37:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256276#M43154</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2025-09-01T02:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256279#M43155</link>
      <description>&lt;P&gt;I believe ones&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7612"&gt;@Alex_Lewis&lt;/a&gt;&amp;nbsp; mentioned should be there. Hard to check it on my phone, but will have a look in a bit.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 02:44:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256279#M43155</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-01T02:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256280#M43156</link>
      <description>&lt;P&gt;You are 100% correct, my apologies. I could have sworn I saw one script mentioned on Friday, but guess must have been removed.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 03:26:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256280#M43156</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-01T03:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256283#M43157</link>
      <description>&lt;P&gt;Hello Check Mates&lt;BR /&gt;&lt;BR /&gt;what about Digicert Certificates which are used on portals?&lt;BR /&gt;like for Mobile Access blade or other platform portals?&lt;BR /&gt;&lt;BR /&gt;do we face the same issue here?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 06:14:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256283#M43157</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2025-09-01T06:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256287#M43158</link>
      <description>&lt;P&gt;It looks like it is when the gateway is doing the OCSP/CRL, so it should only apply:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Site-to-site VPNs where the remote party to the Check Point environment is using Digicert certificates (instead of PSK).&lt;/LI&gt;
&lt;LI&gt;Remote access VPNs where the remote user is using Digicert certificates as part of the authentication.&lt;/LI&gt;
&lt;LI&gt;Outbound HTTPS inspection.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;So all other scenarios, such as Digicert certificates on gateway portals (server certificates) should not be an issue.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 07:02:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256287#M43158</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2025-09-01T07:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256314#M43163</link>
      <description>&lt;P&gt;I checked the Article on saterday and today (monday) but there is no script attached to the SK article.&lt;/P&gt;
&lt;P&gt;As we need to put automation to work to go over our installed base we are in serious need of a way to avoiud many hours of work just to learn which customer are effected by this issue.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 12:18:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256314#M43163</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2025-09-01T12:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: IMPORTANT - Action Required For VPN/Remote Access Security Gateways Using DigiCert - by Sep 8, 2</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256316#M43164</link>
      <description>&lt;P&gt;Im 100% positive there was a script there on Friday, August 29th, I saw it myself.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 12:30:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IMPORTANT-Action-Required-For-VPN-Remote-Access-Security/m-p/256316#M43164</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-01T12:30:03Z</dc:date>
    </item>
  </channel>
</rss>

