<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection, SNI and CN in generated certificate in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-SNI-and-CN-in-generated-certificate/m-p/36631#M7706</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;BR /&gt;we are facing simiar issues at a customers environment with SNI and don't really have a solution, yet.&lt;BR /&gt;This is a reason to attend R80.30 EA because of SNI improvement and I am curious about the testing results.&lt;BR /&gt;cheers&lt;BR /&gt;Vincent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Feb 2019 14:16:23 GMT</pubDate>
    <dc:creator>Vincent_Bacher</dc:creator>
    <dc:date>2019-02-27T14:16:23Z</dc:date>
    <item>
      <title>HTTPS Inspection, SNI and CN in generated certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-SNI-and-CN-in-generated-certificate/m-p/36630#M7705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We're having the following issue:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Security Gateway with Application Control/URL Filtering/HTTPS inspection (R80.10)&lt;/LI&gt;&lt;LI&gt;Improved HTTPS Inspection Bypass feature (Probe Bypass) as per sk104717 not enabled&lt;/LI&gt;&lt;LI&gt;Client wants to access a certain URL (let's call it &lt;A href="https://host.inter.net/)"&gt;https://host.inter.net/)&lt;/A&gt; and connects to IP of this host via port 443. IP is hosted on AWS&lt;/LI&gt;&lt;LI&gt;Client sends SNI in Client Hello with value of "host.inter.net"&lt;/LI&gt;&lt;LI&gt;Security Gateway performs HTTPS inspection and generates SSL certificate with Common Name of "*.us-east-1.es.amazonaws.com" and sends this to client in Sever Hello&lt;/LI&gt;&lt;LI&gt;Client sends TLS Alert "Bad Certificate" to server and closes connection&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Obviously this is happening because the Security Gateway does not use the SNI sent from the client as the CN in the certificate it generates and presents to the client.&lt;/P&gt;&lt;P&gt;Does anyone else have this or similar issues? How do you work around it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2019 13:51:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-SNI-and-CN-in-generated-certificate/m-p/36630#M7705</guid>
      <dc:creator>Kilian_Huber</dc:creator>
      <dc:date>2019-02-27T13:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection, SNI and CN in generated certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-SNI-and-CN-in-generated-certificate/m-p/36631#M7706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;BR /&gt;we are facing simiar issues at a customers environment with SNI and don't really have a solution, yet.&lt;BR /&gt;This is a reason to attend R80.30 EA because of SNI improvement and I am curious about the testing results.&lt;BR /&gt;cheers&lt;BR /&gt;Vincent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2019 14:16:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-SNI-and-CN-in-generated-certificate/m-p/36631#M7706</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2019-02-27T14:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection, SNI and CN in generated certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-SNI-and-CN-in-generated-certificate/m-p/36632#M7707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;same way on R80.20 Take 33&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2019 17:39:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-SNI-and-CN-in-generated-certificate/m-p/36632#M7707</guid>
      <dc:creator>Alessandro_Marr</dc:creator>
      <dc:date>2019-02-27T17:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection, SNI and CN in generated certificate</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-SNI-and-CN-in-generated-certificate/m-p/36633#M7708</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hiii &lt;A href="https://community.checkpoint.com/migrated-users/50398"&gt;Vincent Bacher&lt;/A&gt;‌ You can use &lt;STRONG&gt;Hotfix&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;on the top of R80.10 jumbo take.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;NOTE: Make sure that, that Hotfix is dependent on the jumbo take.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Also&amp;nbsp;If somehow SNI is not able to verify then its work according to the CN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;I am not tested yet with R80.30 but from R80.30 onwards SNI is included with below improvements.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79446_pastedImage_2.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#Chinmaya Naik&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2019 10:18:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-Inspection-SNI-and-CN-in-generated-certificate/m-p/36633#M7708</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-02-28T10:18:24Z</dc:date>
    </item>
  </channel>
</rss>

