<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Harmony SASE - Issue with Docker Pulls – TLS Certificate Error in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-SASE-Issue-with-Docker-Pulls-TLS-Certificate-Error/m-p/257185#M1202</link>
    <description>&lt;P&gt;Are you sure the Harmony SASE CA was correctly added to the trusted CA list of the system?&lt;/P&gt;
&lt;P&gt;You can also create bypass rules for programs. In linux that would be /usr/bin/dockerd and /usr/bin/docker-proxy. In Windows, that's probably "Docker Desktop.exe", but I have not tested this one.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Sep 2025 16:20:55 GMT</pubDate>
    <dc:creator>Pedro_Espindola</dc:creator>
    <dc:date>2025-09-12T16:20:55Z</dc:date>
    <item>
      <title>Harmony SASE - Issue with Docker Pulls – TLS Certificate Error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-SASE-Issue-with-Docker-Pulls-TLS-Certificate-Error/m-p/257079#M1187</link>
      <description>&lt;P&gt;Hello Team ,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;when trying to fetch from docker we are receiveing the following error :&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;"failed to solve: php:8.1-apache-bullseye: failed to resolve source metadata for&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="http://docker.io/library/php:8.1-apache-bullseye" target="_blank" rel="noopener noreferrer"&gt;docker.io/library/php:8.1-apache-bullseye&lt;/A&gt;&lt;SPAN&gt;: failed to do request: Head "r&lt;/SPAN&gt;&lt;A class="" href="https://registry-1.docker.io/v2/library/php/manifests/8.1-apache-bullseye" target="_blank" rel="noopener noreferrer"&gt;egistry-1.docker.io/v2/library/php/manifests/8.1-apache-bullseye&lt;/A&gt;&lt;STRONG&gt;": tls: failed to verify certificate: x509: certificate signed by unknown authority"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed that nothing appears in the logs. To make it work, I had to create a bypass rule for the following Docker-related domains:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;registry-1.docker.io&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;auth.docker.io&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;production.cloudflare.docker.com&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Could you please advise:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Are there best practices we can apply to avoid this issue in the future (e.g., handling TLS inspection with Docker Hub traffic)?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Why doesn’t this behavior appear in the logs, and is there a way to improve visibility for similar cases?&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks in advance for your guidance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 05:13:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-SASE-Issue-with-Docker-Pulls-TLS-Certificate-Error/m-p/257079#M1187</guid>
      <dc:creator>Geomix7</dc:creator>
      <dc:date>2025-09-11T05:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony SASE - Issue with Docker Pulls – TLS Certificate Error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-SASE-Issue-with-Docker-Pulls-TLS-Certificate-Error/m-p/257081#M1188</link>
      <description>&lt;P&gt;I would suggest to open SR# with CP TAC !&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 07:02:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-SASE-Issue-with-Docker-Pulls-TLS-Certificate-Error/m-p/257081#M1188</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-09-11T07:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony SASE - Issue with Docker Pulls – TLS Certificate Error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-SASE-Issue-with-Docker-Pulls-TLS-Certificate-Error/m-p/257108#M1192</link>
      <description>&lt;P&gt;Not sure if Docker has a mechanism to update the Trusted CAs (needed for HTTPS Inspection to work) or if they implement Certificate Pinning (in which case, HTTPS Inspection won't work and you will need to bypass as you've done).&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 14:53:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-SASE-Issue-with-Docker-Pulls-TLS-Certificate-Error/m-p/257108#M1192</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-11T14:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony SASE - Issue with Docker Pulls – TLS Certificate Error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-SASE-Issue-with-Docker-Pulls-TLS-Certificate-Error/m-p/257185#M1202</link>
      <description>&lt;P&gt;Are you sure the Harmony SASE CA was correctly added to the trusted CA list of the system?&lt;/P&gt;
&lt;P&gt;You can also create bypass rules for programs. In linux that would be /usr/bin/dockerd and /usr/bin/docker-proxy. In Windows, that's probably "Docker Desktop.exe", but I have not tested this one.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2025 16:20:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-SASE-Issue-with-Docker-Pulls-TLS-Certificate-Error/m-p/257185#M1202</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2025-09-12T16:20:55Z</dc:date>
    </item>
  </channel>
</rss>

