<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Main Mode Client Machine Certificate Error: Could not retrieve CRL.CN=XXX in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241691#M2393</link>
    <description>&lt;P&gt;Certificates are used as part of the client VPN connection, which are checked against the CRL.&lt;BR /&gt;Very much relevant here.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Feb 2025 15:58:19 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-02-19T15:58:19Z</dc:date>
    <item>
      <title>Main Mode Client Machine Certificate Error: Could not retrieve CRL.CN=XXX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241491#M2389</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we currently have one client that cannot connect via VPN. It's the only client to have that issue at the moment.&lt;/P&gt;&lt;P&gt;SmartConsole says:&lt;BR /&gt;Main Mode Client Machine Certificate Error: Could not retrieve CRL.CN=XXX&lt;/P&gt;&lt;P&gt;I see allowed packets in the logs. If I curl_cli the CRL-Distribution-Point and tcpdump the traffic during client-login I see encrypted&lt;/P&gt;&lt;P&gt;-----BEGIN X509 CRL-----&lt;BR /&gt;abc123&lt;BR /&gt;-----END X509 CRL-----&lt;/P&gt;&lt;P&gt;which are in both cases the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All other clients can succesful login.&lt;/P&gt;&lt;P&gt;Do you have any clues?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 10:15:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241491#M2389</guid>
      <dc:creator>morris</dc:creator>
      <dc:date>2025-02-18T10:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Main Mode Client Machine Certificate Error: Could not retrieve CRL.CN=XXX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241579#M2390</link>
      <description>&lt;P&gt;Have you tried connecting to the CRL directly from the client in question (e.g. in a web browser)?&lt;BR /&gt;Have you tried having the client use a different ISP to see if port 18264 is possibly being blocked?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 21:11:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241579#M2390</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-18T21:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: Main Mode Client Machine Certificate Error: Could not retrieve CRL.CN=XXX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241591#M2391</link>
      <description>&lt;P&gt;If its just single client, maybe have them reboot or reinstall the client. I would test with latest one, E88.62 version. Its highly unlikely its anything on the gateway side.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 22:00:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241591#M2391</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-18T22:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: Main Mode Client Machine Certificate Error: Could not retrieve CRL.CN=XXX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241620#M2392</link>
      <description>&lt;P&gt;The client cannot access to the CRL as he is not connected yet.&lt;/P&gt;&lt;P&gt;Does the client perform the CRL check? I always thought it was done by the gateway. Doesn't make sense to me if the client does it. The same with port 18264. I see allowed packets between gateway and management.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 09:13:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241620#M2392</guid>
      <dc:creator>morris</dc:creator>
      <dc:date>2025-02-19T09:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Main Mode Client Machine Certificate Error: Could not retrieve CRL.CN=XXX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241691#M2393</link>
      <description>&lt;P&gt;Certificates are used as part of the client VPN connection, which are checked against the CRL.&lt;BR /&gt;Very much relevant here.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 15:58:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241691#M2393</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-19T15:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Main Mode Client Machine Certificate Error: Could not retrieve CRL.CN=XXX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241747#M2394</link>
      <description>&lt;P&gt;Yes, I understand. But who checks the certificate against the crl? The client or the gateway/management?&amp;nbsp;&lt;/P&gt;&lt;P&gt;All other clients can connect without any error message.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 08:26:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241747#M2394</guid>
      <dc:creator>morris</dc:creator>
      <dc:date>2025-02-20T08:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: Main Mode Client Machine Certificate Error: Could not retrieve CRL.CN=XXX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241774#M2395</link>
      <description>&lt;P&gt;Depending on your configuration (e.g. Management is behind NAT), the client may send the CRL check through the gateway, but it's ultimately coming from the client.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 13:08:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/241774#M2395</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-20T13:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: Main Mode Client Machine Certificate Error: Could not retrieve CRL.CN=XXX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/243269#M2396</link>
      <description>&lt;P&gt;The VPN-Gateway seems to use another interface to get to the CRL. And that access is dropped on another gateway.&lt;/P&gt;&lt;P&gt;It seems a little odd to me. The client accesses the same external interface with new and legacy certificate.&lt;/P&gt;&lt;P&gt;We are waiting for the other team to unlock the dropped traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 15:26:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/243269#M2396</guid>
      <dc:creator>morris</dc:creator>
      <dc:date>2025-03-07T15:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: Main Mode Client Machine Certificate Error: Could not retrieve CRL.CN=XXX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/243272#M2397</link>
      <description>&lt;P&gt;Did you end up testing with the latest client, E88.62?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 15:59:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Main-Mode-Client-Machine-Certificate-Error-Could-not-retrieve/m-p/243272#M2397</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-07T15:59:16Z</dc:date>
    </item>
  </channel>
</rss>

