<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SNX failing Driver validation in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229976#M2991</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23907"&gt;@NorthernNetGuy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please check SNX version that is installed on Windows?&lt;/P&gt;
&lt;P&gt;It can be found in&amp;nbsp;"c:\Program Files (x86)\CheckPoint\SSL Network Extender\ver.ini" file.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2024 08:46:48 GMT</pubDate>
    <dc:creator>MaksimBahunou</dc:creator>
    <dc:date>2024-10-17T08:46:48Z</dc:date>
    <item>
      <title>SNX failing Driver validation</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229791#M2986</link>
      <description>&lt;P&gt;I've found on my windows 10 22H2 clients that SNX is failing the windows driver validation checks (Secure boot + Driver Signature Enforcement).&lt;/P&gt;&lt;P&gt;checking the setupapi.dev.log file shows the following errors:&lt;/P&gt;&lt;P&gt;Error 0x800b0109: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.&lt;/P&gt;&lt;P&gt;Driver package failed signature verification. Error = 0xE0000247&lt;/P&gt;&lt;P&gt;Failed to import driver package into Driver Store. Error = 0xE0000247&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i Check out the SNX security catalog file, it shows that it is not valid, being signed by an old microsoft CA that expired in 2021.&lt;/P&gt;&lt;P&gt;I've attached screenshot of the certs and catalog.&lt;/P&gt;&lt;P&gt;TAC + R&amp;amp;D has indicated that the driver being signed by an expired CA is fine, and that this is likely an issue with a custom CRL on my clients, but I've never applied a custom CRL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm wondering if anyone else has seen this isue on win10 22H2 and later versions of windows. The proposed workaround of disabling secure boot + validation checks will be rejected by the business.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 18:02:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229791#M2986</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2024-10-15T18:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: SNX failing Driver validation</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229804#M2987</link>
      <description>&lt;P&gt;What version of snx is installed?&lt;BR /&gt;What gateway version/JHF is relevant here?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 19:23:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229804#M2987</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-15T19:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: SNX failing Driver validation</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229807#M2988</link>
      <description>&lt;P&gt;R81.20, JHF 84&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SNX version 7.01.0000&lt;/P&gt;&lt;P&gt;Mobile Access Portal Agent 800.007.049&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 19:34:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229807#M2988</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2024-10-15T19:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: SNX failing Driver validation</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229820#M2989</link>
      <description>&lt;P&gt;The SNX version should be a build like&amp;nbsp;800008302, which you can get with snx -h on the CLI.&lt;BR /&gt;The latest appears to be&amp;nbsp;80008409, which should be applied with the latest R81.20 JHF.&lt;/P&gt;
&lt;P&gt;Assuming you're on the most recent release, you're saying it is signed with an old certificate?&lt;BR /&gt;Can you send me the relevant SR in a PM?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 20:42:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229820#M2989</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-15T20:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: SNX failing Driver validation</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229897#M2990</link>
      <description>&lt;P&gt;the SNX I put above was the 'SLL Network Extender Service' version that gets installed alongside the Mobile Access Portal Agent (actual snx).&lt;/P&gt;&lt;P&gt;SNX build using 'snx -h' is showing 997000069.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/SNX-Versions-and-Requirements.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/SNX-Versions-and-Requirements.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this article confirms the latest version for my release is&amp;nbsp;80008409, and when I do "&lt;SPAN&gt;cat $CVPNDIR/htdocs/SNX/CSHELL/snx_ver.txt"&lt;/SPAN&gt;&amp;nbsp;it shows 800008409.&lt;/P&gt;&lt;P&gt;You can also see the old cert signature in the pictures I attached in my original post.&lt;/P&gt;&lt;P&gt;if the windows agent version # is supposed to match, then maybe when&amp;nbsp;my clients are dowloading SNX they are getting an older version.&lt;/P&gt;&lt;P&gt;DM'ing you the SR as well&lt;/P&gt;&lt;P&gt;*edit*&lt;BR /&gt;according to&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk168353" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk168353&lt;/A&gt;&amp;nbsp;the windows agent version is the latest.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 12:30:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229897#M2990</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2024-10-16T12:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: SNX failing Driver validation</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229976#M2991</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23907"&gt;@NorthernNetGuy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please check SNX version that is installed on Windows?&lt;/P&gt;
&lt;P&gt;It can be found in&amp;nbsp;"c:\Program Files (x86)\CheckPoint\SSL Network Extender\ver.ini" file.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 08:46:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229976#M2991</guid>
      <dc:creator>MaksimBahunou</dc:creator>
      <dc:date>2024-10-17T08:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: SNX failing Driver validation</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229997#M2992</link>
      <description>&lt;P&gt;800008409&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone confirm what certificate and root CA are signing the SSL extender for them? the security catalog and signer can be found at: C:\Program Files (x86)\CheckPoint\SSL Network Extender\netvna.cat&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Click 'View Signature", then click 'View Certificate"&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 12:31:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/229997#M2992</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2024-10-17T12:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: SNX failing Driver validation</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/230003#M2993</link>
      <description>&lt;P&gt;Here are from my PC:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-10-17 15_58_00-.png" style="width: 411px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28104i669CC5BF813DD8A3/image-dimensions/411x537?v=v2" width="411" height="537" role="button" title="2024-10-17 15_58_00-.png" alt="2024-10-17 15_58_00-.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-10-17 15_58_32-.png" style="width: 399px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28103i8C74F7A20B83E21D/image-dimensions/399x522?v=v2" width="399" height="522" role="button" title="2024-10-17 15_58_32-.png" alt="2024-10-17 15_58_32-.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 13:01:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/230003#M2993</guid>
      <dc:creator>MaksimBahunou</dc:creator>
      <dc:date>2024-10-17T13:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: SNX failing Driver validation</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/230006#M2994</link>
      <description>&lt;P&gt;Do you have Secure Boot with&amp;nbsp; driver signature enforcement enabled? Windows should reject SNX if you do based on that.&lt;BR /&gt;&lt;BR /&gt;You can check if Secure boot is enabled in MSINFO under "Secure Boot State"&lt;BR /&gt;if off, then driver signature enforcement will also be off.&lt;/P&gt;&lt;P&gt;If Secure Boot State is On, then in an elevated command prompt, run 'bcdedit' and look for "nointegritychecks", if it shows "yes", then driver signature enforcement is off&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 13:14:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/230006#M2994</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2024-10-17T13:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: SNX failing Driver validation</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/230017#M2996</link>
      <description>&lt;P&gt;Secure Boot is definitely "on".&lt;/P&gt;
&lt;P&gt;As for the "nointegritychecks". By default, I don't see its value. When I tried to alter it, I got "The value is protected by Secure Boot policy and cannot be modified or deleted." So, I disabled Secure Boot, explicitly set "nointegritychecks" to "off" and enabled Secure Boot back.&lt;/P&gt;
&lt;P&gt;No issues with certificate.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28111iAA5F7A0D59433CCF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 13:54:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/230017#M2996</guid>
      <dc:creator>MaksimBahunou</dc:creator>
      <dc:date>2024-10-17T13:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: SNX failing Driver validation</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/230018#M2997</link>
      <description>&lt;P&gt;The value won't show if off for nointetegritychecks, it is off by default for security. can you also confirm if you are on windows 10 22h2?&lt;/P&gt;&lt;P&gt;It should be normal for windows to reject a driver signature that comes from an expired CA I think, I don't know why my different windows test clients would be a rare exception in rejecting this instead of allowing it.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 13:57:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/230018#M2997</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2024-10-17T13:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: SNX failing Driver validation</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/230097#M2998</link>
      <description>&lt;P&gt;I check on Win10 22H2 19045.4849&lt;/P&gt;
&lt;P&gt;I noticed one interesting thing. The root certificate (Microsoft Root Certificate Authority) has validity period from &lt;STRONG&gt;10&lt;/STRONG&gt; May 2001 till &lt;STRONG&gt;10&lt;/STRONG&gt; May 2021.&lt;/P&gt;
&lt;P&gt;While on your screenshot it is &lt;STRONG&gt;9&lt;/STRONG&gt; May 2001 - &lt;STRONG&gt;9&lt;/STRONG&gt; May 2021.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my case certificate serial number is&amp;nbsp;79ad16a14aa0a5ad4c7358f407132e65. Please check with your one.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 05:56:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-failing-Driver-validation/m-p/230097#M2998</guid>
      <dc:creator>MaksimBahunou</dc:creator>
      <dc:date>2024-10-18T05:56:41Z</dc:date>
    </item>
  </channel>
</rss>

