<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL inspection policy - Validate CRL - known issue? in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-inspection-policy-Validate-CRL-known-issue/m-p/70896#M2747</link>
    <description>&lt;P&gt;Not a good advice, I am afraid. You have HTTPS Inspection enabled on your appliance (it is not called a router, BTW, but a security appliance), and the box cannot get CRLs for whatever reason.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have several options:&lt;/P&gt;
&lt;P&gt;1. Disable HTTPS Inspection&lt;/P&gt;
&lt;P&gt;2. Troubleshoot CRL retrieval issue (if you do not know how, reach out to Check Point support)&lt;/P&gt;
&lt;P&gt;3. Do what your ISP is telling you. In this case, you risk accepting any of the revoked and invalid certificates, which is a security issue.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Dec 2019 11:40:41 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2019-12-19T11:40:41Z</dc:date>
    <item>
      <title>SSL inspection policy - Validate CRL - known issue?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-inspection-policy-Validate-CRL-known-issue/m-p/70891#M2746</link>
      <description>&lt;P&gt;I have a Check Point 730 router with firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've had the router for over a year, and lately, the users have had issues connecting to sites with SSL certificates, up until the point where we could not connect to those sites at all.&lt;/P&gt;&lt;P&gt;I spoke to our ISP, and they said this is a known bug, and the workaround is to set "SSL inspection policy - Validate CRL" to "false".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this really a known bug? I could not find documentation about it anywhere.&lt;/P&gt;&lt;P&gt;If this is in fact a known bug, I would like to read about the progress of the issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2019 10:07:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-inspection-policy-Validate-CRL-known-issue/m-p/70891#M2746</guid>
      <dc:creator>Tandishe</dc:creator>
      <dc:date>2019-12-19T10:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inspection policy - Validate CRL - known issue?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-inspection-policy-Validate-CRL-known-issue/m-p/70896#M2747</link>
      <description>&lt;P&gt;Not a good advice, I am afraid. You have HTTPS Inspection enabled on your appliance (it is not called a router, BTW, but a security appliance), and the box cannot get CRLs for whatever reason.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have several options:&lt;/P&gt;
&lt;P&gt;1. Disable HTTPS Inspection&lt;/P&gt;
&lt;P&gt;2. Troubleshoot CRL retrieval issue (if you do not know how, reach out to Check Point support)&lt;/P&gt;
&lt;P&gt;3. Do what your ISP is telling you. In this case, you risk accepting any of the revoked and invalid certificates, which is a security issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2019 11:40:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-inspection-policy-Validate-CRL-known-issue/m-p/70896#M2747</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-12-19T11:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inspection policy - Validate CRL - known issue?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-inspection-policy-Validate-CRL-known-issue/m-p/70900#M2748</link>
      <description>&lt;P&gt;So my contract with the ISP is such that they have all the admin access, not me.&amp;nbsp; Technically I'm renting my Checkpoint equipment and get zero support from checkpoint. I get support from my ISP, and they get support from checkpoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I'm really looking for here is some sort of official documentation that shows that this is (or is not) a "known issue with a workaround". My ISP is claiming this is in the hands of Check Point and being looked into, and that the official advised workaround is to set that parameter to false.&lt;/P&gt;&lt;P&gt;However, my impression is that my ISP is shirking responsibility and can in fact properly help by actually looking into the issue instead of throwing on a bandaid that makes me more vulnerable.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2019 11:49:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-inspection-policy-Validate-CRL-known-issue/m-p/70900#M2748</guid>
      <dc:creator>Tandishe</dc:creator>
      <dc:date>2019-12-19T11:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSL inspection policy - Validate CRL - known issue?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-inspection-policy-Validate-CRL-known-issue/m-p/70907#M2749</link>
      <description>&lt;P&gt;Without an actual support ticket details, I cannot provide you an alternative view on your ISP support process. Feel free to reach out to me offline with the actual support information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Concerning "the known bugs", the only infoI can find that would sound like your case is this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk141953" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk141953&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;It is rather old, and there is a fix available through regular support. Mind, it is only relevant for a specific firmware version.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2019 12:54:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SSL-inspection-policy-Validate-CRL-known-issue/m-p/70907#M2749</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-12-19T12:54:52Z</dc:date>
    </item>
  </channel>
</rss>

