Commencing November 20th in various regions, Microsoft deployed a new SSL certificate that is causing Check Point CloudGuard Controller to not able to authenticate to the Azure environment.
This will impact all customers who are using Cloud Objects that are learned from Microsoft Azure.
Symptoms:
- Microsoft DataCenter object is unable to communicate to Azure in Smart Console.
- Cloud_proxy.elg logs show o rest.CurlException: b'curl: (60) SSL certificate problem: unable to get local issuer certificate\nMore details here: https://curl.haxx.se/docs/sslcerts.html\n\ncurl failed to verify the legitimacy of the server and therefore could not\nestablish a secure connection to it. To learn more about this situation and\nhow to fix it, please visit the web page mentioned above.\n'
- DataCenter objects are no longer being populated on the gateway or in the rule base
- Connections that used to match a rule that used DataCenter objects now being dropped on the cleanup rule.
- PDP is not showing any DataCenter learned objects.
Solution:
Check Point R&D is currently working closely with Microsoft on a fix. We expect a fix in a way of a hotfix, shortly. Please open a TAC case or in case of Diamond Services, please contact your Diamond engineer, if you would like to be notified of a solution once it is available.
Caution:
Do not reboot the Check Point Management station or gateways if they are experiencing this issue. This will lose all learned Cloud objects from Azure Datacenter and there is no way to recover this until the communication issue has been resolved.
Reference SK:
sk169983: Microsoft Azure: Action required: Review your Azure Services Certificate Authorities