Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Venue2185
Explorer

Certificate cannot be validated. Reason: Could not retrieve CRL." with External CA

Hello,

I have a question regarding certificate-based Site-to-Site IPsec VPN on Check Point R81.20.

I'm using certificates issued by an external CA for VPN authentication. The VPN appears to work, but I keep seeing the following validation log:

"Certificate cannot be validated. Reason: Could not retrieve CRL."

  • Does the Check Point Security Gateway require network connectivity to the external CA (or the CRL Distribution Point) to validate the certificate?
  • If the gateway cannot reach the CRL server, is this log expected?

Any advice or best practices would be appreciated.

Thank you!

0 Kudos
2 Replies
israelfds95
MVP Diamond
MVP Diamond

Hi,

Yes, the Security Gateway must be able to reach the CRL or OCSP endpoints specified in the certificate to perform proper certificate validation.

I also recommend checking out the CheckMates post below. It may be helpful:

https://community.checkpoint.com/t5/Mobile/FYI-OCSP-is-default-when-using-3rd-Party-CAs-Automatic-fa...

If the Security Gateway cannot reach the OCSP or CRL server, certificate validation will fail, resulting in validation errors in the logs, and VPN authentication may also fail.




Venue2185
Explorer

Thanks for reply. can it disable CRL or OCSP checking @israelfds95 The firewalls and the CA server do not have network reachability to each other. For using site2site vpn authentication.

edit
i found it for disable CRL sk21156 but but the VPN still fails with an "Invalid Certificate" error.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events