Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ale_G
Participant

HTTPS Ispection - Certificate Validation Failure

Hello all,

for the past few days (especially on government websites) we have been experiencing problems with web browsing. The error shown in the logs is the following:"

Certificate chain is inconsistent. Refer to sk159872 for more details.
Certificate DN: 'CN=*.fondimpresa.it,O=FONDIMPRESA,ST=Roma,C=IT' Requested Server Name: pf.fondimpresa.it.

2026-03-05_123008.png

 

 

 

Unhandled critical extension. Refer to sk159872 for more details.
Certificate DN: 'CN=domiciliodigitale.gov.it,O=Agenzia per l'Italia Digitale,L=Roma,ST=Roma,C=IT' Requested Server Name: domiciliodigitale.gov.it.

2026-03-05_120718.png

 

 

 

 

 

 

HTTPS isp option:

2026-03-05_123549.png

 

 

 

 

 

 

 

 

Public root certificates are present.

Can someone help me understand the reason and help me resolve the issue?

Many thanks,

Alessandro

0 Kudos
11 Replies
the_rock
MVP Diamond
MVP Diamond

Hey Alessandro,

Did you try bypassing any of those sites as a test?

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Ale_G
Participant

Yes, I tried to bypass HTTPS inspection and everything works.

0 Kudos
CaseyB
Advisor

Have you installed the CRL fix released this week? sk184766 

emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Yes do this first, it's what resolved the issue for me.

Ale_G
Participant

Only now I’ve noticed that a popup appeared in SmartConsole mentioning a CRL validation issue.

I’ll try updating the system and will give you feedback.

Thank you

0 Kudos
Ale_G
Participant

I tried installing the fix, but it seems the problem hasn’t been resolved.

2026-03-09_131419.png

2026-03-09_131706.png

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Did you install it on both management and gateways?

0 Kudos
Ale_G
Participant

No, I've installed the fix only on the management server. Our gateways are running version R81.20, and there is no fix available for these appliances in the KB.

2026-03-10_095305.png

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Hmm, ok, in my case it's R82 gateways and R82.10 SMS. 

Try running 'cpca_client recreate_crls' on the management server. When I did this I didn't have any interruption to anything so it seems to be safe.

0 Kudos
Lesley
MVP Gold
MVP Gold

This website uses incomplete cert chain, see SSL labs results:

https://www.ssllabs.com/ssltest/analyze.html?d=pf.fondimpresa.it&hideResults=on

You need to add the missing inter certs in your server config. So add full chain all but not the root cert! Then you get anchor issues in ssllabs.

If you do not manage this website try to add the missing certs into the cp same as you update the CA list. 

https://support.checkpoint.com/results/sk/sk64521

-------
Please press "Accept as Solution" if my post solved it 🙂
Ale_G
Participant

Before doing that, I will install the CRL fix released this week, as suggested by @the_rock.

If this fix does not resolve the issue I will try to follow the steps you suggested.

Thank you!

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events