- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
So we are trying to connect to a proofpoint link for employee training-
https://004e0b01.pphosted.com:10000/
and we can connect to it from home when not connected to company vpn, but when we are inside the network it doesnt work, i have tried the following straight from the internet firewall (running GAiA R80.20) and this is what i got-
It looks like you cannot fetch CRL.
Also, are you using inbonud HTTPS Inspection?
as you can see https inspection is turned off, only categorized https inspection is enabled which i dont think should be causing any cert issues unless im wrong-
With R80.20, starting from certain HFA, HTTPS categorisation verifies the actual web certificate, CRL and its chain. Please make sure the following:
If at least one condition does not match, that's your case:
ERR_lib_error_string: SSL routines
ERR_func_error_string: ssl3_get_server_certificate
ERR_reason_error_string: certificate verify failed
ERR_error_string: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
* SSL certificate problem: unable to get local issuer certificate
* Closing connection 0
curl: (60) SSL certificate problem: unable to get local issuer certificate
How can I make sure that the crl can be retrieved?
Did you already rule out two first cases? Can you access this website from a non-firewalled client? How does the certificate look?
CRL distribution point is mentioned in the certificate itself. Take this URL and try accessing it from the GW, with curl_cli
So apparently it works with the untrusted option as you can see below, what does that mean?
[Expert@VXX-FXX:0]# curl_cli -k https://004e0b01.pphosted.com:10000/
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="https://004e0b01.pphosted.com:10000/admin">here</a>.</p>
</body></html>
Looks like curl isn’t trusting the certificate presented.
Have you tried using the —insecure option as noted in the output?
Yes I will try that out and post here
So apparently it works with the untrusted option as you can see below, what does that mean?
curl_cli -k https://004e0b01.pphosted.com:10000/
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="https://004e0b01.pphosted.com:10000/admin">here</a>.</p>
</body></html>
I think the best is to open a support call. I can see, the certificate is valid, but CRL is not hosted on digicert but on a different site: http://cacerts.thawte.com/ThawteRSACA2018.crt
This might be the source of your issue, or, it might be something else. BTW, check you can fetch http://cacerts.thawte.com/ThawteRSACA2018.crt from your GW.
i tried this-
curl_cli -v http://cacerts.thawte.com/ThawteRSACA2018.crt
and got a binary output and im assuming its able to fetch the cert?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
13 | |
12 | |
11 | |
10 | |
9 | |
8 | |
7 | |
6 | |
5 | |
5 |
Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY