Hi,
about 10 months ago I've set up Identity Awareness in our production environment, which worked like a charm since about a week or two ago. Now I'm faced with an SSL handshake error that doesn't make any sense to me. The symptoms are absolutely identical to what I found in sk167159 (including the DEBUG logs). Sadly there is no solution at the end of the article, that is anywhere useful.
Also important: I don't use #Quantum Security Management but the common virtual management based on Gaia.
Did someone of you encounter this ever before, or does know what to do?
What I've already tried:
- rebooting my whole environment one by one
- cpca_client set_sign_hash sha256 into cpstop;cpstart
- googling like crazy
What also makes this weird:
- AD-based user authentication for Remote Access also does not work
- I can still use the old SmartDashboard (fwpolicy.exe) to search the AD (works like expected), but not the new SmartConsole
- The AD Query (usernames in log entries) works like it should
Any help is appreciated.
Best regards,
Daniel
Logs ($FWDIR/log/cpm.elg😞
26/04/21 14:31:16,203 DEBUG internal.wrappers.LdapConnectionWrapper [qtp1192021461-72]: Constructing LDAPConnection.
26/04/21 14:31:16,203 DEBUG internal.wrappers.SslLdapConnectionWrapper [qtp1192021461-72]: Connection timeout(in seconds): '30'.
26/04/21 14:31:16,203 DEBUG internal.wrappers.SslLdapConnectionWrapper [qtp1192021461-72]: Trying to create the SSL Socket factory(have different behaviour depending on the JRE vendor).
26/04/21 14:31:16,203 DEBUG internal.wrappers.SslLdapConnectionWrapper [qtp1192021461-72]: Checking if environment variable 'PROPERTY_DEFAULT_SSL_PROTOCOL' defined and not empty.
26/04/21 14:31:16,203 DEBUG internal.wrappers.SslLdapConnectionWrapper [qtp1192021461-72]: Environment variable 'PROPERTY_DEFAULT_SSL_PROTOCOL' is not defined.
26/04/21 14:31:16,203 DEBUG internal.wrappers.SslLdapConnectionWrapper [qtp1192021461-72]: Creating first SSL socket factory with protocol: 'SSL_TLSv2'.
26/04/21 14:31:16,227 DEBUG internal.wrappers.LdapConnectionWrapper [qtp1192021461-72]: Got result code different from 'ResultCode.SERVER_DOWN(81)', not reconnecting.
26/04/21 14:31:16,228 DEBUG internal.wrappers.SslLdapConnectionWrapper [qtp1192021461-72]: Connect error(CONNECT_ERROR), checking if SSL connectivity(I/O) or certificate problem.
26/04/21 14:31:16,228 DEBUG internal.wrappers.SslLdapConnectionWrapper [qtp1192021461-72]: Checking if the error is SSLException error.
26/04/21 14:31:16,228 DEBUG internal.wrappers.SslLdapConnectionWrapper [qtp1192021461-72]: Error is SSL error, checking if it's SSL handshake error.
26/04/21 14:31:16,228 DEBUG internal.wrappers.SslLdapConnectionWrapper [qtp1192021461-72]: Error is SSL handshake error, checking if it's SSL certificate error.
26/04/21 14:31:16,228 DEBUG internal.wrappers.SslLdapConnectionWrapper [qtp1192021461-72]: Error is SSL certificate error, checking if it's framework certificate error or ckp error.
26/04/21 14:31:16,228 DEBUG internal.wrappers.SslLdapConnectionWrapper [qtp1192021461-72]: Error is ckp certificate error, forward it to the client.
26/04/21 14:31:19,284 DEBUG internal.wrappers.LdapConnectionWrapper [qtp1192021461-204]: Connection not exist, trying to connect.
26/04/21 14:31:19,284 DEBUG internal.wrappers.LdapConnectionWrapper [qtp1192021461-204]: Trying to connect to the directory according to: com.checkpoint.objects.ldap.connection.internal.properties.QueryAdConnectionDetails {Domain Name='*******', Connection Key='*******', Connection Info list='[]', Directory ID='*******', Username='svccheckpointldap', User DN='CN=*******,OU=Service Accounts,DC=*******', Password='*******', Bind DN='DC=*******', Server name / FQDN='*******', Server IPv4='172.*******', Server IPv6='', Server Uid='*******', Port='636', Use ssl='true', Ui fetch profile ID='*******', Object domain ID='*******', Branches list='[DC=*******]'}.