Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Vladimir
Champion
Champion

VPN through Gateway Browsing HTTPS residual certificate issue

With HTTPS inspection configured and Outbound Certificate distributed, following behavior being observed:

From internal hosts, browsers reaching destination, substituted certificate is shown as valid and there are no indications of the intercept:

    

When remote client (Endpoint VPN) establishes the connection to the same site, certificate is substituted, declared "valid", but the browser indicates the site being "Not Secure":

 

Certificate is installed on the remote client in Trusted Root Certification Authorities:

The culprit was the older certificate issued by the same gateway and installed on clients. After removal of the old certificate, clients' browsers behavior reverted to normal.

2 Replies
Gaurav_Pandya
Advisor

Hi Vladimir,

Good Document.

We import either new certificate or renew the certificate if it is expired but if certificate is still valid and you import new one then you should remove the older one otherwise it points to older one.

0 Kudos
Vladimir
Champion
Champion

Too bad there is no CRL mechanism interface in Check Point that makes it manageable.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events