cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question
Vladimir
Jade

VPN through Gateway Browsing HTTPS residual certificate issue

With HTTPS inspection configured and Outbound Certificate distributed, following behavior being observed:

From internal hosts, browsers reaching destination, substituted certificate is shown as valid and there are no indications of the intercept:

    

When remote client (Endpoint VPN) establishes the connection to the same site, certificate is substituted, declared "valid", but the browser indicates the site being "Not Secure":

 

Certificate is installed on the remote client in Trusted Root Certification Authorities:

The culprit was the older certificate issued by the same gateway and installed on clients. After removal of the old certificate, clients' browsers behavior reverted to normal.

2 Replies

Re: VPN through Gateway Browsing HTTPS residual certificate issue

Hi Vladimir,

Good Document.

We import either new certificate or renew the certificate if it is expired but if certificate is still valid and you import new one then you should remove the older one otherwise it points to older one.

0 Kudos
Vladimir
Jade

Re: VPN through Gateway Browsing HTTPS residual certificate issue

Too bad there is no CRL mechanism interface in Check Point that makes it manageable.

0 Kudos