Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Vladimir
Champion
Champion

VPN through Gateway Browsing HTTPS residual certificate issue

With HTTPS inspection configured and Outbound Certificate distributed, following behavior being observed:

From internal hosts, browsers reaching destination, substituted certificate is shown as valid and there are no indications of the intercept:

    

When remote client (Endpoint VPN) establishes the connection to the same site, certificate is substituted, declared "valid", but the browser indicates the site being "Not Secure":

 

Certificate is installed on the remote client in Trusted Root Certification Authorities:

The culprit was the older certificate issued by the same gateway and installed on clients. After removal of the old certificate, clients' browsers behavior reverted to normal.

2 Replies
Gaurav_Pandya
Advisor

Hi Vladimir,

Good Document.

We import either new certificate or renew the certificate if it is expired but if certificate is still valid and you import new one then you should remove the older one otherwise it points to older one.

0 Kudos
Vladimir
Champion
Champion

Too bad there is no CRL mechanism interface in Check Point that makes it manageable.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events