sk180683 - Check Point Gateway is not sending the 3rd party certificate that uses OCSP it was set to send for site-2-site VPN or Remote Access VPN but instead send the defaultCert
Check Point Gateway is not sending the 3rd party certificate that uses OCSP it was set to send for site-2-site VPN or Remote Access VPN but instead send the defaultCert
Product: Endpoint Security - Remote Access VPN, IPSec VPN
Version: R80.40 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Platform: All
Last Modified: 2023-07-30
Symptoms
- Check Point Gateway is not sending the 3rd party certificate it was set to send for site-2-site VPN or Remote Access VPN but instead send the defaultCert
- vpnd.elg / iked.elg show the following lines up to 20 minutes from policy installation:
[vpnd 3037 4071122944]@FW02[3 Feb 12:17:32] fwKeyStore::RemoveCertKey: Removed VPN--CRT from Global Key Holder
[vpnd 3037 4071122944]@FW02[3 Feb 12:17:32] fwKeyStore::RemoveCertKey: Removed VPN--CRT from IKE Key Holder
[vpnd 3037 4071122944]@FW02[3 Feb 12:17:32] fwKeyStore::RemoveCertKey: Removed VPN--CRT from SSL Key Holder
```
- vpnd.elg or iked.elg will show one of these 3 lines:
[OCSP] fwFetchOCSP_cb: all CRL and OCSP responses are received, calling CB with rc: -949
[OCSP] fwFetchOCSP_cb: all CRL and OCSP responses are received, calling CB with rc: -957
[OCSP] fwFetchOCSP_cb: all CRL and OCSP responses are received, calling CB with rc: -958
```
Cause
The issue happens because after policy install Check Point is starting to check and validate its own 3rd party certs.
If there is a 3rd party cert the gateway is trying to validate but it fails for one of these 3 reasons:
- OCSP unauthorized will be seen in vpnd.elg / iked.elg as
[OCSP] fwFetchOCSP_cb: all CRL and OCSP responses are received, calling CB with rc: -949.
```
- OCSP connect failed will be seen in vpnd.elg / iked.elg as
[OCSP] fwFetchOCSP_cb: all CRL and OCSP responses are received, calling CB with rc: -957
```
- OCSP timeout will be seen in vpnd.elg / iked.elg as
[OCSP] fwFetchOCSP_cb: all CRL and OCSP responses are received, calling CB with rc: -958
```
Before the fix, the Check Point gateway would have removed that certificate from its database and will not try to use it again, which may lead to failures (as the unwanted certificate, usually the defaultCert will be sent instead while the peer expects the 3rd party certificate).
You will see the lines:
[vpnd 3037 4071122944]@FW02[3 Feb 12:17:32] fwKeyStore::RemoveCertKey: Removed VPN-<GW_NAME>-CRT from Global Key Holder
[vpnd 3037 4071122944]@FW02[3 Feb 12:17:32] fwKeyStore::RemoveCertKey: Removed VPN-<GW_NAME>-CRT from IKE Key Holder
[vpnd 3037 4071122944]@FW02[3 Feb 12:17:32] fwKeyStore::RemoveCertKey: Removed VPN-<GW_NAME>-CRT from SSL Key Holder
```
After the fix, the gateway will not remove those certificates but will attempt to validate them every 15 minutes.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.10 starting from Take 110
- Jumbo Hotfix Accumulator for R81 starting from Take 87
- Jumbo Hotfix Accumulator for R80.40 starting from Take 198
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.