sk182318 - "Categorized HTTPS Sites" stopped to classify specific websites
"Categorized HTTPS Sites" stopped to classify specific websites
Please read this important update from Check Point.
Security Alert:
High
Product: URL Filtering
Version: R81 (EOS), R81.10 (EOS), R81.20
Last Modified: 2024-06-05
Symptoms
- The "Categorized HTTPS Sites" option does not classify specific websites when "TLS 1.3 hybridized Kyber support" is enabled in the browser.
Cause
Post-quantum cryptography methods are now supported and enabled by default in the latest version of Chrome ("TLS1.3 hybridized Kyber support" flag) and Edge browsers to prevent “Harvest Now, Decrypt Later” attacks.
In some cases, "Categorized HTTPS Sites" fails to categorize specific website with these post-quantum cryptography methods.
URL Filtering with HTTPS Inspection works as expected.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 65
- Jumbo Hotfix Accumulator for R81.10 starting from Take 150
- Jumbo Hotfix Accumulator for R81 starting from Take 99
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
If you wish not to install the Hotfix:
- Disable "TLS 1.3 hybridized Kyber support" in the browser.
- Inspect the traffic by HTTPS Inspection. See sk108202 - Best Practices - HTTPS Inspection for more information.
Article Properties
Access Level: General
Severity: High
Status: Approved
Date Created: 2024-05-21
Last Modified: 2024-06-05