sk182318 - "Categorized HTTPS Sites" stopped to classify specific websites

"Categorized HTTPS Sites" stopped to classify specific websites

Please read this important update from Check Point.

Security Alert:

High

Product: URL Filtering
Version: R81 (EOS), R81.10 (EOS), R81.20
Last Modified: 2024-06-05

Symptoms

Cause

Post-quantum cryptography methods are now supported and enabled by default in the latest version of Chrome ("TLS1.3 hybridized Kyber support" flag) and Edge browsers to prevent “Harvest Now, Decrypt Later” attacks.

In some cases, "Categorized HTTPS Sites" fails to categorize specific website with these post-quantum cryptography methods.

URL Filtering with HTTPS Inspection works as expected.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

If you wish not to install the Hotfix:

  1. Disable "TLS 1.3 hybridized Kyber support" in the browser.
  2. Inspect the traffic by HTTPS Inspection. See sk108202 - Best Practices - HTTPS Inspection for more information.

Article Properties

Access Level: General
Severity: High
Status: Approved
Date Created: 2024-05-21
Last Modified: 2024-06-05