sk183884 - VPN/Remote Access Security Gateways Using DigiCert/GeoTrust CA
VPN/Remote Access Security Gateways Using DigiCert/GeoTrust CA
Product
- HTTPS Inspection, Remote Access VPN, Site-to-Site VPN
Version
- R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, R82.10
OS
- Gaia, Gaia Embedded
Last Modified
- 2025-11-19
Solution
DigiCert has announced that starting 22 September 2025, they will only support Hypertext Transfer Protocol (HTTP)/1.0 with a proper "Host" header, HTTP/1.1, and HTTP/1.2 connections for Online Certificate Status Protocol (OCSP) and certificate revocation lists (CRL) checks.
There is no need to update your Check Point Security Gateways for Site-to-Site VPN, Remote Access VPN, and Outbound HTTPS Inspection for sites working with a DigiCert-generated certificate. These services will continue to operate smoothly beyond the 22 September 2025 timeline, even without applying the hotfix in advance.
That said, our latest Jumbo Hotfix Accumulator changes the communication method from HTTP/1.0 to HTTP/1.1, ensuring long-term compatibility with all certificate authority services looking ahead.
Recommended step - Install Jumbo Hotfix Accumulator
The fix is included in these Jumbo Hotfix Accumulators:
Note that Check Point Recommended version for all deployments is R82 with its Recommended Jumbo Hotfix Accumulator Take.
| Version | Take # |
| R82 Jumbo Hotfix Accumulator | Latest Take 41 |
| R81.20 Jumbo Hotfix Accumulator | Latest Take 115 |
| R81.10 Jumbo Hotfix Accumulator | Recommended Take 181 |
| Jumbo Hotfix Accumulator for Quantum Force 3900 Appliances | Latest Take 22 |
For earlier Jumbo Hotfix Accumulator Takes and earlier versions, install the hotfix from the table below.
Hotfix that updates Security Gateway / Quantum Spark Gateway to use HTTP 1.1 by default for CRL validation
The Hotfix is available for manual download from this table:
- For Quantum Security Gateways / Cluster Members / Scalable Platform Security Groups:
| Hotfix on Top of | Download Link |
| R82.10 | (TAR) |
| R82 Jumbo Hotfix Accumulator Take 39 | (TAR) |
| R82 Jumbo Hotfix Accumulator Take 36 | (TAR) |
| R82 Jumbo Hotfix Accumulator Take 34 | (TAR) |
| R81.20 Jumbo Hotfix Accumulator Take 113 or Take 111 | (TAR) |
| R81.20 Jumbo Hotfix Accumulator Take 105 | (TAR) |
| R81.10 Jumbo Hotfix Accumulator Take 177 | (TAR) |
| R81 Jumbo Hotfix Accumulator Take 107 | (TAR) |
| R80.40 Jumbo Hotfix Accumulator Take 211 | (TGZ) |
- For hotfix installation instructions on Quantum Security Gateways, see: sk168597 - How to install a Hotfix.
- Customers who run earlier Jumbo Hotfix Accumulator Takes must upgrade to the relevant Jumbo Hotfix Accumulator Take that is listed in the table above.
- Customers who run earlier versions must upgrade to one of the supported versions.
For Quantum Spark Appliances:
| Hotfix on Top of | Appliance Model | Download Link |
| R82.00.00 | 2580 2570 2560 |
(IMG) |
| 2550 2530 |
(IMG) | |
| R81.10.17 | 2000 1900 1800 1600 |
(IMG) |
| 1595 1590 1575R 1575 1570R 1570 1555 1550 1535 1530 |
(IMG) | |
| 1595R | (IMG) |
- For the image upgrade instructions on Quantum Spark Gateways, see: R81.10.X Quantum Spark Locally Managed Administration Guide.
- Customers who run earlier versions must upgrade to one of the versions listed in the table above.