# VPN/Remote Access Security Gateways Using DigiCert/GeoTrust CA

**Product**
- HTTPS Inspection, Remote Access VPN, Site-to-Site VPN

**Version**
- R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, R82.10

**OS**
- Gaia, Gaia Embedded

**Last Modified**
- 2025-11-19

## Solution

DigiCert has [announced](https://docs.digicert.com/en/whats-new/change-log/certcentral-change-log.html#important-http-protocol-changes-for-ocsp-and-crl-certificate-status-checks-619426) that starting 22 September 2025, they will only support Hypertext Transfer Protocol (HTTP)/1.0 with a proper "Host" header, HTTP/1.1, and HTTP/1.2 connections for Online Certificate Status Protocol (OCSP) and certificate revocation lists (CRL) checks.

There is **no need** to update your Check Point Security Gateways for Site-to-Site VPN, Remote Access VPN, and Outbound HTTPS Inspection for sites working with a DigiCert-generated certificate. These services will continue to operate smoothly beyond the 22 September 2025 timeline, even without applying the hotfix in advance.

That said, our latest Jumbo Hotfix Accumulator changes the communication method from HTTP/1.0 to HTTP/1.1, ensuring long-term compatibility with all certificate authority services looking ahead.

### Recommended step - Install Jumbo Hotfix Accumulator

The fix is included in these Jumbo Hotfix Accumulators:

**Note that Check Point Recommended version for all deployments is [R82](https://support.checkpoint.com/results/sk/sk181127) with its [Recommended Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) Take.**

|     |     |
| --- | --- |
| **Version** | **Take #** |
| **R82** Jumbo Hotfix Accumulator | [Latest Take 41](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/R82_Downloads.htm) |
| **R81.20** Jumbo Hotfix Accumulator | [Latest Take 115](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/R81.20_Downloads.htm) |
| **R81.10** Jumbo Hotfix Accumulator | [Recommended Take 181](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/R81.10/R81.10_Downloads.htm) |
| Jumbo Hotfix Accumulator for **Quantum Force 3900 Appliances** | [Latest Take 22](https://support.checkpoint.com/results/sk/sk183557) |

For earlier Jumbo Hotfix Accumulator Takes and earlier versions, install the hotfix from the table below.

### Hotfix that updates Security Gateway / Quantum Spark Gateway to use HTTP 1.1 by default for CRL validation

The Hotfix is available for **manual download** from this table:

- **For Quantum Security Gateways / Cluster Members / Scalable Platform Security Groups:**

|     |     |
| --- | --- |
| **Hotfix on Top of** | **Download Link** |
| **R82.10** |  (TAR) |
| **R82** Jumbo Hotfix Accumulator Take 39 |  (TAR) |
| **R82** Jumbo Hotfix Accumulator Take 36 |  (TAR) |
| **R82** Jumbo Hotfix Accumulator Take 34 |  (TAR) |
| **R81.20** Jumbo Hotfix Accumulator Take 113 or Take 111 |  (TAR) |
| **R81.20** Jumbo Hotfix Accumulator Take 105 |  (TAR) |
| **R81.10** Jumbo Hotfix Accumulator Take 177 |  (TAR) |
| **R81** Jumbo Hotfix Accumulator Take 107 |  (TAR) |
| **R80.40** Jumbo Hotfix Accumulator Take 211 |  (TGZ) |

- For hotfix installation instructions on Quantum Security Gateways, see: [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).
- Customers who run earlier Jumbo Hotfix Accumulator Takes must upgrade to the relevant Jumbo Hotfix Accumulator Take that is listed in the table above.
- Customers who run earlier versions must upgrade to one of the supported versions.

**For Quantum Spark Appliances:**

|     |     |     |
| --- | --- | --- |
| **Hotfix on Top of** | **Appliance Model** | **Download Link** |
| **R82.00.00** | **2580**<br>**2570**<br>**2560** |  (IMG) |
| **2550**<br>**2530** |  (IMG) |
| **R81.10.17** | **2000**<br>**1900**<br>**1800**<br>**1600** |  (IMG) |
| **1595**<br>**1590**<br>**1575R**<br>**1575**<br>**1570R**<br>**1570**<br>**1555**<br>**1550**<br>**1535**<br>**1530** |  (IMG) |
| **1595R** |  (IMG) |

- For the image upgrade instructions on Quantum Spark Gateways, see: [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Backup-Restore-Upgrade-and-Other-System-Operatons.htm#Using_the_Software_Upgrade_Wizard).
- Customers who run earlier versions must upgrade to one of the versions listed in the table above.
