Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Content Gateway SSL Certificate Verification v7.8 > Troubleshooting Certificate Verification Failures
Troubleshooting Certificate Verification Failures
This section describes how to use resources in Content Gateway and on your PC to troubleshoot certificate verification failures.
As new information becomes available, updated Troubleshooting information will be posted online to Troubleshooting for Certificate Verification.
 
Note 
When a failure occurs:
1.
2.
Log on to the Content Gateway manager and go to Configure > SSL > Incidents > Incidents List.
3.
4.
If the message is:
If the Verify entire certificate chain option is enabled, the "Valid from" date of every certificate in the chain may have to be checked. Look for the "depth=" value in the error message for the level in the chain at which the error occurred.
Note: Also check that the time and date are set correctly on the Content Gateway host system. To check the time in the Content Gateway manager, go to Monitor > My Proxy > Alarms.
If the Verify entire certificate chain option is enabled, the expiration date of every certificate in the chain may have to be checked. Look for the "depth=" value in the error message for the level in the chain at which the error occurred.
To verify and remediate the condition, log on to the Content Gateway manager and go to Configure > SSL > Certificates > Certificates Authorities. The new CA should be listed with a red cross to the left. This CA was offered as part of the SSL handshake and added to the CA tree with the status: untrusted.
After validating the CA with Content Gateway, set the allow or deny status. From the Certificate Authorities page, select the CA to view the deny and allow options. If you elect to allow the CA, delete the incident and go to the site to verify access.
Note: When a client certificate is required, there is an option to bypass the client certificate. The default bypass option is to create an incident by going to the SSL > Client Certificates > General page.

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Content Gateway SSL Certificate Verification v7.8 > Troubleshooting Certificate Verification Failures
Copyright 2016 Forcepoint LLC. All rights reserved.