> Source: [sk1000027](https://support.checkpoint.com/results/sk/sk1000027)

# sk1000027 - Identity Broker identity propagation is delayed or inconsistent.

| Property | Value |
|----------|-------|
| Solution ID | sk1000027 |
| Date Created | 2026-08-24 |
| Last Modified | 2026-09-02 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82 |
| OS | Gaia |

## Symptoms

- * Identity sessions published by an Identity Broker are propagated with significant delays or not propagated at all.

<!-- -->

* A traffic capture of the traffic between the Identity Publisher gateway and Identity Subscriber gateway shows repeated CRL validation attempts on port 18264 and HTTPS connections that are delayed by 10 seconds in the middle of the connection.

<!-- -->

* On the CLI
* On the CLI of the Identity Publisher gateway and on the Identity Subscriber Gateway, output of `'pdp broker status -e`' shows the connection between the Publisher and Subscriber in 'sync' state with frequent "*no connection*" errors:

<!-- -->

* In the Identity Publisher configuration file (*$FWDIR/conf/identity_broker.C* ), the value of the `'crl_validation_config`' parameter is '`fail_open`'.

## Cause

When an Identity Publisher gateway publishes identity sessions, it validates the Identity Subscriber gateway\\ss TLS certificate against a Certificate Revocation List hosted on the Management Server, using a per-connection CRL download over TCP port 18264. When this download is unavailable and crl_validation_config is set to fail_open , the Identity Broker continues to send data. The waiting period for the failed download, roughly 10 seconds per connection, is added to every single broker message. As a result, every identity sync message is delayed for 10 seconds, making the connection to appear out of sync.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
