> Source: [sk114296](https://support.checkpoint.com/results/sk/sk114296)

# sk114296 - Random logs with "failed to fetch CRL" error during CRL fetch

| Property | Value |
|----------|-------|
| Solution ID | sk114296 |
| Date Created | 2016-11-02 |
| Last Modified | 2020-07-07 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * HTTPS Inspection log in SmartView Tracker shows:

  `Failed to fetch CRL from the following URLs:`  
  `
  ....`  
  `
  Make sure the security gateway has an outgoing http access, and that the proxy and DNS servers are well configured`

  *Example* :  

  [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk114296/11611020254.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk114296/11611020254.png "Click the image to see it in full size in a new tab/window")
* Debug WSTLSD daemon (per [sk105559](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105559)) on Security Gateway shows:

  `
  cptls_hs_handleValidationResult: validation result code: -986 level: 0`  
  `
  ResultWithCRL: check CRLs 2, IsRevoked: -986`  
  `
  cptls_hs_handleValidationResult: certificate validation failed. level: 0, error code: -986`  
  `
  cptls_hs_handleValidationResult: level: 0, chain_error: -302
  `
* Kernel debug ('`fw ctl debug -m fw + drop cptls crypt`') on Security Gateway shows:

  `fwtls_handle_ioctl: resource: XXX`  
  `
  fwtls_handle_ioctl: validation_id: invalid;`
* Debug of VPND daemon (per [sk89940](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk89940)) on Security Gateway shows:

  `
  Is_ICAdpContainsCRL0: DN points to CRL number 1. DN: http://<HostName_or_IP_of_MGMT_Server>:18264/ICA_CRL1.crl`  
  `
  [CRLCache] fwFetchCRL_e_With_Reason: CRL was not found in cache. Will fetch it async.`  
  `
  fwFetchCRL_do_fetch: found ongoing fetch for the same CRL DP: 0x... expire: 60`  
  `
  fwCRL_validateRevocation: unkonw return from fwFetchCRL 4`  
  `
  fwCert_ValCerts: Could not retrieve CRL.
  `

## Cause

Multiple asynchronous calls to fetch CRLs. In some scenarios, this can impact the VPND daemon.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
