> Source: [sk117892](https://support.checkpoint.com/results/sk/sk117892)

# sk117892 - SSL Handshake fails when HTTPS Inspection Probe Bypass and ECDHE ciphers enabled

| Property | Value |
|----------|-------|
| Solution ID | sk117892 |
| Date Created | 2017-06-06 |
| Last Modified | 2019-07-22 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * **Probe bypass is enabled as per [sk104717](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104717)** ,   
  Output of the following command shows value of 1:  
  *\[Expert@Home\]# fw ctl get int enhanced_ssl_inspection*   
  enhanced_ssl_inspection = 1  

* **ECDHE ciphers are allowed as per [sk104717](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104717),**   
  Output of the following command shows value of 1:  
  *\[Expert@Home\]# cat $CPDIR/registry/HKLM_registry.data \| grep -i ecdhe*   
  :CPTLS_ACCEPT_ECDHE (1)  
  :CPTLS_PROPOSE_ECDHE (1)  

* **WSTLSD debug as per [sk105559](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105559) shows the following errors:**   
  *CLN_SKE_verify_signature: failed to verify ECDHE params. rc: -100
  CLN_handle_SKE_ecdhe_v12: CLN_SKE_verify_signature failed. rc_verify: -974
  CLN_handle_ServerKeyExchange: failed to handle ServerKeyExhange. rc: -974*

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
