> Source: [sk172345](https://support.checkpoint.com/results/sk/sk172345)

# sk172345 - "Invalid CRL Retrieved" and "No Valid CRL" error messages in HTTPS Detect Logs

| Property | Value |
|----------|-------|
| Solution ID | sk172345 |
| Date Created | 2021-03-10 |
| Last Modified | 2023-05-08 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * When HTTPS Inspection is enabled and traffic is inspected, detect logs for HTTPS traffic show these error messages:  
  "`Invalid CRL Retrieved`"  
  "`No Valid CRL`"
* In case of Mobile Access with DynamicID authentication failing, cvpnd debug will show the following lines:  

  \[OCSP\] getOCSPServerAccessInfo: found 0 OCSP URLs in AuthorityInfoAccess extension.  
  \[OCSP\] getOCSPServerAccessInfo: could not find OCSP access in AuthorityInfoAccess extension.  
  \[OCSP\] fwOCSP_getServerAccessInfo: AuthorityInfoAccess extension not found in cert  
  \[fdt\] get_ocsp_url: no OCSP urls  
  \[fdt\] download_crl_ocsp_from_fwcert_and_check_ca: Error - failed to get certificate's CRL or OCSP  
  \[fdt\] get_crl_ocsp: Error - Failed to download current CRL file  
  \[fdt\] get_crl_ocsp: downloading CRLS  
  \[fdt\] get_crl_ocsp: Found 2 server certificates in the chain  
  \[fdt\] get_crl_ocsp: Subject of Certificate #0: 'CN=example.com'...  
  \[fdt\] get_distribution_point_str: Error - Failed to get certificate's distribution points  
  \[fdt\] get_crl_url: Error - Failed to get certificate's first distribution point  
  \[OCSP\] getOCSPServerAccessInfo: found 1 OCSP URLs in AuthorityInfoAccess extension.  
  \[OCSP\] fwOCSP_getServerAccessInfo: got the access info from the cert

## Cause

Revocation validation doesn't work when the certificates chain includes:

* **At least one certificate with CRL DP only**
* **At least one certificate with OCSP URL only**

<br />

## Solution

The current behavior is a warning log to indicate that the Security Gateway did not complete revocation checks for one of the certificates in the chain. The Security Gateway completes certificate validation and resumes the connection if it is valid.  

The fix is included in:

* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 61
* [Jumbo Hotfix Accumulator for R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170114) starting from Take 68
* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456&partition=Basic&product=All) starting from Take 161

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
