> Source: [sk173971](https://support.checkpoint.com/results/sk/sk173971)

# sk173971 - VPN Users fail to authenticate with Certificates, validation fails due to wrong handling of root CA

| Property | Value |
|----------|-------|
| Solution ID | sk173971 |
| Date Created | 2021-07-15 |
| Last Modified | 2021-07-18 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Certificate validation fails for VPN users.
* Output of the `cvpnd` command shows:  

  ```
  [fdt] get_distribution_point_str: Error - Failed to get certificate's distribution points 
  
  [fdt] get_crl_url: Error - Failed to get certificate's first distribution point 
  
  [OCSP] getOCSPServerAccessInfo: found 1 OCSP URLs in AuthorityInfoAccess extension. 
  
  [OCSP] fwOCSP_getServerAccessInfo: got the access info from the cert 
  
  [fdt] download_crl_ocsp_from_fwcert_and_check_ca: entered. proxy: 
  
  [fdt] download_crl_ocsp_from_fwcert_and_check_ca: CRL filename: /opt/CPshrd-R80.40/tmp/curl_crl_ocsp/gate1.goyyamobile.com.crl 
  
  [fdt] download_crl_ocsp_from_fwcert_and_check_ca: Mutex lock name: libcurl_dl_crl_00d0ab64be1a7c5650364e7b4266edf44f 
  
  [fdt] get_distribution_point_str: Error - Failed to get certificate's distribution points 
  
  [fdt] get_crl_url: Error - Failed to get certificate's first distribution point 
  
  [fdt] download_crl_ocsp_from_fwcert_and_check_ca: Error - failed to get certificate's CRL or OCSP
  ```

## Cause

A certificate's chain usually does not contain the root Certificate Authority (CA). The root CA has no Certificate revocation list (CRL) and no Online Certificate Status Protocol (OCSP). As a result, certificate validation fails.

## Solution

This problem was fixed. The fix is included in:   

* [**Check Point R81.10**](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170416)
* **[Jumbo Hotfix Accumulator for R81 starting from Take 13](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170114)**
* **[Jumbo Hotfix Accumulator for R80.40 starting from Take 91](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456)**

<br />

Check Point recommends to always upgrade to the most recent version (upgrade [Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=435) / upgrade [Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=184) / upgrade [Multi-Domain Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=166)).  

**Related Solution:** [sk167177 - DynamicID authentication fails due to server certificate validation failure, if the server certificate does not contain a CRL distribution point](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk167177).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
