<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml">
  <head runat="server">
    <!-- PageID 382 - published by RedDot 7.5 - 7.5.1.69 - 22111 -->
    <META name="PublicArticle" content="True" />
    <META http-equiv="Content-Type" content="text/html; charset=utf-8" />
    <META name="keywords" />
    <META name="summary" />
    <META name="product" content="fp_web" />
    <META name="version" content="v85" />
    <META name="book" content="Content Gateway Manager Help, v8.5.x" />
    <title>Validating certificates</title>
    <!--Loading the 2016 fonts.-->
    <script type="text/javascript" src="//fast.fonts.net/jsapi/c504d579-e135-4f75-8335-4906f6c6ce67.js"></script>
    <!--Library content styles.-->
    <link rel="StyleSheet" href="https://help.forcepoint.com/docs/ni/assets/css/help2016.css" type="text/css" media="all" />
    <!--2016 font support -->
    <link type="text/css" rel="stylesheet" href="//fast.fonts.net/cssapi/c504d579-e135-4f75-8335-4906f6c6ce67.css" />
  </head>
  <body>
    <!--googleoff: all-->
    <a href="https://www.forcepoint.com">
      <img class="logo" alt="Forcepoint logo" src="https://help.forcepoint.com/docs/ni/assets/logo1.png" />
    </a>
    <div class="extLinksContainer">
      <a class="extLinks" href="//support.forcepoint.com/documentation">Documentation</a> | <a class="extLinks" href="//support.forcepoint.com">Support</a></div>
    <!--
		<wsApp:UserAccess ID="useraccess1" runat="server" IsSecure="False" />
		-->
    <div class="spacer1"></div>
    <br />
    <!-- New Navigation DIV -->
    <div class="TL_nav" style="text-align: left;">
      <table cellspacing="0" class="toolBarTable" summary="">
        <!-- End New Navigation DIV -->
        <tr>
          <td>
            <!-- New Go To TOC -->
            <a href="toc.aspx"><img src="images/toc.png" alt="Go to the table of contents" border="0" /></a>
            <!-- End Go To TOC -->
          </td>
          <td>
            <!-- New Previous -->
            <a href="ssl_outbound.aspx"><img src="images/prev.png" alt="Go to the previous page" border="0" /></a>
            <!-- End New Previous -->
          </td>
          <td>
            <!-- New Next (Active) -->
            <a href="ssl_bypass_verify.aspx"><img src="images/next.png" alt="Go to the next page" border="0" /></a>
            <!-- End New Next (Active) -->
          </td>
          <td>
            <!-- New PDF -->
            <a href="wcg_help.pdf"><img src="images/pdf.png" alt="View or print as PDF" border="0" /></a>
            <!-- End New PDF -->
          </td>
          <!--Start JR breadcrumbs -->
          <td width="20px"></td>
          <td>
            <div class="WebWorks_Breadcrumbs" style="text-align: left;">
              <a class="WebWorks_Breadcrumb_Link" href="ssl_intro.aspx">Working With Encrypted Data</a> &gt; Validating certificates</div>
          </td>
          <!--End JR breadcrumbs -->
        </tr>
      </table>
    </div>
    <!--googleon: all-->
    <div>
      <div class="N1H-Heading1"><a name="818315">Validating certificates</a></div>
      <div class="IN-TopicInfo"><a name="818203">Help | Content Gateway | v8.5.x</a></div>
      <table class="DropListTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="DLC-ClosedDynamicList" onclick="WebWorks_ToggleDIV(WebWorksRootPath, &quot;wwdd818193&quot;);"><a name="818193">Related topics:</a><script type="text/javascript" language="JavaScript1.2">WebWorks_WriteArrow(WebWorksRootPath, "wwdd818193", false);</script></div>
            <script type="text/javascript" language="JavaScript1.2">WebWorks_WriteDIVOpen("wwdd818193", false);</script>
            <div class="B1-Bullet1_outer" style="margin-left: 0pt">
              <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
                <tr style="vertical-align: baseline">
                  <td>
                    <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                      <img src="b1.png" alt="*" border="0" width="8" height="8" />
                    </div>
                  </td>
                  <td width="100%">
                    <div class="B1-Bullet1_inner"><span class="LEM-LinkEmphasis"><a href="ssl_bypass_verify.aspx" title="Bypassing verification" name="818197">Bypassing verification</a></span></div>
                  </td>
                </tr>
              </table>
            </div>
            <div class="B1-Bullet1_outer" style="margin-left: 0pt">
              <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
                <tr style="vertical-align: baseline">
                  <td>
                    <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                      <img src="b1.png" alt="*" border="0" width="8" height="8" />
                    </div>
                  </td>
                  <td width="100%">
                    <div class="B1-Bullet1_inner"><span class="LEM-LinkEmphasis"><a href="ssl_revoc_info.aspx" title="Keeping revocation information up to date" name="818202">Keeping revocation information up to date</a></span></div>
                  </td>
                </tr>
              </table>
            </div>
            <script type="text/javascript" language="JavaScript1.2">WebWorks_WriteDIVClose();</script>
          </td>
        </tr>
      </table>
      <div class="B-Body"><a name="818204">SSL certificate verification is an important component of SSL security. Through certificate exchange and verification, the client (Content Gateway) and the origin server verify that each is who it says it is.</a></div>
      <div class="B-Body"><a name="749371">Content Gateway performs this task with the certificate verification engine (CVE). </a></div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="746377">Use the tabs on the </a><span class="B-Bold">Configure&nbsp;&gt; My Proxy&nbsp;&gt; SSL&nbsp;&gt; Validation</span> page to enable and configure the CVE. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="746014">For information about options when verification fails and you prefer to trust the site, see </a><span class="LEM-LinkEmphasis"><a href="ssl_bypass_verify.aspx" title="Bypassing verification">Bypassing verification</a></span>. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="749469">For a comprehensive discussion of the use and best practices of the CVE, see </a><span class="URL-URL"><a href="https://help.forcepoint.com/docs/web/v84/wcg_ssl_cve/first.aspx" target="external_window">SSL Certificate Verification Engine</a></span>.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="N2HN-HeadNoTopic2">
        <span class="Heading_Number"></span><a name="747204">Configuring validation settings</a></div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">1.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="747243">In the Content Gateway manager, go to the </a><span class="B-Bold">Configure&nbsp;&gt; SSL&nbsp;&gt; Validation&nbsp;&gt; General</span> tab.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">2.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="747244">If it is not already selected, mark the </a><span class="B-Bold">Enable the certificate verification engine</span> check box.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="749528">Certificate verification is enabled by default.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="749546">If this option is not selected, certificate validation does not occur.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">3.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="747271">Indicate whether or not to </a><span class="B-Bold">Deny certificates where the common name does not match the URL</span>. When this option is selected, 2 checks are made:</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="750992">The certificate's Common Name is checked for an exact match of the destination URL.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="749722">If the first check fails, the certificate's Subject Alternative Name (SAN) list is checked for an exact match of the destination URL.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="749732">Checks are case</a><span class="B-Bold"> insensitive</span>.</div>
      <div class="I-IndentedText"><a name="747272">Because an exact match is required, there may be instances when a legitimate variation in the Common Name, or the absence of a matching variation in the SAN, may result in a block.</a></div>
      <div class="I-IndentedText"><a name="747273">For example, using "https://cia.gov" to access "https://www.cia.gov" may result in a block. Additionally, a block may occur when users attempt to access a site by IP address.</a></div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">4.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="751050">If you have enabled the Deny certificates option, indicate whether or not to </a><span class="B-Bold">Allow wildcard certificates</span>. When selected, this option allows matches with Common Names that include the "*" (wildcard) character in the name. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="749747">Some HTTPS servers use a wildcard in the Common Name so that a single certificate can cover an entire domain. For example, "*.example.com" could cover "email.example.com" and "stream.example.com", among others.</a></div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="747333">Use of the wildcard means that individual servers within the domain are not verified; they are included as a result of the wildcard.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="747334">Allowing wildcard certificates eases the strict matching burden when a Common Name match is required. It is also helpful for domains that have multiple subdomains like google.com or yahoo.com. It also introduces some risk that a fraudulent or undesirable variation of a domain may go unblocked.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">5.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="798038">Select the </a><span class="B-Bold">No expired or not yet valid certificates</span> option to deny access to sites that offer an expired or not yet valid certificate. This is a basic check that is important because many malicious sites operate with expired certificates.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="818795">If this option is not selected, access to those sites is permitted.</a></div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">6.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="818796">Indicate whether or not to </a><span class="B-Bold">Deny self-signed certificates</span>. By default, the option is enabled, and self-signed certificates (certificates without an official certificate authority) are considered invalid.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">7.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="747557">Indicate whether or not to </a><span class="B-Bold">Verify entire certificate chain</span>. By default, this option is enabled, and Content Gateway verifies expiration and revocation status of all certificates between the site certificate and the root Certificate Authority as specified in the certification path of the certificate. This is an important check.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">8.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="749769">Indicate whether or not to </a><span class="B-Bold">Check certificate revocation by CRL</span>. Certificate revocation lists (CRLs) are used to check a certificate's revocation status. CRLs list certificates that have been issued and subsequently revoked by the CA. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="749770">Verifying the revocation status is a basic check that is very important because certificates are revoked when they are improperly issued, have been compromised, have a false identity, or violate policies specified by the CA.</a></div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="761654">If this option is enabled, verify that the daily CRL update feature is enabled on the </a><span class="B-Bold">Revocation Settings</span> tab under <span class="B-Bold">CRL Settings</span>.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="761708">If this option is </a><span class="B-Bold">not</span> used, disable the daily CRL update feature on the <span class="B-Bold">Revocation Settings</span> tab under <span class="B-Bold">CRL Settings</span>.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">9.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="633498">Indicate whether or not to </a><span class="B-Bold">Check certificate revocation by OCSP</span>. Online Certificate Status Protocol (OCSP) is an alternate way to check a certificate's revocation status. While OCSP is beneficial, it is not used as widely as CRLs and therefore is not as reliable. Also, it is a real-time, Internet-hosted check that can introduce some request handling latency.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="F-Frame"><a name="633508"> </a></div>
      <table class="NoteTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="NI-NoteIcon">
              <img src="note.gif" alt="*" border="0" width="33" height="33" /><a name="633501">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="N-Note">Note<a name="633503">&nbsp;</a></div>
            <div class="NT-NoteText"><a name="633504">It is recommended that you use OCSP in addition to, rather than instead of, CRLs. See </a><span class="LEM-LinkEmphasis"><a href="ssl_revoc_info.aspx" title="Keeping revocation information up to date">Keeping revocation information up to date</a></span> for more information about CRLs and OCSP.</div>
          </td>
        </tr>
      </table>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">10.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="633509">If you are using OCSP revocation checking, use the </a><span class="B-Bold">Block certificates with Unknown OCSP state</span> option to determine whether to block certificates that return the "Unknown" status.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">11.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="748076">If both CRL and OCSP revocation checking are enabled, indicate your </a><span class="B-Bold">Preferred method for revocation check</span>. The selected method (CRL, by default), is applied first.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">12.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="748207">If you have enabled CRL or OCSP checking (or both), use the </a><span class="B-Bold">Block certificates with no CRL URI and with no OCSP URI</span> option to block certificates that do not have the expected, associated URIs. For example, if only CRL checking is enabled and the certificate doesn't have a CRL URI, if this option is enabled the connection is blocked. When both CRL and OCSP checking are enabled, the block occurs only if both CRL and OCSP lack a URI.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="748273">You can view URI information in the certificate when you select to view the certificate in your browser. See </a><span class="LEM-LinkEmphasis"><a href="c_certs.aspx" title="Managing certificates">Managing certificates</a></span> for details.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="748277">Because many certificates do not include CRL or OCSP information, this option can result in a high number of verification failures. Often the failures are reported as "Unknown revocation state" errors.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I2-IndentedText2"><a name="748278">This can result in a highly restrictive security policy, with many access denials.</a></div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="748310">As with all verification failures, you can allow for exceptions using the Incident List. See </a><span class="LEM-LinkEmphasis"><a href="c_incident.aspx" title="Managing HTTPS website access">Managing HTTPS website access</a></span>.</div>
            </td>
          </tr>
        </table>
      </div>
    </div>
    <!--googleoff: all-->
    <div class="library_search">
      <form class="support_search" action="/content/kb-search.aspx" method="get">
        <label></label>
        <label></label>
        <input type="text" name="q" value=" Search eSupport" onfocus="if (this.value == ' Search eSupport') {this.value = '';}" onblur="if (this.value == '') {this.value = ' Search eSupport';}"></input>
        <input type="submit" value=" "></input>
      </form>
    </div>
    <br class="clear" />
    <!-- New Navigation DIV -->
    <div class="TL_nav" style="text-align: left;">
      <table cellspacing="0" class="toolBarTable" summary="">
        <!-- End New Navigation DIV -->
        <tr>
          <td>
            <!-- New Go To TOC -->
            <a href="toc.aspx"><img src="images/toc.png" alt="Go to the table of contents" border="0" /></a>
            <!-- End Go To TOC -->
          </td>
          <td>
            <!-- New Previous -->
            <a href="ssl_outbound.aspx"><img src="images/prev.png" alt="Go to the previous page" border="0" /></a>
            <!-- End New Previous -->
          </td>
          <td>
            <!-- New Next (Active) -->
            <a href="ssl_bypass_verify.aspx"><img src="images/next.png" alt="Go to the next page" border="0" /></a>
            <!-- End New Next (Active) -->
          </td>
          <td>
            <!-- New PDF -->
            <a href="wcg_help.pdf"><img src="images/pdf.png" alt="View or print as PDF" border="0" /></a>
            <!-- End New PDF -->
          </td>
          <!--Start JR breadcrumbs -->
          <td width="20px"></td>
          <td>
            <div class="WebWorks_Breadcrumbs" style="text-align: left;">
              <a class="WebWorks_Breadcrumb_Link" href="ssl_intro.aspx">Working With Encrypted Data</a> &gt; Validating certificates</div>
          </td>
          <!--End JR breadcrumbs -->
        </tr>
      </table>
    </div>
    <div class="extFooterContainer">
      <div class="extFooter">
        <div align="center">Copyright 2023 Forcepoint. All rights reserved.</div>
      </div>
    </div>
    <SCRIPT>
   function getFileName() {
      //this gets the full url
      var url = document.location.href;
      //this removes the anchor at the end, if there is one
      url = url.substring(0, (url.indexOf("#") == -1) ? url.length : url.indexOf("#"));
      //this removes the query after the file name, if there is one
      url = url.substring(0, (url.indexOf("?") == -1) ? url.length : url.indexOf("?"));
      //this removes everything before the last slash in the path
      url = url.substring(url.lastIndexOf("/") + 1, url.length);
      //return
      return url;
   }

   var url = document.URL;
   var Docname = getFileName()
   s.pageName = "enu:support:technical library:v85xwcg_help:" + Docname;
   s.prop1 = "enu:support";
   s.prop2 = "enu:support:technical library";
   s.channel = "support";
   // <!--
   s.server = "<%= System.Environment.MachineName %>";
   //--></SCRIPT>
    <script language="javascript1.1" type="text/javascript">
   /********Do Not alter below this line ***********/
   var s_code = s.t(); if (s_code) document.write(s_code)
   //--&gt;</script>
  </body>
  <!--"GENERALQUARTERSALLHANDSMANYOURSTATIONS"-->
</html>