Certificate verification failures occur for the following reasons:
Important: The failures you see at your site will depend, in part, on the CVE options you have enabled.
- A certificate that was not issued by a CA in Content Gateway’s trusted CA list; this is often a self-signed certificate
- A certificate that was not issued by a CA that is trusted by the destination server
- A revoked CA (on a CRL or OCSP list)
- An expired or not yet valid certificate
- An expired, not yet valid, or revoked certificate in the certificate chain
- A self-signed certificate in the chain
- A name mismatch between the hostname and URL, or similar (hostname and the Common Name, hostname and the Subject Alternative Name; hostname and use of a wildcard in the certificate)
- Missing and/or optional fields in the certificate (no CRL or OCSP state; result in “Unknown revocation state” errors)
- A problem in the logic of the CVE