<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.10 - ICA renewed - mcc replace failed in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-10-ICA-renewed-mcc-replace-failed/m-p/163322#M27272</link>
    <description>&lt;P&gt;Thanks for Reply and hints, we plan to virtualize the system, going back in date and time, so that we have the old system before ICA timed out and then do the upgrade again and the ica renewal. That should work. TAC case is open, awaiting their ideas.&amp;nbsp;&lt;BR /&gt;best regards&lt;BR /&gt;Gero&lt;/P&gt;</description>
    <pubDate>Mon, 28 Nov 2022 09:02:00 GMT</pubDate>
    <dc:creator>Gero_Stolle</dc:creator>
    <dc:date>2022-11-28T09:02:00Z</dc:date>
    <item>
      <title>R80.10 - ICA renewed - mcc replace failed</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-ICA-renewed-mcc-replace-failed/m-p/163177#M27220</link>
      <description>&lt;P&gt;Hello Mates,&lt;BR /&gt;I plan to upgrade a R80.10 standalone system,&amp;nbsp;so I update first to the last Jumbo.&amp;nbsp;&lt;BR /&gt;but in between the ICA was outdated and no access to the Smartconsole was possible&lt;BR /&gt;so I did the ICA renew by following&amp;nbsp;&lt;SPAN&gt;sk158096 and using the&amp;nbsp;ICA_renewal_V7.sh not yet realizing that this script may be not valid for R80.10.&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;I got following error in the last step when MCC replace should exchange the ICA&amp;nbsp; to the database:&lt;/P&gt;&lt;P&gt;Expert@fred:0]# ./ICA_renewal_V7.sh&lt;BR /&gt;Please note that sk158096 exists with all relevant information regarding this process.&lt;BR /&gt;It is recommended to take a snapshot before running this procedure.&lt;BR /&gt;This script makes critical changes.&lt;BR /&gt;Are you still want to renew the internal CA (y/n)? y&lt;/P&gt;&lt;P&gt;About to ask the Internal CA to sign again its own certificate.&lt;/P&gt;&lt;P&gt;Re-signing the Internal CA certificate finished successfully.&lt;/P&gt;&lt;P&gt;The new certificate is saved to file 'new_ica.cer'.&lt;/P&gt;&lt;P&gt;Note that the new certificate is not loaded into the objects database.&lt;BR /&gt;Use the following command to replace the ICA certificate in the objects database:&lt;BR /&gt;mcc replace internal_ca new_ica.cer&lt;/P&gt;&lt;P&gt;MCC: [ERROR] Failed to login.&lt;BR /&gt;MCC: CA objects not loaded.&lt;BR /&gt;MCC: Could not find CA internal_ca.&lt;BR /&gt;ICA certificate replacement in MGMT database failed. Exiting...&lt;BR /&gt;&lt;BR /&gt;so I tried again&lt;BR /&gt;[Expert@fred:0]# mcc replace internal_ca new_ica.cer&lt;BR /&gt;MCC: [ERROR] Failed to login.&lt;BR /&gt;MCC: CA objects not loaded.&lt;BR /&gt;MCC: Could not find CA internal_ca.&lt;BR /&gt;[Expert@fred:0]#&lt;/P&gt;&lt;P&gt;but the log ist successful and the certs are there&lt;BR /&gt;[Expert@fred:0]# mcc lca&lt;BR /&gt;MCC: [ERROR] Failed to login.&lt;BR /&gt;MCC: CA Objects not loaded&lt;BR /&gt;&lt;BR /&gt;echo $(pwd)/InternalCA.p12&lt;BR /&gt;/home/admin/InternalCA.p12&lt;BR /&gt;&lt;BR /&gt;sicRenew -d&lt;BR /&gt;was successful too, so I have valid cert's now, only not able to add them to the database&amp;nbsp;&lt;BR /&gt;checked by&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;cpopenssl pkcs12 -in $FWDIR/conf/InternalCA.p12 -nokeys -nomacver -passin pass: 2&amp;gt;/dev/null | cpopenssl x509 -noout -enddate&lt;BR /&gt;and&lt;BR /&gt;cpca_client lscert -stat Valid -kind SIC&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;I already asked my customer if the Admin Account which was used to established the system was deleted and substituted with a new account.&amp;nbsp;&lt;BR /&gt;May be this could be the reason&amp;nbsp; ?&lt;BR /&gt;-&amp;nbsp; any ideas for fixing this ?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I would appreciate any input&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks in Advance&lt;BR /&gt;&lt;BR /&gt;Gero&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 11:53:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-ICA-renewed-mcc-replace-failed/m-p/163177#M27220</guid>
      <dc:creator>Gero_Stolle</dc:creator>
      <dc:date>2022-11-25T11:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - ICA renewed - mcc replace failed</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-ICA-renewed-mcc-replace-failed/m-p/163228#M27241</link>
      <description>&lt;P&gt;The ICA should have no connection to admin users.&lt;BR /&gt;There may be some additional corruption here and recommend engaging with the TAC.&lt;BR /&gt;Yes, R80.10 is End of Support, but since your goal is to complete an upgrade, you should be able to get assistance.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 20:50:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-ICA-renewed-mcc-replace-failed/m-p/163228#M27241</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-25T20:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - ICA renewed - mcc replace failed</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-ICA-renewed-mcc-replace-failed/m-p/163244#M27247</link>
      <description>&lt;P&gt;I read your post very carefully and I have to agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;. It seems that something got corrupted and might be worth to check with support. Not sure if there is an easy way to fix this, but maybe debug would prove that.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Nov 2022 13:57:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-ICA-renewed-mcc-replace-failed/m-p/163244#M27247</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-26T13:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - ICA renewed - mcc replace failed</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-ICA-renewed-mcc-replace-failed/m-p/163322#M27272</link>
      <description>&lt;P&gt;Thanks for Reply and hints, we plan to virtualize the system, going back in date and time, so that we have the old system before ICA timed out and then do the upgrade again and the ica renewal. That should work. TAC case is open, awaiting their ideas.&amp;nbsp;&lt;BR /&gt;best regards&lt;BR /&gt;Gero&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 09:02:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-ICA-renewed-mcc-replace-failed/m-p/163322#M27272</guid>
      <dc:creator>Gero_Stolle</dc:creator>
      <dc:date>2022-11-28T09:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - ICA renewed - mcc replace failed</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-ICA-renewed-mcc-replace-failed/m-p/163388#M27280</link>
      <description>&lt;P&gt;That might be your best bet for resolving this issue, actually (backdating the system or a clone of it and renew the ICA before it expires).&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 14:45:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-ICA-renewed-mcc-replace-failed/m-p/163388#M27280</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-28T14:45:46Z</dc:date>
    </item>
  </channel>
</rss>

