- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
AI Security Masters
LGTM: Bypassing an LLM Build Gate
When Prompt Injection Fails
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
CheckMates Go:
Half is Not Enough
Hey guys,
I wanted to run something by you all to see if what Im thinking makes sense. So I was helping customer today with trying to upgrade brand new dedicated log server from R82 jumbo 60 to R82.10, but verification kept failing saying file sic_conf.p12 did not exist. I never seen that before, but was thinking it could be because that log server currently is not connected to the mgmt, shows error in smart console and we noticed sic is also broken.
Not 100% sure if thats required for the upgrade itself, but cant really think of anything else.
Thoughts?
Tx as always!
I agree.
Makes sense that the upgrade attempt should only be allowed on a healthy fully functioning log/management server, including SIC with the primary SMS.
Why was SIC not working between them?
I just had a little look around in the upgrade scripts. What surprises me is that I don't see any mention of the sic_conf.p12 file mentioned by Any.
When I search for the sic_cert.p12 file I found in the scripts, I see the following in the file /opt/CPupgrade-tools-R82.10/scripts/run_puv.sh referenced by migrate_server and co.:
# 17. Block upgrade in case sic_cert.12 file is not exists
if [ "X$MDSDIR" = "X" ]; then
if [ "X$isManagement" == "X1" -o "X$isLogServer" == "X1" ]; then
if [ ! -f "$CPDIR/conf/sic_cert.p12" ]; then
if [ "X$isPrimary" != "X1" ]; then
# file is not exists
output="${output}\n$i. The file $CPDIR/conf/sic_cert.p12 is missing."
i=$((i+1))
fi
fi
fi
fi
Hey boys,
As suspected, was SIC issue. We did reset sic on log server, communication worked, then upgrade to R82.10 succedded.
Tx as always for all your support.
I'm not familiar with this file either, but I've never had to run the verifier on a log server without an established SIC.
I mean, the SIC connection should already be established, then this error will also be gone.
However, as I am not familiar with the file or the error, I may be mistaken.
Interesting is that i don't find this file on our MLMs but files with similar names:
/var/opt/CPshrd-R82/conf/sic_local_cert.p12
/var/opt/CPshrd-R82/conf/sic_cert.p12
Did that search go into the DLS/CLM customer sub directories?
Yes. I did a
find / -name "*.p12" 2>/dev/null
And found this file in the directories above and in all customers conf folders
/var/opt/CPmds-R82/customers/<customer name>/CPshrd-R82/conf/sic_local_cert.p12
I just had a little look around in the upgrade scripts. What surprises me is that I don't see any mention of the sic_conf.p12 file mentioned by Any.
When I search for the sic_cert.p12 file I found in the scripts, I see the following in the file /opt/CPupgrade-tools-R82.10/scripts/run_puv.sh referenced by migrate_server and co.:
# 17. Block upgrade in case sic_cert.12 file is not exists
if [ "X$MDSDIR" = "X" ]; then
if [ "X$isManagement" == "X1" -o "X$isLogServer" == "X1" ]; then
if [ ! -f "$CPDIR/conf/sic_cert.p12" ]; then
if [ "X$isPrimary" != "X1" ]; then
# file is not exists
output="${output}\n$i. The file $CPDIR/conf/sic_cert.p12 is missing."
i=$((i+1))
fi
fi
fi
fi
I will have remote with the customer in few hours, will see once we connect this log server to mgmt what happens.
I agree.
Makes sense that the upgrade attempt should only be allowed on a healthy fully functioning log/management server, including SIC with the primary SMS.
Why was SIC not working between them?
Long story Don. Its a large hospital and too many people involved in this...anyway, once we get sic working, will try again. Tx for the help, as always,
Hey boys,
As suspected, was SIC issue. We did reset sic on log server, communication worked, then upgrade to R82.10 succedded.
Tx as always for all your support.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 30 | |
| 9 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEATue 06 Oct 2026 @ 02:00 PM (EDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus AMERTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEATue 06 Oct 2026 @ 02:00 PM (EDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus AMERThu 08 Oct 2026 @ 11:00 AM (EDT)
Under the Hood: Check Point SASE | Zero Trust Network Access, Step by StepAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY