- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hey guys,
I wanted to run something by you all to see if what Im thinking makes sense. So I was helping customer today with trying to upgrade brand new dedicated log server from R82 jumbo 60 to R82.10, but verification kept failing saying file sic_conf.p12 did not exist. I never seen that before, but was thinking it could be because that log server currently is not connected to the mgmt, shows error in smart console and we noticed sic is also broken.
Not 100% sure if thats required for the upgrade itself, but cant really think of anything else.
Thoughts?
Tx as always!
I agree.
Makes sense that the upgrade attempt should only be allowed on a healthy fully functioning log/management server, including SIC with the primary SMS.
Why was SIC not working between them?
I just had a little look around in the upgrade scripts. What surprises me is that I don't see any mention of the sic_conf.p12 file mentioned by Any.
When I search for the sic_cert.p12 file I found in the scripts, I see the following in the file /opt/CPupgrade-tools-R82.10/scripts/run_puv.sh referenced by migrate_server and co.:
# 17. Block upgrade in case sic_cert.12 file is not exists
if [ "X$MDSDIR" = "X" ]; then
if [ "X$isManagement" == "X1" -o "X$isLogServer" == "X1" ]; then
if [ ! -f "$CPDIR/conf/sic_cert.p12" ]; then
if [ "X$isPrimary" != "X1" ]; then
# file is not exists
output="${output}\n$i. The file $CPDIR/conf/sic_cert.p12 is missing."
i=$((i+1))
fi
fi
fi
fi
Hey boys,
As suspected, was SIC issue. We did reset sic on log server, communication worked, then upgrade to R82.10 succedded.
Tx as always for all your support.
I'm not familiar with this file either, but I've never had to run the verifier on a log server without an established SIC.
I mean, the SIC connection should already be established, then this error will also be gone.
However, as I am not familiar with the file or the error, I may be mistaken.
Interesting is that i don't find this file on our MLMs but files with similar names:
/var/opt/CPshrd-R82/conf/sic_local_cert.p12
/var/opt/CPshrd-R82/conf/sic_cert.p12
Did that search go into the DLS/CLM customer sub directories?
Yes. I did a
find / -name "*.p12" 2>/dev/null
And found this file in the directories above and in all customers conf folders
/var/opt/CPmds-R82/customers/<customer name>/CPshrd-R82/conf/sic_local_cert.p12
I just had a little look around in the upgrade scripts. What surprises me is that I don't see any mention of the sic_conf.p12 file mentioned by Any.
When I search for the sic_cert.p12 file I found in the scripts, I see the following in the file /opt/CPupgrade-tools-R82.10/scripts/run_puv.sh referenced by migrate_server and co.:
# 17. Block upgrade in case sic_cert.12 file is not exists
if [ "X$MDSDIR" = "X" ]; then
if [ "X$isManagement" == "X1" -o "X$isLogServer" == "X1" ]; then
if [ ! -f "$CPDIR/conf/sic_cert.p12" ]; then
if [ "X$isPrimary" != "X1" ]; then
# file is not exists
output="${output}\n$i. The file $CPDIR/conf/sic_cert.p12 is missing."
i=$((i+1))
fi
fi
fi
fi
I will have remote with the customer in few hours, will see once we connect this log server to mgmt what happens.
I agree.
Makes sense that the upgrade attempt should only be allowed on a healthy fully functioning log/management server, including SIC with the primary SMS.
Why was SIC not working between them?
Long story Don. Its a large hospital and too many people involved in this...anyway, once we get sic working, will try again. Tx for the help, as always,
Hey boys,
As suspected, was SIC issue. We did reset sic on log server, communication worked, then upgrade to R82.10 succedded.
Tx as always for all your support.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 63 | |
| 19 | |
| 13 | |
| 12 | |
| 12 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY