- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hi everyone,
I recently checked the sic certificates on our management server with “cpca_client lscert -stat Valid -kind SIC” and noticed an unknown certificate. The certificate name is the name of our management server and it’s not used for the internal ca or for anything else – or I couldn’t find it which might be the case.
I’ve checked sk20905 and sk43783 but I don’t think, they can be applied here. Furthermore I’ve checked every p12 on the server but none of those I’ve found, is the unknown certificate.
And running sicRenew –d ( sk43783 ) on a cloned vm in my testlab didn’t renew this certificate. I only renewed the “CN=cp_mgmt” certificate.
I tried “cpca_client create_cert -n "CN=CN=CP-FW-Mgmt.company.de" -f $CPDIR/conf/test_cert.p12” and this did create a new certificate but I’m unsure, if this is the correct way to renew this certificate.
Management server and both gateways are on R80.40 Take 180.
Is this certificate even needed ? And if so, how can I renew it ?
Many thanks for your help!
You guys are the best @PhoneBoy, @the_rock, @_Val_ ! Enabling ICA mgmt tool put me in the right path.
I followed the sk30501 for settings up access to the ICA but I couldn't access the ICA site although cpca_client set_mgmt_tool print showed that access was enabled and port 18265 was listening.
After some troubleshooting I found the solution for both problems in sk39915 in the notes section. Apparently the private key file was now longer valid or get corrupted as a result of the upgrade process. After running the next commands:
I was able to access the ICA management site. I wanted to find the certificate a bit easier using the serial number and ran cpca_client another time. To my surprise the expiring certificate was replaced by a new one. Success !
I added of few more screenshots if someone else is running into this issue. What I noticed is that the internalca_site.p12 file contains different certificates than I did expect. And apparently there is now a new internal_ca certificate ( expiring in 2038 ) and it is different to the internal_ca certificate shown in smart console.
I did some tests and everything seems to work. Thus I'm hopping there not a new problem now.
Anyway, many thanks again for your help!
Could it be that you are having a VPN to another company, with certificate authentication?
Thats odd indeed. So when I ran it on my lab mgmt server (R81.20), I see 5 entries and all of them refer to correct dates, as CN either shows cp_mgmt, mgmt host name OR gateway name. Did same on R81.10 mgmt and literally very similar output, shows expiring January 2027.
Question...when you log into smart console and navigate to servers -> trusted CA -> how many entries do you see there?
Andy
Hi guys,
under trusted CA I've got only one entry - the internal_ca with an expiration date in 2036. And I checked our VPN configuration as well. We have only a single tunnel to another company. And that one uses a cluster certificate which is expiring in 2026.
When we bought our new gateways in 2019 we were on R77.30 and for upgrading to R80.40 we used migrate/export. Could it be, that the certificate is a left over from R77.30 ?
Yea, those internal_ca's usually have 15 years expiry date. I see what you are saying, its definitely a possibility its left there from R77.30...but I would maybe confirm 100% with TAC.
I asked our consulting partner to open a service request. They haven't seen this problem on any of their customers before.
So lets see what TAC have to say.
It's possible it's leftover from R77.x.
Can you show the actual certificate details?
I think that's possible. But I've to ask how to do that from the command line?
[Expert@CP-FW-Mgmt:0]# cpca_client search 61360 -where serial
Operation succeeded. rc=0.
1 certs found.
Subject = CN=CP-FW-Mgmt.company.de,O=CP-FW-Mgmt.company.de.vjyypw
Status = Valid Kind = SIC Serial = 61360 DP = 0
Not_Before: Mon Jan 22 09:36:17 2018 Not_After: Sun Jan 22 09:36:17 2023
Fingerprint = SAY TILE ACT WORN NIT COME AWK SET OTT DUG JAW TAN
Thumbprint = 3a:fd:74:01:ff:02:c2:d4:04:c7:70:c1:08:11:fc:7e:b0:a7:5c:37
That's probably not the right way to do this or is it ?
I don't believe it's possible to retrieve from the CLI.
It should be possible from the (web-based) ICA tool, which needs to be enabled.
See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut... 
You guys are the best @PhoneBoy, @the_rock, @_Val_ ! Enabling ICA mgmt tool put me in the right path.
I followed the sk30501 for settings up access to the ICA but I couldn't access the ICA site although cpca_client set_mgmt_tool print showed that access was enabled and port 18265 was listening.
After some troubleshooting I found the solution for both problems in sk39915 in the notes section. Apparently the private key file was now longer valid or get corrupted as a result of the upgrade process. After running the next commands:
I was able to access the ICA management site. I wanted to find the certificate a bit easier using the serial number and ran cpca_client another time. To my surprise the expiring certificate was replaced by a new one. Success !
I added of few more screenshots if someone else is running into this issue. What I noticed is that the internalca_site.p12 file contains different certificates than I did expect. And apparently there is now a new internal_ca certificate ( expiring in 2038 ) and it is different to the internal_ca certificate shown in smart console.
I did some tests and everything seems to work. Thus I'm hopping there not a new problem now.
Anyway, many thanks again for your help!
Great job! You are welcome, but in all fairness, I think all of us strive to be like @PhoneBoy , but he is CP encyclopedia, legend, guru, expert...so in my mind, if he is out of suggestions, then its NEVER good lol
 
					
				
				
			
		
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count | 
|---|---|
| 22 | |
| 16 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | 
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewWed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY