> Source: [sk106405](https://support.checkpoint.com/results/sk/sk106405)

# sk106405 - "Bad Response format" error in SmartDashboard when enrolling a VPN certificate from Windows based CA using SCEP

| Property | Value |
|----------|-------|
| Solution ID | sk106405 |
| Date Created | 2015-06-09 |
| Last Modified | 2020-11-12 |
| Technical Level | Advanced |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82.20, R81.20, R82, R82.20 |

## Symptoms

- * "`Bad Response format`" error in SmartDashboard (after clicking on the "Complete" button) when enrolling a VPN certificate using SCEP from the external CA based on Windows Server 2008 and above.

* The *$FWDIR/log/fwm.elg* file on Check Point Management Server shows the following message:  

  "`cpScep_processCertReply: Got bad authenticate attributes. The message digest doesn't match`"

## Cause

The Security Management Server does not take into consideration the hash algorithm used by the external CA and always signs its response using MD5.

If the external CA also uses MD5, then everything would work well. However, when this is not the case, enrollment will fail.

On Windows Server 2008 and above, SHA-1 is the default hash algorithm.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
