> Source: [sk107994](https://support.checkpoint.com/results/sk/sk107994)

# sk107994 - opsec_pull_cert.exe fails with "Opsec error. rc=-1 err=-93 The referred entity does not exist in the Certificate Authority"

| Property | Value |
|----------|-------|
| Solution ID | sk107994 |
| Date Created | 2016-01-18 |
| Last Modified | 2017-09-10 |
| Technical Level | Advanced |

## Symptoms

- When running `opsec_pull_cert.exe` to set up a 3rd party OPSEC LEA Log server, users get the "`Opsec error. rc=-1 err=-93 The referred entity does not exist in the Certificate Authority`" error.

## Cause

This can happen when the -n parameter:

1. Referring to an object that has not been defined in the Policy Editor.
2. Referring to an object that has already had the certificate pulled over. That is it shows trust state as 'Initialized' in SmartDashboard
3. Referring to an object that has not yet had a SIC certificate created for it. That is the 'communication' button has not been pressed and a SIC certificate has not been created for it.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
