> Source: [sk109618](https://support.checkpoint.com/results/sk/sk109618)

# sk109618 - Cannot establish SIC with the 3rd party vendor after creating a new OPSEC Application

| Property | Value |
|----------|-------|
| Solution ID | sk109618 |
| Date Created | 2016-01-13 |
| Last Modified | 2024-12-15 |
| Technical Level | Advanced |
| Products | Other |
| Versions | Not Version-Specific |
| OS | Gaia |

## Symptoms

- * Cannot establish SIC with the 3rd party vendor after creating a new OPSEC Application.
* OPSEC 3rd party vendor reports it is unable to pull the certificate from the Security Management server.
* The OPSEC Third Party Vendor errors may have similar errors too:  

  `"SIC infrastructure was unable to establish the connection to OPSEC Server [SIC_FAILURE]. SIC Error for lea: Could not retrieve CRL.."`   

* alternative error messages   

  `"failed to fetch certificate from server"

  `  

* Splunk Enterprise system access to R80 Manager error messages   

  `External Handler failed with code "1" and output 'REST ERROR[400]: Bad request - failed to fetch the certificate from the server. See splunkd.log for stderr output 

  `

## Cause

Depending on the OPSEC SDK integration it might not support SHA-256 certificates or newer, as documented in [sk103840 - SHA-1 and SHA-256 certificates in Check Point Internal CA (ICA)](https://support.checkpoint.com/results/sk/sk103840) or connections with TLS1.1 or newer.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
