> Source: [sk110747](https://support.checkpoint.com/results/sk/sk110747)

# sk110747 - Remote Access users unable to connect when authenticating using certificate issued by subordinate CA

| Property | Value |
|----------|-------|
| Solution ID | sk110747 |
| Date Created | 2016-03-28 |
| Last Modified | 2022-05-01 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |

## Symptoms

- * VPN client attempts to connect to Remote Access community but fails.
* The issue only happens when using a certificate issued by a subordinate Certificate Authority. When issuing a certificate from a trusted (Root) Certificate Authority and using it to connect, the user is able to connect to the community.
* In VPND:  
  \[vpnd 14650 1978533568\]@IPSec-VC-CP\[25 Nov 19:37:27\] IsChainTrusted: reached the chain's top level: 0  
  \[vpnd 14650 1978533568\]@IPSec-VC-CP\[25 Nov 19:37:27\] IsSignedByIntermediateCA: IntermediateCA Retrieval is no activated.  
  \[CERT\] IsChainTrusted: reached the chain's top level: 0  
  \[CERT\] IsSignedByIntermediateCA: IntermediateCA Retrieval is no activated.  
  \[CERT\] Get_Issuers_of_chain: IntermediateCA Retrieval is no activated.  
  \[CERT\] IsChainTrusted: Trust Not Found.

## Cause

Problem with validating trust for certificates issued by subordinate CA.

## Solution

This problem was fixed. The fix is included in:  

* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 55
* [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 68
* [Jumbo Hotfix Accumulator for R80.30](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.30/Default.htm) starting from Take 251

For other [supported versions](https://www.checkpoint.com/support-services/support-life-cycle-policy/), [contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) to get a Hotfix for this issue.   
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.   
For faster resolution and verification please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and Security Gateways involved in the case.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
