> Source: [sk114432](https://support.checkpoint.com/results/sk/sk114432)

# sk114432 - Policy installation fails with "Internal SSL authentication SSL error [ Unknown ]" error

| Property | Value |
|----------|-------|
| Solution ID | sk114432 |
| Date Created | 2016-11-09 |
| Last Modified | 2023-05-19 |
| Technical Level | Advanced |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R81.20, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20 |
| OS | Gaia |

## Symptoms

- * "*Internal SSL authentication SSL error \[ Unknown \]* " SIC error on Policy installation failure for specific gateways.  

* `$CPDIR/log/cpd.elg` file on the Security Management Server / Domain Management Server shows:

  <br />

  * `fwCA::RevokeCert: Certificate DN "CN=NAME,O=OTHERNAME" with status 'Certificate is in pending-revoke status': rc = Entity referred does not exist in the Certificate Authority.`
  * `fwCA::RevokeCertsForCN: revoked certificates which were in PENDING status (DN "CN=NAME,O=OTHERNAME")`

  <br />

  <br />

* When resetting SIC it fails with: "*Failed to retrieve the operating system version. (Untrusted Host) Please make sure Check Point Services are running on Gateway, and trust has been established.* "  

* When testing SIC communication it fails with: "*Internal SSL authentication \[ Certificate chain is inconsistent.\]*"

## Cause

All the above symptoms are caused by another Security Gateway that is located between the Security Management Server and the Security Gateway on which the policy installation fails due to SSL authentication error:

\[Security Gateway on which policy installation fails\] --- \[Another Security Gateway that performs SSL inspection\] --- \[Security Management Server\]

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
