> Source: [sk115552](https://support.checkpoint.com/results/sk/sk115552)

# sk115552 - SMB appliances are unable to fetch SMP Root CA and External CAs once connected to the SMP

| Property | Value |
|----------|-------|
| Solution ID | sk115552 |
| Date Created | 2017-01-17 |
| Last Modified | 2022-06-01 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |

## Symptoms

- * SMB appliances connected to the SMP fail to fetch the SMP's 'Cloud Services provider' CA , and any external CAs configured on the SMP.
* When checking the VPN certificates of the appliance under VPN -\> Trusted CAs , we only find the appliance's internal certificate \[ 1 in red\] , but can't find the 'Cloud Services provider' CA or any other external CAs \[2 in blue\]: ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk115552/SMPCert1701182353.png)

* When connecting the appliance to the SMP, the following logs are seen in the `/var/log/messages` file:  
  `user.warn root: [SMP] Command 'smpCa.save' has failed: 'trustedCa.2: Certificate already installed', 'trustedCa.3: Certificate already installed', 'trustedCa.1: Certificate already installed', 'smpCa.certificate: CA certificate for this certificate not found'`  
  `
  user.warn root: [SMP] Failed to save topic 'certificates'`
* The absence of these certificates causes VPN tunnel establishment failures for VPN communities using the SMP, or direct S2S VPN tunnels that are certificate based.

## Solution

[Contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) to get a Hotfix for this issue.   
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.   
For faster resolution and verification please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and Security Gateways involved in the case.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
