> Source: [sk116095](https://support.checkpoint.com/results/sk/sk116095)

# sk116095 - "failed to establish trust" error message when trying to enroll the certificate from Capsule Workspace

| Property | Value |
|----------|-------|
| Solution ID | sk116095 |
| Date Created | 2017-02-26 |
| Last Modified | 2019-03-25 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * "failed to establish trust" error message when trying to enroll the certificate from Capsule Workspace.
* The Security Gateway fails to match the CN because CN is corrupted:  
  \[ 32324\]\[30 Dec 13:18:13\]\[CertEnroll\] \[CVPN_INFO\] Cvpn::CertEnrollManager::getDSGatewayCert: getDSGatewayCert returned: (-2)  
  \[ 32324\]\[30 Dec 13:18:13\]\[CertEnroll\] \[CVPN_WARNING\] establishTrustWithICADone: Establish trust with ICA failed, reason: Establish trust with ICA failed. reason: There's no trusted server certificate by the given DN:

## Cause

The issue is caused by double quotes in the CN.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
