> Source: [sk120452](https://support.checkpoint.com/results/sk/sk120452)

# sk120452 - Mobile Access Portal Agent fails to install the certificate

| Property | Value |
|----------|-------|
| Solution ID | sk120452 |
| Date Created | 2017-09-19 |
| Last Modified | 2022-12-28 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Linux |

## Symptoms

- During Mobile Access Portal Agent installation, this error message appears in the terminal window:  

```

Installing Check Point Mobile Agent... certutil: function failed: SEC_ERROR_LEGACY_DATABASE: The certificate/key database is in an old, unsupported format.

certutil: function failed: SEC_ERROR_LEGACY_DATABASE: The certificate/key database is in an old, unsupported format.
```

- or -

```

Installing Check Point Mobile Agent... certutil: could not find certificate named "CShell_Certificate": SEC_ERROR_BAD_DATABASE: security library: bad database.

Cannot remove certificate from Firefox profile
```

## Cause

The Firefox certificate database's format is old, and the Mobile Access Portal Agent no longer supports it.

## Solution

This problem was fixed. The fix is included in:

* **[Check Point R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122485)**

Check Point recommends to always [upgrade to the most recent version](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=72).

If you do not wish to upgrade:

1. Close Firefox (if it is open).  

2. Update Firefox to the latest version.  

3. Update [certutil](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil) to the latest version.  

4. Launch Firefox.  

5. Delete/untrust all certificates named **Check Point Mobile** in the Firefox's Certificate Manager below the **Authorities** tab: **Tools \> Options \> Advanced \> Certificates: View Certificates**
6. Install the Mobile Access Portal Agent again.

**Note:** Refer to [sk119772](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk119772) for the names of the packages corresponding to your Linux distribution.

**Related Solution:**

* [sk113410 - Mobile Access Portal and Java Compatibility - New Mobile Access Portal Agent technology](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113410)
* [sk119772 - Mobile Access Portal Agent Prerequisites for Linux](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk119772)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
