> Source: [sk130292](https://support.checkpoint.com/results/sk/sk130292)

# sk130292 - "SIC Error for lea: Client could not choose an authentication method for service lea" in IBM QRadar logs

| Property | Value |
|----------|-------|
| Solution ID | sk130292 |
| Date Created | 2018-06-25 |
| Last Modified | 2019-06-02 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20, R82.20 |
| OS | Gaia |

## Symptoms

- * IBM QRadar logs show following prints:

  `> PM_policy_choose: finished successfully. 1st method = sslca `  
  `> PM_policy_choose: finished successfully. choose: `**DENY**`. `  
  `> policy_choose: choose failed. `  
  `> sic_client-negotiate_auth_method: policy choose failed. `  
  `> opsec_auth_client_connected: connect failed (119) `  
  `> opsec_auth_client_connected: `**SIC Error for lea: Client could not choose an authentication method for service lea**   
  `> opsec_client_client_connected: conn=(nil) opaque=0x84a9b30 err=0 comm=0x84a0700 `  
  `> COM 87a0700 got signal 131075 `  
  `> Destroying comm 84a0700 `  
  `> Destroying session 84a0700 with 1 active sessions `  
  `> Destroying session (a4b2390) id 3 (ent=84a7968) `**reason=SIC_FAILURE**

* After upgrading to R80.X and SIC is reset to OPSEC LEA QRadar Log Server, logging stops working.

* TCP Dump shows QRadar server terminates the port 18184 session.

## Cause

This is typically a SHA-256 computability issue with the LEA Protocol. Check on the QRadar server if the Protocol is the latest version, ie:  

`rpm �qa | grep LEA`   

#QRADAR-PROTOCOL-LEA-7.2-**20170918**143428.i386

As per IBM the binary build release date must be newer than 2016/12/06 in order to support SHA-256.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
