> Source: [sk158334](https://support.checkpoint.com/results/sk/sk158334)

# sk158334 - Mobile Access certificate fingerprint presented on Remote Access client.

| Property | Value |
|----------|-------|
| Solution ID | sk158334 |
| Date Created | 2019-07-15 |
| Last Modified | 2021-09-05 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- * When Mobile Access blade has different certificate then the IPSec blade, during site creation, the fingerprint of the Mobile Access certificate is presented.
* After making a change in the Mobile Access certificate, a message to trust the new fingerprint is presented for Remote Access users.

## Cause

Before the IPSec negotiation between the client and the gateway, there is an SSL handshake between them in order for the negotiation to be transferred over an encrypted link.

The gateway does not "know" that the SSL handshake is only an infrastructure for the IPSec negotiation, and it is treating it as Mobile Access. This is why it is presenting the Mobile Access certificate.

## Solution

No fix is required; the system is functioning as designed.

The IPSec certificate will be used during the IKE negotiation, as expected.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
