> Source: [sk162213](https://support.checkpoint.com/results/sk/sk162213)

# sk162213 - Policy Installation fails with with " Installation failed. Reason: Authentication error [ SIC error no. 147 ]" 

| Property | Value |
|----------|-------|
| Solution ID | sk162213 |
| Date Created | 2019-09-06 |
| Last Modified | 2024-03-05 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Policy installation fails with errors:   

  `SIC Status for Host: Not Communicating`  
  `

  Authentication error [error no. 147]`  

  `

  ** Check that peer SIC is configured properly`  
  `
  and that system date and time on the Security Management Server and peer are synchronized **`  

* Debug FWM process on the Management side per [sk86186](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk86186), shows:  

  `
  SIC Error for CpdPing: Authentication error`  
  `
  opsec_auth_client_connected: connect failed (147)`  
  `
  [FWM PID]@Management[DATE TIME] opsec_auth_client_connected: SIC Error for CpdPing: Authentication error`  

* Debug of CPD process on the gateway per [sk86320](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk86320) shows:   

  `
  [CPD PID]@Gateway[DATE TIME] fwValidationStat::~fwValidationStat: called.`  
  `
  [CPD PID]@Gateway[DATE TIME] fwCert_ValCerts: Certificate is revoked. CN=cp_mgmt,O=`.abc.def.**hxn9p4**   
  [CPD PID]@Gateway[DATE TIME] validate_callback: rc = -991   
  [CPD PID]@Gateway[DATE TIME] SIC Error for CpdPing: Certificate revoked.  

  Note: Copy the end of the certificate '' for later.

## Cause

The Security Management server uses a revoked certificate to establish SIC. Resetting SIC creates a new certificate that is not used on subsequent SIC attempts. This may because the name of the management server has changed or was recently upgraded from R77 or older to R80+, which is stricter with CN= name convention. Corruption may also apply.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
