> Source: [sk162516](https://support.checkpoint.com/results/sk/sk162516)

# sk162516 - Capsule clients fail to connect with "Error: SSL Error Invalid Certificate (Purpose)"

| Property | Value |
|----------|-------|
| Solution ID | sk162516 |
| Date Created | 2019-09-24 |
| Last Modified | 2019-09-25 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- Capsule clients (Windows, iOS, or Android) fail to connect with the error "Error: SSL Error Invalid Certificate (Purpose)".

## Cause

Gateway certificate contains a key extension which is not valid.

As per <https://tools.ietf.org/html/rfc5280#section-4.2.1.12> Key Usage and Extended Key Usage are to be processed separately, but result of both must agree. (e.g. if EKU is present and we are using HTTPS we should have Server Authentication listed under EKU, while only an IPSEC attribute was listed)  
This would cause the SSL clients to reject the certificate when the necessary attribute was not present there.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
