> Source: [sk164056](https://support.checkpoint.com/results/sk/sk164056)

# sk164056 - "An internal error has occurred" when trying to replace an Internal CA certificate using a third-party CA certificate in Spark Firewall appliance

| Property | Value |
|----------|-------|
| Solution ID | sk164056 |
| Date Created | 2019-12-15 |
| Last Modified | 2026-05-03 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |

## Symptoms

- When the user tries to replace the Internal CA certificate with a third-party CA certificate, the certificate upload completes successfully.

However, after the user enters the certificate password and applies it, this error appears:

`
An internal error has occurred.`  
`
If the problem persists please contact Check Point Technical Assistance Center`  
`
Web server error.`

## Cause

The imported certificate is not a CA certificate, but an "**End Entity**" certificate.

You can find this information in the "**Basic Constraints**" parameters of the certificate.

Example:

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1576428864056/EndEntity1912150858.PNG)

## Solution

Make sure the imported certificate is a CA certificate.

The **Subject Type** of the certificate must be **CA**.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
