> Source: [sk164732](https://support.checkpoint.com/results/sk/sk164732)

# sk164732 - Secondary MDS and MLM are unable to renew certificate

| Property | Value |
|----------|-------|
| Solution ID | sk164732 |
| Date Created | 2020-01-17 |
| Last Modified | 2021-03-24 |
| Technical Level | General |
| Products | Multi-Domain Security Management Server |
| Versions | R82.10, R81.20, R82 |
| OS | Gaia |

## Symptoms

- * Secondary MDS or MLM can't renew management certificate.  
  If MDS/MLM failed to renew a management certificate until end of graceful renewal period, the clients trying to connect to MDS/MLM in question would get error: "Certificate is revoked".
* cpd.elg shows:  
  \[CPD 11247 4145886928\]@Mds-Secondary\[14 Jan 20:54:09\] sicRenew: SIC Renewal: Cannot renew SIC certificate. Failed to initialize renewal protocol with the ICA.  
  \[CPD 11247 4145886928\]@Mds-Secondary\[14 Jan 20:54:09\] sicRenew: Try to restart all Check Point processes.  
  \[CPD 11247 4145886928\]@Mds-Secondary\[14 Jan 20:54:09\] Renew_SIC_Cert_cb: CPD failed to renew sic certificate. status = 3, rc - -1.  
  \[CPD 11247 4145886928\]@Mds-Secondary\[14 Jan 20:54:09\] Renew_SIC_Cert_cb: Will try again in 1 hour.  
* 'sicRenew -d' shows:  
  \[16 Jan 22:39:07\] Get_mngmt_IP: Running on a standby management will look for active one.  
  \[16 Jan 22:39:07\] CreateStrList: Invalid list size, 0.  
  \[16 Jan 22:39:07\] RenewSICCert: Failed getting management IP list.  
  \[16 Jan 22:39:07\] SIC Renewal: Cannot renew SIC certificate. Failed to initialize renewal protocol with the ICA.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) starting from Take 38
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) starting from Take 195
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) starting from Take 160
* [Jumbo Hotfix Accumulator for R80.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116380) starting from Take 278

<br />

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

<br />

In some cases, after applying the fix, SIC may still fail.  
The cpd.elg file will show:  
`error message: The old certificate has already expired. `  
`Certificate cannot be renewed by the Internal CA.`  
`Contact your system administrator to initiate a new certificate. (Error no. -173).`  

To fix this:  
Reset the SIC of the MLM.  
A. reset SIC via MLM without impacting the logging :  
\[Expert@HostName\]# cp_conf sic init \<New_Activation_Key\> norestart  
\[Expert@HostName\]# cpwd_admin stop -name CPD -path "$CPDIR/bin/cpd_admin" -command "cpd_admin stop"  
\[Expert@HostName\]# cpwd_admin start -name CPD -path "$CPDIR/bin/cpd" -command "cpd"  
B. Reset and establish SIC via Primary MDS Smartconsole.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
