> Source: [sk166236](https://support.checkpoint.com/results/sk/sk166236)

# sk166236 -  "Update failed. Could not connect to "secureupdates.checkpoint.com". SSL peer certificate failed." error in security log when update fails

| Property | Value |
|----------|-------|
| Solution ID | sk166236 |
| Date Created | 2020-04-10 |
| Last Modified | 2020-04-19 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |
| Platform | 910 |

## Symptoms

- * Security log shows the following error:

  ```
   
  Update failed. Could not connect to "secureupdates.checkpoint.com".
  SSL peer certificates failed.
  ```

* When FDT and CUI logging are enabled, sfwd log shows:

  ```
  
  [6 Mar 14:20:55] CFwdCommStreamLocal::Write sent 156 bytes
  ciu_log_send: log sent: product=IPS exp= reason=Update failed.  Could not connect to "secureupdates.checkpoint.com". SSL peer certificate failed.
  
  ciu_app_update_now_cb: status=E_CIU_UPDATE_STAT_FAIL err=Update failed.  Could not connect to "secureupdates.checkpoint.com". SSL peer certificate failed.
  ```

  <br />

## Cause

secureupdates.checkpoint.com is resolving an incorrect IP.   

To confirm this, run '*nslookup secureupdates.checkpoint.com* ' from expert and compare the output to what you see when you run '*nslookup secureupdates.checkpoint.com 8.8.8.8* '.

<br />

## Solution

1. From expert, run:   

'*curl_cli -v https://secureupdates.checkpoint.com/appi/v3_1_0/gw/Version --cacert /pfrm2.0/opt/fw1/bin/ca-bundle.crt* '.   

2. Make sure the certificate matches:  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1586441979882/certificatematch20200409103639.png)

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
