> Source: [sk167255](https://support.checkpoint.com/results/sk/sk167255)

# sk167255 - Capsule VPN / Capsule Connect (Android / iOS) fail to connect, "The site's certificate has expired!" error

| Property | Value |
|----------|-------|
| Solution ID | sk167255 |
| Date Created | 2020-06-05 |
| Last Modified | 2020-06-08 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Android, iOS |

## Symptoms

- * Capsule VPN / Connect (Android / iOS) / Capsule Workspace fail to connect, "`The site's certificate has expired!`" error.   
  **Note** : Sectigo AddTrust certificate is the 3rd party who signed the certificate used for IPSec or any of the MultiPortal blades ([sk87920](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk87920)).   
  **Note**: The issue started after May 30, 2020.
* vpnd.elg debug ([sk89940](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk89940)) shows:

  ```
  
  Serial Number: 13ea28705bf4eced0c36630980614336
  
  Issuer: CN=AddTrust External CA Root,OU=AddTrust External TTP Network,O=AddTrust AB,C=SE
  
  Subject: CN=USERTrust RSA Certification Authority,O=The USERTRUST Network,L=Jersey City,ST=New Jersey,C=US
  
  Not valid before: Tue May 30 12:48:38 2000 Local Time
  
  Not valid after:  Sat May 30 12:48:38 2020 Local Time
  
  few lines below the following line will appear:
  
  [CPTLS] cptls_hs_print_alert: alert level: CPTLS_fatal, description: CPTLS_certificate_expired(45).
  ```

* Android client log file *logfile1.txt* shows the following error:

  ```
  
  D NEMO.service says: VERIFY Failure: error_msg: 'SSL error - a certificate has expired. Check your system clock', error_code: '-1' 
  ```

* iOS client log file shows the following error:

  ```
  
  Error received:319 Description:SSL error - a certificate has expired. Check your system clock
  ```

  <br />

## Cause

Sectigo AddTrust External CA Root [expired](https://support.sectigo.com/articles/Knowledge/Sectigo-AddTrust-External-CA-Root-Expiring-May-30-2020) on May 30, 2020.   

Capsule VPN \\ Capsule Connect clients do not support a broken or incomplete certificate chain. For this reason, it has always been required that the Gateway be configured properly with the full chain of the SSL certificate.  

In this case, the old chain is deprecated (the AddTrust root CA cert in the chain has expired). A new chain needs to be configured on the Gateway and then served to the client when connecting.

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
