> Source: [sk167293](https://support.checkpoint.com/results/sk/sk167293)

# sk167293 - Policy installation fails with "Policy installation had failed due to an internal error. If the problem persists please contact Check Point support" 

| Property | Value |
|----------|-------|
| Solution ID | sk167293 |
| Date Created | 2020-06-22 |
| Last Modified | 2023-06-19 |
| Technical Level | General |
| Products | Multi-Domain Security Management Server |
| Versions | R82.10, R81.20, R82, R82.20 |

## Symptoms

- * "`Policy installation had failed due to an internal error. If the problem persists please contact Check Point support`" error message on policy installation failure.  

* The `cpm.elg` file shows:   

  ` 
  INFO coresvc.internal.ObjectDumper [unboundedTaskExecutor-20]:`**found 4 internal ca's and 5 internal ca cert's**   
  `
  ERROR utils.runtime.CpAssert$DefaultAssertionErrorHandler [unboundedTaskExecutor-20]: AssertionError has been caught: Internal ca cert doesn't exist`  
  `
  ERROR infrastructure.logging.CpAssertionErrorExceptionLoggerHandler [unboundedTaskExecutor-20]: incident [75e774c9-7aef-4d1d-84e1-03694f864ca3]:`  
  `
  Internal ca cert doesn't exist`  

* Issue can happen on one Domain or all of them.

## Cause

During Policy Installation, we poll all Internal CA's and Internal CA certificates concerning the target domain. In this case, we wrongfully had additional CA certificate which had nothing to do with the VPN community configured on the Domain.

<br />

## Solution

This problem was fixed. The fix is included in:

* [Check Point R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166715)

Check Point recommends to always upgrade to the most recent version   
([upgrade Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=435) / [upgrade Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=184) / [upgrade Multi-Domain Security Management](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=166)).

<br />

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
