> Source: [sk170112](https://support.checkpoint.com/results/sk/sk170112)

# sk170112 - Identity Collector fails to connect to a Security Gateway due to MultiPortal certificate

| Property | Value |
|----------|-------|
| Solution ID | sk170112 |
| Date Created | 2020-10-26 |
| Last Modified | 2025-12-13 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * "Identity collector cannot connect to Security Gateway - refer to sk113021" is shown when using the "Test" button.

* Kernel Debug as per [sk105723](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105723) does not show the same symptoms.

* Identity Collector service debugs ([sk122686](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122686)) in ia_ag.log shows the following error:  
  `
  [WinHttpCCC (NAC::IS::TD::Surprise)] UTILS::WinHttpCCC::asyncCallbackMethod: 
  STATUS_REQUEST_ERROR: error 12175 (async API 5) on request (id 1 - 69728f8)`

* A traffic capture shows that the Server Certificate that the Security Gateway presents to the Identity Collector is already expired based on its validity range and the IDC closes the connection shortly after.

## Cause

Bad / Expired certificate on the Security Gateway on one of the MultiPortal services.

To help pin-point the certificate, it can be identified based on a packet capture when the Security Gateway presents its certificate to the Identity Collector.

In the following example the certificate is expired (captured on Oct. 17 2020) and was found to be on the Captive Portal:

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1602985766359/unknown202010172220401.png)

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
