> Source: [sk171296](https://support.checkpoint.com/results/sk/sk171296)

# sk171296 - Synchronization between CMAs fails with "Failed to Obtain Internal CA data" error

| Property | Value |
|----------|-------|
| Solution ID | sk171296 |
| Date Created | 2021-01-18 |
| Last Modified | 2026-06-24 |
| Technical Level | Advanced |
| Products | Multi-Domain Security Management Server |
| Versions | R81 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |

## Symptoms

- * Database sync from primary to second CMA fails with "Failed to Obtain Internal CA data" error.  

* When clicking on the standby or any Gateway in the noted Domain, this error is presented:   
  `There is a severe Certificate Authority error, the trust model is corrupted.`  
  `To recover the CA, proceed as follows:`  
  1. `On the Security Management Server, reset the Security Gateways.`
  2. `Run the command line: "fwm sic_reset" to clean the registry and delete database files.`
  3. `Using cpconfig, recreate the Certificate Authority.`
  4. `Re-build Check Points's Security Gateways trust and IKE certificates.`

  <br />

  <br />

* Extremely high CPU on the CPCA process of affected CMA.  

* CPCA process flaps to N/A state  

* `CPCA debug >>" CPPRODIS_init_error_logging_ex: set logfile /opt/CPmds-R80.20/customers/<CMA>/CPsuite-R80.20/fw1/log/cpca.elg (size=20971520 #files=10) for application 'cpca' product 'FW1'.`  
  `CPPRODIS_init_error_logging_ex: initialized error logging for product 'FW1' application 'cpca'."`

## Cause

High amount of expired or revoked certificates.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
