> Source: [sk172183](https://support.checkpoint.com/results/sk/sk172183)

# sk172183 - sicRenew utility fails when secondary Domain Management Server is in active state 

| Property | Value |
|----------|-------|
| Solution ID | sk172183 |
| Date Created | 2021-02-23 |
| Last Modified | 2022-12-22 |
| Technical Level | General |
| Products | Multi-Domain Security Management Server |
| Versions | R81 (EOS) |
| OS | Gaia |

## Symptoms

- * sicRenew utility fails when the secondary Domain Management Server is in active state.

* This error message appears in 'sicRenew -d' command output:  
  `
  RenewSICCert_cb: CA Internal error. `  
  `
  Certificate cannot be renewed by the Internal CA. (Error no. -179).`

## Cause

By default, renewal is done against the primary Security Management Server, because the secondary Domain Server CA did not create the certificate. The IP address of the CA on the primary Management Server should be accessed for SIC certificate renewal.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170114) starting from Take 34

The Hotfix allows running the sicRenew utility, and manually specifying the CA's IP address to avoid this problem.  
After installing the hotfix run:   
# sicRenew -i \<mgmt-ip\>   

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
