> Source: [sk173173](https://support.checkpoint.com/results/sk/sk173173)

# sk173173 - Machine Certificate Authentication fails because the client is not offered the correct Root CA

| Property | Value |
|----------|-------|
| Solution ID | sk173173 |
| Date Created | 2021-05-20 |
| Last Modified | 2021-05-24 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81 (EOS) |

## Symptoms

- * Machine Certificate Authentication fails because the client is not offered the correct Root CA.
* Both Windows and Mac users affected.
* The correct Certificate Root CA is still valid (not expired) and can be seen in SmartConsole.
* The client does have the correct certificate in the client's local repository.
* If Certificate Authentication is set to "When available", the User does not login with Certificate Authentication, and uses another login method instead.
* If Certificate Authentication is set to "Always use", then the User login fails.
* From the `C:\Program Files (x86)\CheckPoint\Endpoint Security\Endpoint Connect\trac.log` from the client: You can see the following Root CAs being offered. They do not include the correct ROOT CA needed for the Machine Certificate Authentication.  
  Below is an example of 6 Root CAs that are available in SmartConsole. The 7th Root CA needed for Machine Certificate Authentication is missing and is not offered to the client.  

  \[ 6068 6792\]\[13 Apr 9:34:56\]\[RaisCertManager\] RaisCertManager::CertManager::GetCertByName: **Searching the certificate in the machine's store.**   
  \[ 6068 6792\]\[13 Apr 9:34:56\]\[RaisCertManager\] RaisCertManager::CertManager::GetCertByName: CertManager::GetCertByName: Pushing DN = *Certficate CA #1*   

  \[ 6068 6792\]\[13 Apr 9:34:56\]\[RaisCertManager\] RaisCertManager::CertManager::GetCertByName: CertManager::GetCertByName: Pushing DN = *Certificate CA #2*   

  \[ 6068 6792\]\[13 Apr 9:34:56\]\[RaisCertManager\] RaisCertManager::CertManager::GetCertByName: CertManager::GetCertByName: Pushing DN = Certificate CA #3  

  \[ 6068 6792\]\[13 Apr 9:34:56\]\[RaisCertManager\] RaisCertManager::CertManager::GetCertByName: CertManager::GetCertByName: Pushing DN = *Certificate CA #4*   

  \[ 6068 6792\]\[13 Apr 9:34:56\]\[RaisCertManager\] RaisCertManager::CertManager::GetCertByName: CertManager::GetCertByName: Pushing DN = *Certifcate CA #5*   

  \[ 6068 6792\]\[13 Apr 9:34:56\]\[RaisCertManager\] RaisCertManager::CertManager::GetCertByName: CertManager::GetCertByName: Pushing DN = *Certificate CA #6*

## Cause

Possible Data corruption.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
