> Source: [sk173715](https://support.checkpoint.com/results/sk/sk173715)

# sk173715 - When Mobile Access is not enabled, a warning appears with the fingerprint of the ICA certificate, not the fingerprint of the Mobile Access certificate

| Property | Value |
|----------|-------|
| Solution ID | sk173715 |
| Date Created | 2021-05-26 |
| Last Modified | 2021-05-27 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Gaia |

## Symptoms

- When the Mobile Access blade is not enabled, a warning comes into view with the fingerprint of the ICA certificate, not the fingerprint of the Mobile Access certificate. The fingerprint warning occurs only when the user creates a site with the VPN Gateway or adds a new certificate to the IPsec repository or Mobile Access repository.

## Solution

This is an expected behavior.   

When a Remote Access VPN Client connects to a VPN Gateway, the VPN Gateway sends its fingerprint (randomly generated during the Gateway installation). The Remote Access VPN Client shows a popup warning with this fingerprint, and the user gives approval or rejects this initial connection.   

Before the IPSec negotiation between the Remote Access VPN Client and the VPN Gateway, there is an SSL handshake between them for the negotiation to be transferred over an encrypted link.  

When the Mobile Access blade has a different certificate than the IPSec blade, the fingerprint of the Mobile Access certificate appears during site creation. If the Mobile Access blade is not enabled and the user did not implement a certificate on the platform portal, the Gateway presents the fingerprint of the ICA certificate.   

To identify and align the fingerprint with the one you see on the user machine:  

1. Navigate to the trusted CA and open the **internal_ca** object
2. Below the **Local Security Management Server** click on **view** . The fingerprint is at the bottom, below **SHA-1 Fingerprints**.

**Related Solutions** :  

* [sk158334 - Mobile Access certificate fingerprint presented on Remote Access client](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk158334)
* [sk66263 - Avoiding VPN / SNX client fingerprint message when changing certificate or connecting to a backup site](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk66263)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
