> Source: [sk173814](https://support.checkpoint.com/results/sk/sk173814)

# sk173814 - "cloud_proxy.elg" certificate error causes failure to update tags from data center

| Property | Value |
|----------|-------|
| Solution ID | sk173814 |
| Date Created | 2021-06-02 |
| Last Modified | 2022-10-11 |
| Technical Level | Advanced |
| Products | Cloud Firewall |
| Versions | R81 (EOS), R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * The cloud vendor is Cisco
* The Management Server fails to update the IP list of the tags.
* Checking connectivity to the Data Center results in an error about the certificate and prompts you to trust the new certificate.
* "cloud_proxy.elg" shows this error: ERROR util.certificate.SSLSocketConnection \[scanner-780347807\]: Socket IOException Exception for host X.X.X.X:443 ERROR util.certificate.CertificatesHelper \[scanner-780347807\]: Error while getting certificate from X.X.X.X 28/05/21 01:25:07,559 ERROR scanner.util.DcScannerUtils \[scanner-780347807\]: Exception while connecting to APIC \[Server https://X.X.X.X, user name XXXX\]. Return connectivity problem. java.net.ConnectException: Connection refused (Connection refused) at java.net.Socket.connect(Socket.java:682) at com.ibm.jsse2.av.connect(av.java:694) at com.checkpoint.datacenter.util.certificate.SSLSocketConnection.getSslSocketConnection(SSLSocketConnection.java:25) at com.checkpoint.datacenter.util.certificate.SslCertificateRetriever.getCertificate(SslCertificateRetriever.java:7) at com.checkpoint.datacenter.util.certificate.CertificatesHelper.getActualCertificate(CertificatesHelper.java:93) at com.checkpoint.datacenter.scanner.PrivateCloudScanner.getCertificate(PrivateCloudScanner.java:36) at com.checkpoint.datacenter.scanner.PrivateCloudScanner.isAnyDomainTrusted(PrivateCloudScanner.java:23) at com.checkpoint.datacenter.scanner.DcScanner.run(DcScanner.java:32) at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:522) at java.util.concurrent.FutureTask.run(FutureTask.java:277) at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1160) at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:635) at java.lang.Thread.run(Thread.java:820)
* "cloud_proxy.elg" shows with these errors: ERROR datacenter.scanner.PrivateCloudScanner \[scanner-780347807\]: Failed to get certificate with scanner:\[APIC \[Server https://X.X.X.X, user name XXXX\]\] ERROR datacenter.scanner.DcScanner \[scanner-780347807\]: Certificate is not trusted or could not get certificate for scanner 780347807. ERROR datacenter.scanner.DcScanner \[scanner-780347807\]: Data Center server scanning failed on Connectivity problem. APIC \[Server https://X.X.X.X, user name XXXX\] ERROR datacenter.enforcement.DomainEnforcementUpdater \[enforcer_CloudIA-mgmt01a-tcn\]: Failed to get updated objects from data center EnforcementDataCenter{cmsType='APIC', domainId='d4451474-6300-4bbc-b6ae-aaed2bf3c146', serverId='2a5d5328-e42e-4e52-8a4a-d92ba478395c'} due to a certificate problem, objects which were imported from this data center won't be updated com.checkpoint.datacenter.util.exception.CMSOperationException: Cannot retrieve scanner id. Probably certificate problem.

## Cause

The Cisco APIC has renewed the certificate or made a change that causes the Management Server to no longer trust the current certificate.   
**Note -** This is not a Check Point issue.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
