> Source: [sk180117](https://support.checkpoint.com/results/sk/sk180117)

# sk180117 - Old and new SMP root CA certificates are on the trusted CA, causing VPN failure

| Property | Value |
|----------|-------|
| Solution ID | sk180117 |
| Date Created | 2022-10-12 |
| Last Modified | 2022-10-18 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |

## Symptoms

- * On 6 October 2022, the SMP certificate was replaced on eu-1.spark-management.checkpoint.com. When Security Gateways managed by the SMP fetch the new certificate, they fail to apply the change, resulting in VPN failure.

  **Note:** The Domain is managed in eu-1.spark-management.checkpoint.com
* The VPN does not come up because of an invalid certificate/authentication error.

* The old SMP root CA certificate (expires in 2027) and the new SMP root CA certificate (expires in 2032) are on the trusted CA on the Security Gateway.

* System log warning shows:

  `'SMP system' updated cloud certificates. Attempt failed`   
  Click on the screenshot to enlarge it.   
  ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk180117/Untitled202210121409121.png)

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
