> Source: [sk180644](https://support.checkpoint.com/results/sk/sk180644)

# sk180644 - Identity Collector fails to connect to Security Gateway - certificate duration longer than 13 months

| Property | Value |
|----------|-------|
| Solution ID | sk180644 |
| Date Created | 2023-03-02 |
| Last Modified | 2024-12-30 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * In the Identity Collector GUI, after users click **Test** to test the connection to the Security Gateway, the test fails with the message: "*Error: Refer to sk113021*".
* On the Windows Server with Identity Collector installed, the `%windir%\Temp\ia_ag.log` log file shows this WinHTTP error (TLS certificate invalid):  
  `"UTILS::WinHttpCCC::asyncCallbackMethod: STATUS_REQUEST_ERROR: error 12175"`
* In SmartConsole \> Security Gateway Object \> navigation tree \> **IPSec VPN** tab \> table below "**Repository of Certificates Available to the Gateway** \> "**defaultCert** \> **View...** the "**Not Valid Before** " date and the "**Not Valid After**" date are more than 13 months apart.

## Cause

On September 1, 2020, the industry issued a new maximum period for 2-year SSL/TLS certificates. The new maximum period for DV, OV, and EV SSL/TLS certificates is 398 days (approximately 13 months).  

The WinHTTP software library, which handles TLS traffic of the Identity Collector, enforces the maximum period for public certificates.  

If the TLS certificate presented by the Security Gateway has "Not valid before" and "Not   
valid after" dates that are more than 13 months apart, Identity Collector considers the certificate invalid. Because Identity Collector considers the certificate invalid, Identity Collector does not connect to the Security Gateway.

## Solution

Check Point updated the Security Management Server / Multi-Domain Server to generate 1-year certificates for the Security Gateways. For more information, including a list of versions / Jumbo Hotfix Takes that include the update, see [sk176527](https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk176527).  

When you renew a "defaultCert" that was created in an earlier version of Security Management Server, the renewed certificate may have a duration that is longer than 13 months. If this is the case, follow this procedure:  

1. On the Multi-Domain Security Management Server, go to the content of the Domain Management Server that manages the Security Gateway / Cluster. Run:   
   `# mdsenv <IP Address of Name of Domain Management Server>`
2. Configure the IKE certificate standard validity period to 1 year. Run:   
   `# cpca_client set_cert_validity -k IKE -y 1`
3. Renew the "**defaultCert** " of the Security Gateway.
   1. In SmartConsole, open the Security Gateway object.,
   2. Make sure the IPsec VPN blade is enabled.
   3. In the navigation tree, click **IPSec VPN**.
   4. In the table below **Repository of Certificates Available to the** **Gateway** , select **defaultCert**.
   5. Click **Renew**.
   6. After the certificate renewal is finished, click **View** to view the certificate
   7. Make sure that the "**Not Valid After**" date of the certificate is one year from today's date.
   8. Save the changes.
   9. (Optional) Disabled the VPN blade
   10. Install the policy to the Security Gateway
4. Connect Identity Collector to the Security Gateway.

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
