> Source: [sk181105](https://support.checkpoint.com/results/sk/sk181105)

# sk181105 - "Got alert from peer that the certificate expired" after ICA certificate renewal

| Property | Value |
|----------|-------|
| Solution ID | sk181105 |
| Date Created | 2023-06-14 |
| Last Modified | 2023-06-22 |
| Technical Level | Advanced |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R81.20, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20 |
| OS | Gaia |
| Platform | VMWare ESX |

## Symptoms

- * `$CPDIR/log/cpd.elg` file on the Security Management Server / Domain Management Server contains these messages after ICA certificate renewal:   


  `SIC Error for amon: Got alert from peer that the certificate expired`  
  `
  ckpSSL_AsyncNegotiateHandler: neg_error is: (-3)`  
  `
  ckpSSL_GetErrorString: err_code is: (-3)`  
  `
  ckpSSL_GetErrorString: err is: (1045)`  
  `
  ckpSSL_fwasync_connected: err_msg: (Got alert from peer that the certificate expired)`

* Policy installation fails with: *Installation failed. Reason: Internal SSL authentication SSL error \[unknown\]*

* Reinitializing SIC between the Security Management Server / Primary Domain Management Server and Secondary Domain Management Server / managed Security Gateways does not resolve the issue.

## Cause

ICA certificate expired on the Security Management Server / Domain Management Server and renewed using **[sk158096 "How to renew an Internal Certificate Authority (ICA) certificate](https://support.checkpoint.com/results/sk/sk158096)** ,but the SIC certificate was not renewed on each applicable Security Management Server / Multi-Domain Security Management Server / Domain Management Server.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
