> Source: [sk181527](https://support.checkpoint.com/results/sk/sk181527)

# sk181527 - AlgoSec/Tufin server refuses the communication with a Check Point Management Server because of an unrecognized certificate authority

| Property | Value |
|----------|-------|
| Solution ID | sk181527 |
| Date Created | 2023-10-02 |
| Last Modified | 2025-08-04 |
| Technical Level | Advanced |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |

## Symptoms

- * Sending logs from a Check Point Management Server to an AlgoSec server does not work.

* Traffic capture on the AlgoSec server shows that it refuses the communication with a Check Point Management Server because of an unrecognized certificate authority.

* Debug of the *fwm* daemon on the Check Point Management Server shows this error in the *$FWDIR/log/fwm.elg* file:

  `
  opsec_new_auth_conn_to_server: conn from [IP ADDRESS OF ALGOSEC SERVER] to entity cpmi_server (0xb30d630)`  
  ` failed (301) SIC Error for cpmi: Got alert from peer that the CA is unknown`  
  ` 
  [FWM ...]@MGMT_HOSTNAME[DATE TIME] conn_failure_handler: called with sic_errno 301`  
  ` and sic_errmsg SIC Error for cpmi: Got alert from peer that the CA is unknown 
  `
* Debug of the *cpca* daemon on the Check Point Management Server shows this error in the *$FWDIR/log/cpca.elg* file:

  `
  ckpSSL_fwasync_connected: err_msg: (Got alert from peer that certificate validation failed) 
  `
* The log from the AlgoSec server contains these lines:

  `
  SIC ERROR 301 - SIC Error for cpmi: Certificate chain is inconsistent.`  
  `
  `  
  `
  moving opsec_cpmi.conf to opsec_cpmi.conf_old`  
  `
  Info: get_opsec_certificate: Certificate was created successfully`  
  `
  CN is CN=xxx,O=xxx`  
  `
  Info:creating /home/xxx/.fa/firewalls/xxx/opsec_cpmi.conf`  
  `
  Info: _Running: sha2_fa_cpmi_get_tables /home/xxx/.fa/firewalls/xxx/opsec_cpmi.conf -t -v table applications 2>&1 | grep -i error_`  
  `
  Error: OPSEC returned the following error: Error: SIC ERROR 301 - SIC Error for cpmi: Certificate chain is inconsistent.`  
  `
  Error: SIC ERROR 301 - SIC Error for cpmi: Certificate chain is inconsistent.`  
  `
  Error: Failed to establish CPMI connection to <IP ADDRESS OF CHECK POINT MANAGEMENT SERVER>
  `

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
