> Source: [sk182415](https://support.checkpoint.com/results/sk/sk182415)

# sk182415 - FWM and FWMHA are in terminated state after uninstalling Hotfix or Jumbo Hotfix from Standalone server

| Property | Value |
|----------|-------|
| Solution ID | sk182415 |
| Date Created | 2024-07-01 |
| Last Modified | 2024-07-15 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R81.20, R81.10 (EOS) |

## Symptoms

- * The output of the `"cpwd_admin list"` command on a Standalone server show that the FWM and FWMHA processes are terminated, for example:  

  `
  [Expert@Management]# cpwd_admin list | grep FWM`  
  `
  FWM 0 T 4 [11:56:19] 22/9/2023 N fwm`  
  `
  FWMHA 0 T 4 [11:56:19] 22/9/2023 N fwmha -H`

* The FWM and FWMHA processes are down and do not start after running `"cpstop;cpstart"` or after a reboot of the server.

* Starting FWM in debug mode (with "`fwm -d`") shows these errors:  

  `
  [FWM PID]@Standalone [Date Time] extract_p12_file: Called, path is [/opt/CPshrd-R81.10/conf/sic_local_cert.p12]`  
  `
  [FWM PID]@Standalone [Date Time] extract_p12_file:[ERROR] Failed to parse PKCS12`  
  `
  [FWM PID]@Standalone [Date Time] sic_over_ssl_free_global_data: Called`  
  `
  [FWM PID]@Standalone [Date Time] sic_over_ssl_free_global_data: Finish`  
  `
  [FWM PID]@Standalone [Date Time] sic_local_over_ssl_init_do:[ERROR] Failed to extract sic local cert`  
  `
  [FWM PID]@Standalone [Date Time] sic_local_over_ssl_init: Going to release mutex`  
  `
  [FWM PID]@Standalone [Date Time] sic_local_over_ssl_init_SSL_CTX:[0x9719a28][ERROR] sic_local_over_ssl_init has failed`  
  `
  [FWM PID]@Standalone [Date Time] NgmSicLocalCommunicationConfigurer::configure:[0x978dce0] sic_local_init_SSL_CTX failed. ctx is [0x9719a28]`  
  `
  [FWM PID]@Standalone [Date Time] GetDll: libCPMIServerTables.so found in cache`  
  `
  [FWM PID]@Standalone [Date Time] CTableMgr::GetTable: no such table globals`  
  `
  [FWM PID]@Standalone [Date Time] CCkpTableMgr::BuildTableFromSet: Building table 'globals'`  
  `
  [FWM PID]@Standalone [Date Time] GetDll: libCPMIServerTables.so found in cache`  
  `
  [FWM PID]@Standalone [Date Time] CPMIGetDomainUID: Setting domain uid by domain name`  
  `
  [FWM PID]@Standalone [Date Time] CPMIGetDomainUID: Setting domain uid to xxxxxxxx-3720-xxxx-aa6e-0800300d9fde.`  
  `
  [FWM PID]@Standalone [Date Time] fwmLogin: Warning: gsoap FWM session ID is NULL or empty`  
  `
  [FWM PID]@Standalone [Date Time] fwmLogin: error returned from ngm server`  
  `
  [FWM PID]@Standalone [Date Time] fwmLogin: Fault returned from remote server: SOAP 1.1 fault: SOAP-ENV:Client[no subcode]`

## Cause

The file *sic_conf.xml* stores the *sic_local_cert.p12* password in it.  
When the Hotfix or Jumbo Hotfix Take is uninstalled, the original *sic_conf.xml* file is restored, which contains the wrong password for *sic_local_cert.p12*.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
