> Source: [sk183357](https://support.checkpoint.com/results/sk/sk183357)

# sk183357 - Single Management Object (SMO) does not distribute contract to Maestro Security Group Members

| Property | Value |
|----------|-------|
| Solution ID | sk183357 |
| Date Created | 2025-04-21 |
| Last Modified | 2026-07-14 |
| Technical Level | General |
| Products | Scalable Platforms |
| Versions | R81.20 |

## Symptoms

- During contracts renewal, non-SMO Security Group Members in a Maestro Security Group do not receive the updated contract automatically.

## Cause

The Management Server maintains a database that stores all Certificate Keys (CKs) of managed appliances. It uses this database to check for contract updates from the User Center.

In a Maestro environment, this database includes only the SMO's MAC-address CK. As a result, non-SMO Security Group Members do not receive the updated contract automatically.

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).  

This **workaround**is also available:

Follow these steps to manually update the contract on non-SMO Security Group Members:

1. Pull the new contract from the User Center. According to UC rules, the pulled file contains the contract data for the whole account. If the Security Group is built from appliances belonging to several different accounts, the same procedure should be followed for each account.
2. Copy the contract file to the SMO (any folder =\<CONTRACT_FILE_PATH\>)
3. Install the contract data file on the SMO with the command "cplic contract put \<CONTRACT_FILE_PATH\>." The cp.contract file is accumulative so the $CPDIR/conf/cp.contract will contain the merge of all the calls for "cplic contract put \<CONTRACT_FILE_PATH\>".
4. Backup the merged file # cp $CPDIR/conf/cp.contract $CPDIR/conf/cp.contract.bkp
5. Use the command # asg_cp2blades $CPDIR/conf/cp.contract.bkp
6. On non-SMO blade run # cplic contract put $CPDIR/conf/cp.contract.bkp

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
