> Source: [sk183386](https://support.checkpoint.com/results/sk/sk183386)

# sk183386 - Endpoint Security Clients are not communicating with the Endpoint Security Management Server

| Property | Value |
|----------|-------|
| Solution ID | sk183386 |
| Date Created | 2025-04-24 |
| Last Modified | 2025-04-24 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | E89.X, E88.X |
| OS | Windows |

## Symptoms

- * All the Endpoint Security clients are in disconnected state.
* cpda.log shows these errors:  
  `root [debug] verify error=26(unsupported certificate purpose)

  root [error] Failed curl_perform, error: 60 (== SSL peer certificate or SSH remote key was not OK), decription 'SSL certificate problem: unsupported certificate purpose' [CHTTPCall_curl::sendReq_internal]

  [debug] NewCaCert: SSL caCert error occured, possibly server changed caCert, setting DA to recalculate proximity [CDA::updateSslErrorOccured]`
* Certificate validation in *cpda.log* differs from the expected chain.

## Cause

Verification of SSL certificate chain in the *cpda.log* file shows that an SSL inspection injected some other certificate in the middle of certificate chain and therefore certificate failed on the validations. (`...Issuer -> XXXXXXX.dm-rind.rcip.co.il...`)  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1745490825637/tempsnip202504240637071.png)  
This differs from the expected certificate chain (use the URL mentioned in the log file to view the expected certificate chain). Here is an example of the expected certificate chain: **![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1745490825637/fvsfxqtk202504240642212.png)**

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
