> Source: [sk183612](https://support.checkpoint.com/results/sk/sk183612)

# sk183612 - Hardening certificate validation in Harmony Endpoint for Windows E89.10

| Property | Value |
|----------|-------|
| Solution ID | sk183612 |
| Date Created | 2025-07-01 |
| Last Modified | 2026-05-28 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | E89.X |
| OS | Windows |

## Symptoms

- * failing to communication with EP server
* cpda.log on client shows: 2025-12-22 13:20:47.636 t:7076 root \[debug\] Request TYPE == 9 \[CHTTPCall_curl::sendReq_internal\]   
  2025-12-22 13:20:47.716 t:7076 root \[debug\] ctx=0x47ccb90 cert=0x751ab50 curr_cert=0x751bf90 \[verificationCallbackImpl\]   
  2025-12-22 13:20:47.716 t:7076 root \[debug\] verify error=20(unable to get local issuer certificate) depth=1 \[verificationCallbackImpl\]   
  2025-12-22 13:20:47.716 t:7076 root \[debug\] Chain starting from depth=1 certificate: \[verificationCallbackImpl\]   
  2025-12-22 13:20:47.718 t:7076 root \[debug\] --\> Subject -\> Go Daddy Secure Certificate Authority - G2. \[CoreCommon::CPVerifier::PrintCertToLog\]   
  2025-12-22 13:20:47.718 t:7076 root \[debug\] --\> Issuer -\> Go Daddy Root Certificate Authority - G2. \[CoreCommon::CPVerifier::PrintCertToLog\]   
  2025-12-22 13:20:47.718 t:7076 root \[debug\] --\> valid from 2011-05-03 09:00 to 2031-05-03 09:00 (now 2025-12-22 13:20). \[CoreCommon::CPVerifier::PrintCertToLog\]   
  2025-12-22 13:20:47.718 t:7076 root \[debug\] --\> Subject -\> Go Daddy Root Certificate Authority - G2. \[CoreCommon::CPVerifier::PrintCertToLog\]   
  2025-12-22 13:20:47.718 t:7076 root \[debug\] --\> Issuer -\> Go Daddy Class 2 Certification Authority. \[CoreCommon::CPVerifier::PrintCertToLog\]   
  2025-12-22 13:20:47.718 t:7076 root \[debug\] --\> valid from 2014-01-01 08:00 to 2031-05-30 09:00 (now 2025-12-22 13:20). \[CoreCommon::CPVerifier::PrintCertToLog\]   
  2025-12-22 13:20:47.718 t:7076 root \[debug\] --\> Subject -\> Go Daddy Class 2 Certification Authority. \[CoreCommon::CPVerifier::PrintCertToLog\]   
  2025-12-22 13:20:47.718 t:7076 root \[debug\] --\> Issuer -\> Go Daddy Class 2 Certification Authority. \[CoreCommon::CPVerifier::PrintCertToLog\]   
  2025-12-22 13:20:47.718 t:7076 root \[debug\] --\> valid from 2004-06-29 19:06 to 2034-06-29 19:06 (now 2025-12-22 13:20). \[CoreCommon::CPVe
* E89.20 and higher : Connectivity Blade status shows partial functionality with remediation link to this SK cpda.log on client shows following message "Detailed status 10010=true"

## Cause

In E89.10 Endpoint has updated the openssl version to 3.5.0 which uses stricter SSL validation procedures according to RFC 5280

Old trusted root certificate used to sign certificate chain for management server hosts does not satisfy requirements of this RFC and has to be replaced with newer certificate. On computers where the Microsoft store is not updated and new certificate is not found chain validation will fail.

<br />

Administrators have to update the Microsoft Certificate store with the latest certificates since in the future versions this error will not be ignored and connection to management server on not updated computers will be lost.

## Solution

1. Update the Microsoft Certificate store on the affected client computers automatically using Windows Update feature.  
2. Alternative - Add missing certificate manually.   

|----------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------|
| ### Go Daddy Root Certificate Authority - G2 [Download PEM](https://support.checkpoint.com/results/download/138545 "Root certificate") | Valid until: ?Friday, ?1 ?January ?2038 2:59:59 Thumbprint: 47beabc922eae80e78783462a79f45c254fde68b |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
