> Source: [sk184143](https://support.checkpoint.com/results/sk/sk184143)

# sk184143 - MacOS RA-VPN "Failed to create Site" Error Due to Missing ECDSA Cipher Support

| Property | Value |
|----------|-------|
| Solution ID | sk184143 |
| Date Created | 2025-10-27 |
| Last Modified | 2025-11-03 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * MacOS clients cannot create a VPN site to the Check Point Security Gateway.
* Connection attempts result in handshake failures and SSL errors.
* Logs in ``$FWDIR/log/vpnd.elg` show:
  cptls_params::choose_from_cipher_list:`` Peer does not support `TLS_ECDHE_ECDSA_WITH_AES_###_GCM_SHA###`
* Windows clients successfully connect using the same Security Gateway and certificate.
* MacOS client proposes only cipher suites based on Rivest-Shamir-Adleman (RSA) and does not include the Elliptic Curve Digital Signature Algorithm (ECDSA) cipher suites required by certificates that use Elliptic Curve Cryptography (ECC).

## Cause

Starting from Endpoint Security version MAC_E87.80, the **cpcrypto** module upgrade omitted support for ECDSA signature algorithms, specifically the `TLS_ECDHE_ECDSA ` cipher suites. This prevents MacOS clients from negotiating secure connections with gateways using ECC certificates.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
