> Source: [sk184230](https://support.checkpoint.com/results/sk/sk184230)

# sk184230 - Certificate validity period not applied after using the "set_cert_validity" command

| Property | Value |
|----------|-------|
| Solution ID | sk184230 |
| Date Created | 2025-10-27 |
| Last Modified | 2026-07-23 |
| Technical Level | General |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82, R81.20, R81.10 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |

## Symptoms

- * Certificates created in the Security Management Server environment remain valid for their default period (typically 2 years), even after running the "`cpca_client set_cert_validity`" command to set the validity period to a different value.
* The command executes successfully and displays: `cert validity period was changed successfully`
* The ICA Management Tool shows the updated validity settings but does not apply them to newly created certificates.

## Cause

The validity period change from "`cpca_client set_cert_validity`" is not properly integrated with the certificate generation process in these versions:  

* R81.10 Jumbo Hotfix Accumulator Take 150 and higher
* R81.20 Jumbo Hotfix Accumulator Take 89 and higher

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 118
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 158

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).
Or follow this **workaround:**   
Certificates can be modified individually:  

1. Open the ICA Management tool. For configuration, see [R82 Quantum Security Management Administration Guide](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Default.htm) \> The ICA Management Tool (or another relevant for you version of this document).
2. Navigate in the ICA Management Tool Portal to the settings of a specific certificate.
3. Modify the validity period in the "Advanced" tab for each certificate.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
