> Source: [sk184408](https://support.checkpoint.com/results/sk/sk184408)

# sk184408 - Smart-1 Cloud Log Exporter fails with "Bad Certificate" error

| Property | Value |
|----------|-------|
| Solution ID | sk184408 |
| Date Created | 2025-12-08 |
| Last Modified | 2025-12-10 |
| Technical Level | Advanced |
| Products | Smart-1 Cloud |
| Versions | Cloud |

## Symptoms

- * The Log Exporter cannot establish a secure connection to the Security Information and Event Management (SIEM) server.
* Smart-1 Cloud shows a "Bad certificate" error during the TLS handshake, even though OpenSSL tests indicate a valid certificate chain.
* The ` $INDEXERDIR/log/log_indexer.elg` file shows that multiple root Certificate Authorities (CAs) exist:  

  `[log_indexer PID]@Host[DATE TIME] fwCert_FixChain_with_rca: Found additional root CA down the chain with the same DN, need to check if certificate is indeed the same`  
  `
  [log_indexer PID]@Host[DATE TIME] fwCert_FixChain_with_rca: Found matching root CA down the chain. Chopping will be done`  
  `
  [log_indexer PID]@Host[DATE TIME] fwCert_FixChain_with_rca: certificate number 2 will be removed`  
  `
  [log_indexer PID]@Host[DATE TIME] fwCert_FixChain_with_rca: finished removing non-needed certs from the chain returning chopped chain`  
  `
  [log_indexer PID]@Host[DATE TIME] fwValidatePath: checking chain of len 3`  
  `
  [log_indexer PID]@Host[DATE TIME] fwValidateCert: grace period list does not exist. Allow grace period in verification.`

## Cause

The `ca.pem` file uploaded to Smart-1 Cloud Log Exporter contained the root Certificate Authority (CA) and two subordinate CA certificates. This configuration caused the Check Point CPCrypto module to fail certificate validation because it expects a single root CA for proper chain validation.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
