> Source: [sk184890](https://support.checkpoint.com/results/sk/sk184890)

# sk184890 - Unable to access Gaia Portal from all Maestro Security Group Members after an upgrade from R81.20 to R82

| Property | Value |
|----------|-------|
| Solution ID | sk184890 |
| Date Created | 2026-04-27 |
| Last Modified | 2026-04-28 |
| Technical Level | Advanced |
| Products | Check Point Portal |
| Versions | Cloud |
| OS | Gaia |
| Platform | 29000 |

## Symptoms

- * After upgrading a Maestro environment from R81.20 to R82, access to the Gaia Portal from all Security Group Members fails. The browser shows:

  `ERR_CONNECTION_CLOSED`

  Note - Access to the Gaia Portal works after changing the Multi-Portal port from 443 to 8443 (workaround).
* On the affected Security Group Member, the `/var/log/httpd2_error_log` file contains:

  `server certificate does not include an ID which matches the server name`.
* Running `g_all fw ctl zdebug + crypt` while reproducing the issue shows:

  `
  vm_mux_cpas_generic_read_handler: [GHTAB] get_ghtab_cptls_params_id failed, trying to get default id;
  get_ghtab_cptls_default_params_id: cptls_params entry was not found.;
  vm_mux_cpas_generic_read_handler: [GHTAB] get_ghtab_cptls_default_params_id failed;
  `
* The `vpnd.elg` debug file (collected during policy installation) shows:

  `
  [CPTLS] bool fetch_certificate_keyholder (fwset, const char*, fwKeyHolder*&): 'cert_reference' is `  
  `empty`  
  `
  ...`  
  `
  fwKeyHolder_AddCAs_toKeyholder: fwRootCAfromobj failed for xxxxxca04-CA; the database may be `  
  `corrupted`  
  `
  `
* In SmartConsole:

  * Navigate to **Servers** \> **Trusted CAs**.
  * Open the applicable CA object.
  * In the **OPSEC PKI** tab, clicking **View** under **Certificate** fails with: `Failed to read CA certificate ... from database`.

## Cause

The Management database contains unused Trusted CA objects that do not have associated CA certificates. These invalid objects can cause the portal TLS negotiation to fail, which results in the browser closing the connection.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
