> Source: [sk31539](https://support.checkpoint.com/results/sk/sk31539)

# sk31539 - Security Management Server warns about expiring Security Gateway certificates during policy installation

| Property | Value |
|----------|-------|
| Solution ID | sk31539 |
| Date Created | 2006-03-01 |
| Last Modified | 2025-08-12 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R81 (EOS), R81.10 (EOS), R81 (EOS) |

## Symptoms

- Upon installing Security Policy, Security Management server warns about expiring Security Gateway certificates:

* `warning: The following certificate of gateway "CN=XXX VPN Certificate,O=XXX;" is about to expire:`

  `warning: <N>. DN: "CN=XXX VPN Certificate,O=XXX;", expiration date: XXX. refer sk31539`
* `warning: The following certificate of gateway "CN=XXX VPN Certificate,O=XXX;" has already expired:`

  `warning: <N>. DN: "CN=XXX VPN Certificate,O=XXX;", expiration date: XXX . refer sk31539`

## Solution

With every Security Policy installation, the Security Management server reviews the certificates held by all the Security Gateways that it manages. The Security Management server generates a report, per Security Gateway, warning about those certificates that will expire within 60 days time from the current date. **This functionality is always enabled, and the 60 days is a fixed warning period.**

**Security Policy verification alone will not generate a certificate expiration report.** A certificate expiration report is generated whether the Policy installation is initiated from the SmartDashboard, or from the Security Management Server's command line.

Check Point recommends to always upgrade to a recent version, and to the most recent HFA (HotFix Accumulator) of this version.

In general, after a Security Policy is installed in SmartConsole, and if there are any resulting errors or warnings, a button will appear in the bottom, left-hand corner of the Installation Process window. The text on the button can be either "**Show Errors** " (when both errors and warnings are produced) or "**Show Warnings**" (when only warnings are produced).

With the certificate expiration report feature, after installing the policy, if there are any certificates that expire within the next 60 days for any of the Security Gateways managed by the Security Management server, this button will appear.

**Note -**Depending on the type of processing errors encountered, there may be Policy Installation instances, in which no certificate expiration report is generated.

When you click this button, a Verification and Installation Messages table is displayed. The table contains the associated errors and/or warnings generated by the Policy Installation process.

Per Security Gateway (a defined network object), each certificate due to expire within 60 days is listed along with both its Distinguished Name (DN) and expiration date-time (certificate is "not valid after").

When policy installations are initiated from the Security Management server command line, certificate expiration warning messages are displayed on the terminal used to initiate the installation process. Information reported is the same as in SmartConsole / SmartDashboard.

**Notes:**

* **Certificate expiration warning messages are not recorded in any log by the Management Server.**
* Warnings are generated and presented anew with each Policy installation.
* If, for a given Policy installation, none of the managed Security Gateways have any certificates due to expire within the next 60 days, then no expiration warning messages are produced.
* Currently, this is only supported for Security Gateway, and a warning will not appear for Edge devices whose certificate is about to expire.
* Security Gateways and Clusters use the VPN IKE certificate for:
  * VPN products.
  * Multi-Portals (Mobile Access Portal, Identity Awareness Captive Portal, User Check Portal, and so on).
  * [Gaia Portal with enabled Multi-Portal feature.](https://support.checkpoint.com/results/sk/sk97648)

**Procedure:**

**Important:** We recommend to perform this procedure during a maintenance window, as an outage of the certificate-based VPN tunnel may occur.

1. Connect to the command line on the Management Server.

2. Log in to the Expert mode.

3. On the Multi-Domain Security Management Server, go to the content of the Domain Management Server that manages the Security Gateway / Cluster:

   `mdsenv <IP Address of Name of Domain Management Server>`
4. Configure the IKE certificate standard validity period to 3 years:

   `cpca_client set_cert_validity -k IKE -y 3`
5. Renew the IKE certificate:

   1. Connect with SmartConsole to the Security Management Server / Domain Management Server that manages the Security Gateway / Cluster.

   2. From the left navigation panel, click **Gateways \& Servers**.

   3. Open the Security Gateway / Cluster object.

   4. Make sure the **IPSec VPN** Software Blade is enabled:

      1. From the left tree, click the **General Properties** page.

      2. On the **Network Security** tab, select the checkbox **IPSec VPN** - even if you do not use it in this Security Gateway / Cluster (you disable it later).

   5. From the left tree, click the **IPSec VPN** page.

   6. Examine the current expiration date:

      1. In the section **Repository of Certificates Available on the Gateway**, select the certificate.

      2. Click the "**View**" button.

      3. In the line "**Not Valid After**", examine the date.

      4. Click the "**OK**" button.

   7. In the section **Repository of Certificates Available on the Gateway**, select the certificate.

   8. Click the "**Renew**" button.

   9. Click the "**Yes**" button to confirm.

   10. In the "**Generate Keys and Get Internal CA Certificate** " window, click "**OK**".

   11. Click "**OK**" to close the Security Gateway / Cluster object.

   12. Open the Security Gateway / Cluster object.
   13. From the left tree, click the **IPSec VPN** pane.

   14. Examine the current expiration date:

       1. In the section **Repository of Certificates Available on the Gateway**, select the certificate.

       2. Click the "**View**" button.

       3. In the line "**Not Valid After**", examine the date.

       4. Click the "**OK**" button.

   15. If you do **not** use the **IPSec VPN** Software Blade in this Security Gateway / Cluster, then disable it:

       1. From the left tree, click the **General Properties** page.

       2. On the **Network Security** tab, clear the checkbox **IPSec VPN**.

   16. Click "**OK**" to close the Security Gateway / Cluster object.

   17. Install the Access Control Policy on this Security Gateway / Cluster object.

   18. Install the Access Control Policy on all other Security Gateway / Cluster objects that participate in a VPN community with this Security Gateway / Cluster object.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
