> Source: [sk43030](https://support.checkpoint.com/results/sk/sk43030)

# sk43030 - IKE: Main Mode CRL is not yet valid.

| Property | Value |
|----------|-------|
| Solution ID | sk43030 |
| Date Created | 2009-10-23 |
| Last Modified | 2019-07-21 |
| Technical Level | Advanced |

## Symptoms

- * VPN tunnels will go down and will not renegotiate
* IKE debug shows that phase 1 fails with reason: INVALID-CERTIFICATE
* smartlog: IKE: Main Mode CRL is not yet valid.Make sure that the time, daylight saving time and date on your machine are well configured.CN=..

## Cause

The Security Gateway clock is not synchronized with the Security Management clock.

Debugs of vpnd will show:

**Main Mode CRL is not yet valid.Make sure that the time, daylight saving time and date on your machine are well configured.**

The debug will also show:

**\[vpnd 5478 1982740160\]@gateway\[2 Dec 23:52:31\] thisUpdate: Mon Dec 3 00:36:30 2012 Local Time**   
**\[vpnd 5478 1982740160\]@gateway\[2 Dec 23:52:31\] nextUpdate: Mon Dec 10 00:36:30 2012 Local Time**

**\[vpnd 5478 1982740160\]@gateway\[2 Dec 23:52:31\] now: Sun Dec 2 23:52:31 2012 Local Time**

These debug lines indicate that vpnd is scheduled to perform certificate validation at Mon Dec 3, but the current date is Dec 2. This discrepancy invalidates the certificate and the tunnel will fail.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
