> Source: [sk60223](https://support.checkpoint.com/results/sk/sk60223)

# sk60223 - How to fix "The direct CA certificate in the received chain doesn't match the CA certificate for which you created the certificate request."

| Property | Value |
|----------|-------|
| Solution ID | sk60223 |
| Date Created | 2011-01-16 |
| Last Modified | 2018-05-28 |
| Technical Level | Advanced |
| Products | SmartConsole |
| Versions | R82.10, R82.x, R82.20, R82, R81.20 |

## Symptoms

- When trying to complete a 3rd party certificate, you get the following error: "The direct CA certificate in the received chain doesn't match the CA certificate for which you created the certificate request."

## Cause

The error you are getting is due to the fact that the Trusted CA you setup in dashboard and used to generate the CSR is different from the CA that was used to sign your certificate. This is likely due to the CA keeping several intermediate CAs and signing your cert with one of them instead of their root CA. Typically this is not an issue, but Check Point places strict requirements on this.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
