> Source: [sk81360](https://support.checkpoint.com/results/sk/sk81360)

# sk81360 - "Failed to update Internal CA DB" error on synchronization failure in Management High Availability configuration

| Property | Value |
|----------|-------|
| Solution ID | sk81360 |
| Date Created | 2012-10-29 |
| Last Modified | 2025-10-16 |
| Technical Level | Advanced |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Linux, Gaia |

## Symptoms

- * "`Failed to update Internal CA Database`" error in SmartDashboard on synchronization failure in Management High Availability configuration.

* The CPCA process is down on the secondary Domain Management server.

* "`Collision`" or "`Lagging`" status in SmartDashboard for Management HA Servers / Domain Management Servers (R77.x versions)

* These messages are printed in `$FWDIR/log/cpca.elg*`:  

  `
  [cpca 27848 4121188160] cpFileCopy: failed to fopen source file`  

  `
  [cpca 27848 4121188160] fwCA::CopyDb: error copying /opt/CPsuite-R80.20/fw1/conf/InternalCA.C to /opt/CPsuite-R80.20/fw1/log/mgha/41e821a0-3720-11e3-aa6e-0800200c9fde/ica{9066FAB0-7CB6-484F-A63A-CE7FD0EE06C7}/InternalCA.C`

## Cause

* Internal Certificate Authority files have become corrupt on the Secondary Security Management Server / Secondary Domain Management Server  

  OR  

* Size of some *$FWDIR/conf/hit_count_rules_tables.sqlite_\** files on the problematic Primary / Secondary Security Management Server / Primary Domain Management Server.  

  OR  

* A large sized *cp.contract* file (\> 15MB) created a bottleneck and prevents the synchronization between Domain Management Servers from completing (R77.x versions).

<!-- -->

* The user might have run the solution mentioned in [sk99130](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk99130) on the Secondary Security Management server. The solution mentioned in [sk99130](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk99130)removes the ICA related files and needs to be executed on the Security Gateway only, and not on the Primary or Secondary Security Management server (R77.x versions).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
