> Source: [sk96594](https://support.checkpoint.com/results/sk/sk96594)

# sk96594 - "Internal CA cannot find the reference number in its database" error when trying to use Remote Access VPN / SNX clients

| Property | Value |
|----------|-------|
| Solution ID | sk96594 |
| Date Created | 2013-11-11 |
| Last Modified | 2023-07-19 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * "`Internal CA cannot find the reference number in its database`" error when Remote Access VPN / SNX client on Windows OS / MAC OS X is trying to use a certificate registration key (new, or a renewed one).

* "`The registration key is not valid`" error when iOS / Android client is trying to use a certificate registration key (new, or a renewed one).

* Issue occurs in Full HA cluster when the cluster member that runs the Active Security Management Server is currently in the Standby cluster state.

## Cause

In MGMT-HA environment, the cluster member queries the management database to get the Management Server's IP address, from which to fetch the certificate.

If the cluster member in the "Active" cluster state ***is*** the machine that runs the Active Security Management Server, then the Active cluster member will get its own IP address and ***will be*** able to fetch the certificate from itself.

If the cluster member in the "Active" cluster state is ***not*** the machine that runs the Active Security Management Server, then the Active cluster member will ***not*** be able to fetch the certificate from itself.  
Such MGMT-HA configuration is ***not*** officially supported for enrollment/renewal with certificates.

**There is no synchronization of certificates waiting for enrollment/renewal between the Primary and Secondary Security Management Server.**

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
