> Source: [sk97833](https://support.checkpoint.com/results/sk/sk97833)

# sk97833 - Pushing VSX configuration fails with "The certificate is not valid"

| Property | Value |
|----------|-------|
| Solution ID | sk97833 |
| Date Created | 2014-01-06 |
| Last Modified | 2024-06-09 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20, R82.10, R82.20, R81.20, R82, R82.20 |
| OS | Gaia |

## Symptoms

- * Pushing configuration to a Virtual System fails:

  ```
  
  Checking connection with VSX
  Generating VSX Configuration for XXX on XXX.
  Pushing VSX Configuration to <VS_NAME>.
  <VS_NAME>: error :Virtual System cannot be created 
  <VS_NAME>: VSX configuration was applied successfully.
  Virtual System Processing Completed Successfully
  Establishing Trust with - <Object_Name> ...
  The certificate is not valid.
  Failed to establish trust with <Object_Name> - 
  
  Initiating trust with Virtual System operation has finished with warnings.
           Make sure that all Virtual Systems/Routers are accessible from the management server,
           and that you have a valid license. Edit the failed object and click OK.
           If the problem persists contact Check Point Technical Support.
  ```

* Renewing the certificate on the Virtual System or resetting the SIC does not resolve issue.

* Output of \[Expert@HostName\]# cpca_client lscert -dn "CN=" from the Management Server , shows that the relevant certificate is on 'Pending' status.
* Output of \[Expert@HostName\]# vsx stat -v on the VSX shows that the relevant Virtual System is on 'Untrust' status.

## Cause

The Management Server is pushing the SIC certificate to the Virtual System using port 18211 (service FW1_ica_push).

The Virtual System is pulling the SIC certificate from its Management Server using port 18210 (service FW1_ica_pull).

If connectivity is not allowed on these ports, the Management Server and the VSX will fail to push and pull the certificate.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
