> Source: [sk98749](https://support.checkpoint.com/results/sk/sk98749)

# sk98749 - Subject DN in server certificate differs from expected

| Property | Value |
|----------|-------|
| Solution ID | sk98749 |
| Date Created | 2014-02-28 |
| Last Modified | 2020-01-14 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X, R82.10, R82, R81.20 |
| OS | Windows |

## Symptoms

- * After making some modifications to the CA, some clients are unable to connect to the server anymore.   

* Errors in the EndPoint logs (cpda file) logs:   

  ERROR--- Subject DN in server certificate differs from expected, server DN: /O=MX-CHEE01..bjd2tw/CN=cp_mgmt,   
  expected: CN=cp_mgmt,O=MX-CHEE01..tmricp.   
  Last win error: 0 (0x0)(the_verify_callback)  
  ERROR--- Failed to send request/receive response due to HTTP curl library function curl_easy_perform returned  
  error code 60 (== Peer certificate cannot be authenticated with known CA certificates).   
  Last win error: 0 (0x0) (CHTTPCall_curl::sendReq_internal)  
  ERROR--- CURL error description: SSL certificate problem, verify that the CA cert is OK.   
  Details: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed.   
  Last win error: 122 (0x7A) (CHTTPCall_curl::sendReq_internal)  
  ERROR--- CURLE_SSL_CACERT, Peer certificate cannot be authenticated with known CA certificates.   
  Last win error: 122 (0x7A) (CHTTPCall_curl::sendReq_internal)  
  No HTTP response status code has been received (CHTTPCall_curl::sendReq_internal)  
  ERROR--- Failed to send request (or problem with response).   
  Last win error: 122 (0x7A) (CCPPeer::sendReq)

## Solution

If there is an HTTPS inspection enabled on a Gateway between Endpoint Security clients and Endpoint Security server and the inspection rule is built based on object's IP address - move the bypass HTTPS inspection rule to the top of the rule base.

or

[Contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) for assistance in resolving this issue.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
