> Source: [sk99034](https://support.checkpoint.com/results/sk/sk99034)

# sk99034 - "The direct CA certificate in the received chain doesn't match the ca certificate for which you created the certificate check that the chain was received from the correct CA" error when importing a certificate in the Security Gateway object

| Property | Value |
|----------|-------|
| Solution ID | sk99034 |
| Date Created | 2014-04-19 |
| Last Modified | 2022-10-25 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- "`The direct CA certificate in the received chain doesn't match the ca certificate for which you created the certificate check that the chain was received from the correct CA`" error after generating a certificate signing request (CSR) and importing a certificate (CRT file) in the Security Gateway object

## Cause

The signing authority's CA certificate has changed and no longer matches what is is defined in your CA object in SmartDashboard.

To verify, view the CA certificate on your CA object(s) versus the CA certificate in the chain of the downloaded CRT file.

## Solution

The solution is to create a new CA object using the new CA cert

1. Open the cert given from your failed csr

2. In the certification path, choose the CA certificate that appears to have changed and view it

3. In the Details tab, choose copy to file. Follow the wizard to export the cert. When asked choose DER for the format

4. Create a new CA object

1. right click Objects tree\>servers and opsec\>servers\>trusted CAs
2. New CA's trusted
3. Give it a name. Under opsec pki click get
4. import the exported file you made
5. Un-Check "ldap servers" below. Leave http checked
6. install database

4. Generate a new CSR, get it signed and import. It should now be successful.

(If unsuccessful and there is an intermediate CA, try redoing both the intermediate and root CAs)

Related Documentation:   
[How To Install Third Party SSL Certificates for IPSec VPN](http://downloads.checkpoint.com/dc/download.htm?ID=16641)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
