Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ihenock1011
Collaborator
Jump to solution

Secondary SMS Certificate expired error

Hi Team,

We have deployed two Check Point Smart Management Servers (SMS) and their synchronization appears successful. However, when attempting to log in to the secondary SMS, we encounter a certificate expiration error.

Could you please advise on the cause of this issue and the recommended steps for resolving the certificate expiration on the secondary SMS server?

FYI: The error screenshot is attached here.

Thanks,

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
Champion Champion
Champion

Known issue that happens every time we set up Management HA for the CCSE labs on R81.20 GA.  Simply execute cprestart or reboot the Secondary and the problem will go away.  This was an issue in prior code releases too, not sure why this can't ever seem to be fixed.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com

View solution in original post

(1)
9 Replies
just13pro
Collaborator

When you are login to Primary, will you get the similar error?

 

0 Kudos
Ihenock1011
Collaborator

Nop The primary is working Ok.

0 Kudos
Timothy_Hall
Champion Champion
Champion

Known issue that happens every time we set up Management HA for the CCSE labs on R81.20 GA.  Simply execute cprestart or reboot the Secondary and the problem will go away.  This was an issue in prior code releases too, not sure why this can't ever seem to be fixed.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
(1)
the_rock
Legend
Legend

@Timothy_Hall is 100% right. I had this happen in the lab 3 times and either cprestart or reboot fixes it, easy peasy. 

Andy

0 Kudos
just13pro
Collaborator

Interesting, I had setup few times with Mgmt HA but so far never encountered any of this error message.

0 Kudos
the_rock
Legend
Legend

What version was it?

0 Kudos
just13pro
Collaborator

mostly R81.10.

Done with R80.10 as well but never encountered such.

 

0 Kudos
the_rock
Legend
Legend

I will try replicate it in R81.10

Timothy_Hall
Champion Champion
Champion

It seems to be some kind of timing/race condition that depends on the performance of the secondary.  In a VMWare environment my CCSE attendees run into it every single time.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events