sk181798 - CPCA daemon is 'down' after creating a new Domain
CPCA daemon is 'down' after creating a new Domain
Product
Multi-Domain Security Management
Version
R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
OS
Gaia
Last Modified
2025-01-16
Symptoms
- After you add a new Domain, the output of the
mdsstatcommand shows that thecpcadaemon remains in thedownstate.
Cause
The content of the $MDS_CPDIR/registry/HKLM_registry.data_cust registry file is incorrect and contains SIC settings (this file is the base registry for a new Domain and contains specific data during a Domain creation).
The Certificate Authority server settings did not initialize during the Domain creation because the SIC section was already populated.
Solution
This problem was fixed. The fix is included in:
- Check Point Quantum R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 79
- Jumbo Hotfix Accumulator for R81.10 starting from Take 158
If you choose not to upgrade, Contact Check Point Support to get a Hotfix for this issue.
Workaround procedure for a new Domain, on which there are no certificates (no managed objects or users):
Connect to the command line on the Multi-Domain Security Management Server.
Log in to the Expert mode.
Go to the context of the new problematic Domain Management Server:
mdsenv <IP Address or Name of Domain Management Server>Reset the Certificate Authority:
fwm sic_resetCreate the Certificate Authority:
mdsconfig -ca <Name of Domain Management Server> <IP Address of Domain Management Server>
Example:
mdsconfig -ca MyNewDomain 192.168.2.4
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2023-12-13
Last Modified: 2025-01-16