# CPCA daemon is 'down' after creating a new Domain

## Product
Multi-Domain Security Management

## Version
R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20

## OS
Gaia

## Last Modified
2025-01-16

## Symptoms
- After you add a new Domain, the output of the `mdsstat` command shows that the `cpca` daemon remains in the `down` state.

## Cause
The content of the _$MDS_CPDIR/registry/HKLM_registry.data_cust_ registry file is incorrect and contains SIC settings (this file is the base registry for a new Domain and contains specific data during a Domain creation).

The Certificate Authority server settings did not initialize during the Domain creation because the SIC section was already populated.

## Solution
This problem was fixed. The fix is included in:

- [Check Point Quantum R82](https://support.checkpoint.com/results/sk/sk181127)
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 79
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 158

If you choose not to upgrade, [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a **Hotfix** for this issue.

**Workaround procedure for a new Domain, on which there are no certificates (no managed objects or users):**

1. Connect to the command line on the Multi-Domain Security Management Server.
2. Log in to the Expert mode.
3. Go to the context of the new problematic Domain Management Server:
   
   `mdsenv <IP Address or Name of Domain Management Server>`
4. Reset the Certificate Authority:
   
   `fwm sic_reset`
5. Create the Certificate Authority:
   
   `mdsconfig -ca <Name of Domain Management Server> <IP Address of Domain Management Server>`

Example:
   
   `mdsconfig -ca MyNewDomain 192.168.2.4`

#### NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties
Access Level: General

Status: Approved by TAC

Date Created: 2023-12-13

Last Modified: 2025-01-16
