# Certificate validity period not applied after using the "set_cert_validity" command

## Product
- Multi-Domain Security Management, Security Management

## Version
- R81.10 (EOS), R81.20, R82

## OS
- Gaia

## Last Modified
- 2026-07-23

## Symptoms
- Certificates created in the Security Management Server environment remain valid for their default period (typically 2 years), even after running the "`cpca_client set_cert_validity`" command to set the validity period to a different value.
- The command executes successfully and displays: `cert validity period was changed successfully`
- The ICA Management Tool shows the updated validity settings but does not apply them to newly created certificates.

## Cause
The validity period change from "`cpca_client set_cert_validity`" is not properly integrated with the certificate generation process in these versions:
- R81.10 Jumbo Hotfix Accumulator Take 150 and higher
- R81.20 Jumbo Hotfix Accumulator Take 89 and higher

## Solution
This problem was fixed. The fix is included in:
- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 118
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 158

If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

Or follow this **workaround:**
Certificates can be modified individually:
1. Open the ICA Management tool. For configuration, see [R82 Quantum Security Management Administration Guide](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Default.htm) > The ICA Management Tool (or another relevant for you version of this document).
2. Navigate in the ICA Management Tool Portal to the settings of a specific certificate.
3. Modify the validity period in the "Advanced" tab for each certificate.

#### NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties
- Access Level: General
- Status: Approved by TAC
- Date Created: 2025-10-27
- Last Modified: 2026-07-23
