Symantec Messaging Gateway (SMG) license registration fails with: "Connection error 56: SSL routines::tlsv1 alert unknown ca"
When attempting to register or update a license in Symantec Messaging Gateway (SMG), the registration fails with the following error:
Cannot register the specified license file. Unable to communicate with Symantec to register. Please check your connection settings, and try again. Connection error 56: OpenSSL SSL_read: error:0A000418:SSL routines::tlsv1 alert unknown ca
This may occur even if curl commands to register.brightmail.com and aztec.brightmail.com succeed from the appliance CLI.
Messaging Gateway
This error typically indicates a mismatch or corruption in the local license state or an SSL/TLS handshake failure where the certificate presented during the registration-specific transaction is not recognized by the internal license-control engine.
To resolve this issue, you must clear the current license state from the appliance and re-initiate the registration.
-r flag removes the license, and -f forces the action..slf file, or use the CLI:Verify the license status in the Control Center under Dashboard or by running license-control -l in the CLI.
Note that once an appliance has been registered using the standard online method (via the Control Center), the system locks the licensing mechanism to that method. Attempting an offline registration on such a system will result in the error: "This system has previously been registered in the normal fashion. license-control cannot be used on this system."