Windows RRAS cannot find IKEv2 certificate after restart


we have server running windows server 2012 vpn connections rras. after initial difficulties pki certificate acceptable ikev2, got working.

it worked week, , now, after restarted services unrelated issue, seems server can no longer find correct certificate though in certificate manager.

all clients (built-in windows vpn client) give error 13806: ike failed find valid machine certificate. contact network security administrator installing valid certificate in appropriate certificate store.

the client logs enormous , hard make sense of, don't seem error message doesn't.

the certificate worked before in machine store on rras server. checked again against detailed survey of works , doesn't work , appears fine. certificate's cn set internal fqdn, subject alternative name: dns name set dns name vpn clients using.

other things i've considered:

  • the certificate doesn't expire until 2015.
  • both client , server trust ad ca's root certificate
  • using pptp same server works fine
  • server event logs seem show nothing
  • attempting connect computer inside network fails same error

is there way can force server pick right certificate or @ least see why refuses certificate accepted earlier?

i tried recreating certificate using parameters in blog post linked still did not work. realized possible enabling directaccess had caused problem, tried uninstall directaccess, couldn't, reinstalled whole os , reconfigured. worked. think directaccess created certificate conflicted correct ike certificate.


Windows Server  >  Windows Server 2012 General



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Domain migration ERR3:7075 Failed to change domain affiliation, hr=8007054a This operation is only allowed for the Primary Domain Controller of the domain

How do a find data in one file, search for it in another file and if not found, write a custom message to another file