> Source: [sk115714](https://support.checkpoint.com/results/sk/sk115714)

# sk115714 - When User (connecting via L2TP or Capsule VPN with LDAP) authenticates with certificate, the user is rejected

| Property | Value |
|----------|-------|
| Solution ID | sk115714 |
| Date Created | 2017-10-03 |
| Last Modified | 2023-11-19 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * When Remote Access User authenticates with certificate issued by external CA, they are rejected.
* When Remote Access User authenticates with certificate from Internal CA (ICA), they connect successfully.
* Once SecuRemote is used, User can connect either with certificate from ICA or from external CA.
* *vpnd.elg* shows: "fetch_user_wrapper_cb: Error occurred - User does not support public key authentication"
* In SmartLog, see log: "User authentication failed: No such user"
* In the case of Capsule VPN, certificate authentication fails for LDAP users regardless if the certificate is signed by the ICA or an external CA.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
