> Source: [sk118523](https://support.checkpoint.com/results/sk/sk118523)

# sk118523 - CAPI Certificate list is empty in the Connect dialog box of Endpoint Security VPN client

| Property | Value |
|----------|-------|
| Solution ID | sk118523 |
| Date Created | 2017-06-28 |
| Last Modified | 2017-07-12 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Windows |

## Symptoms

- * CAPI Certificate list is empty in the Connect dialog box of Endpoint Security VPN client.
* ICA Certificate enrollment succeeds for the user, and when finishes, the list of certificates is empty.
* The certificate is successfully placed in the CAPI store and is viewable.
* The shell is configured as a third party shell program instead of default shell "explore" in the registry location:  
  `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, attribute names "Shell".`
* The client debug file trac.log is showing:  
  `[PID][DATE TIME][RunAs] GetSecurityContextInformation: Failed to GetCurrentShellProcessId: There are no more files.`
* The issue happen only on 32-bit Client machines.

## Cause

The default shell process has been changed.

In the current design of Endpoint Connect, it is looking for the shell process according to the process name written in the registry.  
For win32 machine it will look in: *HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*   
and for win 64 machine it will look in *HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon.*

Currently, it is not supported to configure Endpoint Connect to look in a different place.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
