> Source: [sk166972](https://support.checkpoint.com/results/sk/sk166972)

# sk166972 - Endpoint Security Client with machine certificate fails to connect to VPN Gateway with "Internal error" message

| Property | Value |
|----------|-------|
| Solution ID | sk166972 |
| Date Created | 2020-06-02 |
| Last Modified | 2022-09-08 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- * Endpoint Security Client fails to connect with the VPN Gateway and shows the following message: "`Internal error; connection failed. More details may be available in the logs`".
* trac log debugs shows the following error:

  ```
  
  [ 15252 23472][28 Apr 7:46:17][] fwCNGPubKey_imp::Sign_imp: about to CryptAcquireCertificatePrivateKey...
  
  
  
  
  [ 15252 23472][28 Apr 7:46:17][] fwCNGPubKey_imp::Sign_imp: Failed to acquire key handle with error code (0x80090016).
  
  
  
  
  [ 15252 23472][28 Apr 7:46:17][Rais_CAPICERT] Rais_CAPICERT::capi_cert_sign: Failed to sign Buffer
  ```

  <br />

## Cause

The error code is one of the CryptAcquireContext errors NTE_BAD_KEYSET (0x80090016). This could happen if:   

* Key container does not exist.
* There is no access to the key container.
* The Protected Storage Service is not running.
* The certificate has expired.

For more information, click [here](https://support.microsoft.com/en-us/help/238187/cryptacquirecontext-use-and-troubleshooting).

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
