> Source: [sk170140](https://support.checkpoint.com/results/sk/sk170140)

# sk170140 - Endpoint Security VPN clients with Machine Certificate Authentication fail to connect with "Internal error; connection failed. More details may be available in the logs"

| Property | Value |
|----------|-------|
| Solution ID | sk170140 |
| Date Created | 2020-10-19 |
| Last Modified | 2020-12-24 |
| Technical Level | Advanced |

## Symptoms

- * Endpoint Security VPN clients that use Machine Certificate authentication fail to connect.
* The end user sees this error in the GUI:  
  "`Internal error; connection failed. More details may be available in the logs" `.
* *trac.log* (client log) shows these lines:  
  `[RaisCertManager] RaisCertManager::_GenerateFriendlyNameWithSerial: ERROR!! subject or serial is empty, return empty string`  
  and these lines:  
  `[IKE] using machine cert: <unknown>`

  <br />

## Cause

The subject field in the certificate is empty.  

Per the [Remote Access VPN R80.40 Administration Guide](https://downloads.checkpoint.com/dc/download.htm?ID=82114) (page 113, under**Limitations**):
"The Subject field of a machine certificate must not be empty."

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
