> Source: [sk178727](https://support.checkpoint.com/results/sk/sk178727)

# sk178727 - Remote Access VPN Client with certificate authentication fails to connect with "Internal error" message on Windows 11/10

| Property | Value |
|----------|-------|
| Solution ID | sk178727 |
| Date Created | 2022-04-13 |
| Last Modified | 2024-09-11 |
| Technical Level | Advanced |
| Products | Security Gateway, Endpoint Security |
| Versions | R82.10, R82, R81.20, Cloud, E89.X, E88.X |

## Symptoms

- * Remote Access VPN Client on Windows 11 fails to connect using certificate and shows the message:

  *Internal error; connection failed. More details may be available in the logs*
* The *trac.log* file contains this error:

  `[IKE] create_MM5(certificates authentication): Failed to sign hash (-996)`  
  `
  [rais] [DEBUG] [RaisMessages::CreateMessageSet(s)] message:`  
  ` (msg_obj`  
  `
  :format (1.0)`  
  `
  :id (ClipsMessagesInternalError)`  
  `
  :def_msg ("Internal error; connection failed. More details may be available in the logs")`  
  `
  :arguments ()`  
  `
  )`
* The *trac_capi.log* file shows:

  ```
  
  [] fwCAPIPubKey_imp::Init2(BSTR pszProvider, BSTR bstrContainerName): Call to CryptAcquireContextW failed.
  
  [] Key not valid for use in specified state.

  
  �(0x8009000b)
  ```

## Cause

The Windows API function `CryptAcquireContext` fails to decrypt a private key associated with the user's certificate. This can happen after the user changes his domain account password.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
