> Source: [sk183089](https://support.checkpoint.com/results/sk/sk183089)

# sk183089 - Capsule VPN certificate authentication fails using ICA

| Property | Value |
|----------|-------|
| Solution ID | sk183089 |
| Date Created | 2025-02-10 |
| Last Modified | 2025-02-12 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- * Capsule VPN for Android internal users tries to connect to the VPN site using a user certificate signed by the ICA of the Management server. The login fails with the message: `"Internal error occurred, if this error persists after application restart please contact your administrator."`
* Debug from the client shows:  

  `01-26 17:10:06.694 8139 2312 D NEMO.D 17:10:06.692 2ceecb0 ccc_server_rc_to_error: GW returned an unknown code = 599`  
  `01-26 17:10:06.694 8139 2312 E NEMO.E 17:10:06.692 2ceecb0 auth failed`  
  `01-26 17:10:06.694 8139 2312 E NEMO.E 17:10:06.692 2ceecb0 auth: ccc_auth_step failed: Internal error - [CCC_E_GENERAL] (1)`  
  `01-26 17:10:06.694 8139 2312 E NEMO.E 17:10:06.692 2ceecb0 auth: set error: Internal error - [CCC_E_GENERAL]`  

* Debug from the Security Gateway side shows:  

  `[vpnd PID]@vGW[DATE TIME][slim] CPRAS_Dispatcher_GetServiceData: Trying to get certificate DN from Kernel `  

  `[vpnd PID]@vGW[DATE TIME][AUTHENTICATION_MANAGER] handleFinishGetServiceDataAsyncCb: dn_str: CN=slavikm,OU=users,O=fwm.dpp.cz.camqod, strlen(dn_str): 39.`  

  `[vpnd PID]@vGW[DATE TIME][CLIENT_CONFIG] CCCMultiLoginOption::getRealmById: login option = vpn_Personal_Certificate_P12`  

  `[vpnd PID]@vGW[DATE TIME][CLIENT_CONFIG] CCCMultiLoginOption::isLoginOptionIDAllowed: vpn_Personal_Certificate_P12 allowed`  

  `[vpnd 21154 4066857408]@vfwso[26 Jan 17:10:06][AU] CAuthCertRules::GetUsernameFromCert (0x186e20c0): Could not extract user according to certificate attributes`

## Cause

The lookup of the internal user's certificate fails because the Security Gateway does not fetch the user from their Subject DN.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
