> Source: [sk183867](https://support.checkpoint.com/results/sk/sk183867)

# sk183867 - Endpoint VPN clients display error: Access denied: Wrong username and password - SmartConsole, the error shown is user is not allowed to use certificate

| Property | Value |
|----------|-------|
| Solution ID | sk183867 |
| Date Created | 2025-08-27 |
| Last Modified | 2025-09-03 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20 |
| OS | Gaia |

## Symptoms

- * Endpoint VPN clients display error: `Access denied: Wrong username and password`
* In SmartConsole, the error shown is `user is not allowed to use certificate.`
* On the Security Gateway, the following appears in the log file \`/var/log/iked.elg\`:   
  `[iked0]@usaaz[tunnel] MMProcess5Epilogue1: signatures not defined for user`  
  `[iked0]@usaaz MsgObj_vcumulate: Set= (msg_obj :format (1.0) :id `  
  `(CPSC_INTERNAL_ACCESS_DENIED) :def_msg ("Access denied - wrong user name or password ")
  :arguments ()
  )`

## Cause

The system blocks certificate authentication because the user is not configured for it.   

*Signature not defined for user* indicates that the certificate authentication is attempted for user that does not have it allowed.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
