| Previous | Next |
| ERROR_IPSEC_IKE_TIMED_OUT | ERROR_IPSEC_IKE_SA_DELETED |
ERROR_IPSEC_IKE_NO_CERT
ERROR_IPSEC_IKE_NO_CERT means the local computer could not select a usable machine certificate for the IPsec authentication method. A certificate can exist but still be unusable because it is in the wrong store, expired, lacks the needed EKU, has no accessible private key, or is not trusted by the peer.
What to check
- Inspect the Local Computer certificate store, not only the current-user store.
- Verify validity dates, intended purpose/EKU, issuer trust and private-key availability.
- Make sure the IPsec rule selects certificate authentication and that its certificate requirements match the deployed template.
Microsoft: IKE/AuthIP authentication methods
Microsoft: Connection security rules
Microsoft: IPsec IKE system error codes
Looking for a different code? Search another status or error code.