| Previous | Next |
| ERROR_IPSEC_IKE_INVALID_AUTH_ALG | ERROR_IPSEC_IKE_LOAD_FAILED |
ERROR_IPSEC_IKE_INVALID_SIG
ERROR_IPSEC_IKE_INVALID_SIG (0x00003633) Windows could not validate the certificate signature used in the IKE exchange. This can be caused by an invalid certificate chain, an incompatible signature algorithm, a corrupted certificate, or a peer that selected the wrong certificate.
What to check
- Verify the peer certificate chain, validity period, issuer trust, EKU, and private-key association.
- Confirm that the certificate signature algorithm is accepted by the current Windows and IPsec policy.
- Check revocation availability separately; an invalid signature and a failed CRL check are different conditions.
certutil -store my
Microsoft: Remote Access and Always On VPN troubleshooting
Microsoft: IKE authentication method types
Microsoft: IPsec/IKE system error codes
Looking for a different code? Search another status or error code.