Site icon EfmSoft

What does NTSTATUS 0xC00002F9 (STATUS_PKINIT_NAME_MISMATCH) mean?

 
Previous Next
STATUS_NO_PA_DATA STATUS_SMARTCARD_LOGON_REQUIRED

STATUS_PKINIT_NAME_MISMATCH

The PKINIT certificate identity does not match the user

PKINIT uses X.509 public-key data during the Kerberos initial authentication exchange. In Windows smart-card logon, the certificate must map to the account being authenticated; common mapping evidence includes the UPN in certificate extensions and, on updated domain controllers, strong certificate mapping requirements.

This status should be investigated as a certificate-to-account mapping problem, not as a PIN-only failure. The card can be readable and the private key can be usable while the certificate identity still fails the KDC name checks.

What to inspect

References


Looking for a different code? Search another status or error code.

Exit mobile version