| Previous | Next |
| ERROR_IPSEC_IKE_CRL_FAILED | ERROR_IPSEC_IKE_INVALID_CERT_TYPE |
ERROR_IPSEC_IKE_INVALID_KEY_USAGE
ERROR_IPSEC_IKE_INVALID_KEY_USAGE means the certificate may be valid and trusted but lacks a key-usage extension appropriate for the IKE authentication operation.
Trust-chain success does not make the certificate usable for IKE. Compare the certificate template and usage extensions with a known working machine certificate before changing tunnel rules or revocation settings.
What to check
- Inspect Key Usage and Enhanced Key Usage extensions on the machine certificate.
- Compare the deployed certificate template with the authentication method required by the IPsec rule.
- Replace or reenroll the certificate rather than trying to override certificate constraints in the tunnel policy.
Microsoft: IKE/AuthIP authentication methods
Looking for a different code? Search another status or error code.
