Site icon EfmSoft

What does Windows error code 13908 (ERROR_IPSEC_IKE_STRONG_CRED_AUTHORIZATION_AND_CERTMAP_FAILURE) mean?

 
Previous Next
ERROR_IPSEC_IKE_AUTHORIZATION_FAILURE_WITH_OPTIONAL_RETRY ERROR_IPSEC_IKE_NEG_STATUS_EXTENDED_END

ERROR_IPSEC_IKE_STRONG_CRED_AUTHORIZATION_AND_CERTMAP_FAILURE

ERROR_IPSEC_IKE_STRONG_CRED_AUTHORIZATION_AND_CERTMAP_FAILURE preserves two diagnostic signals. Windows could not authorize the Security Association because a sufficiently strong PKINIT-based credential was not available, and certificate-to-account mapping might also be involved. The combined name is not proof that both checks failed; it tells the investigator to examine both paths.

Certificate-to-account mapping is more than certificate-chain validation. In an IKE/AuthIP policy that uses mapping, the certificate is associated with a user or computer account in Active Directory so that Windows can obtain an access token and evaluate group-based authorization. A certificate can therefore be trusted and have a usable private key while still failing to identify the account required by the active rule.

Separate the two checks

Compared with ERROR_IPSEC_IKE_STRONG_CRED_AUTHORIZATION_FAILURE, this code adds certificate-to-account mapping as a possible second fault domain. Changing only the VPN address pool, traffic selector, or ESP cipher will not resolve either of those identity checks.

References


Looking for a different code? Search another status or error code.

Exit mobile version