CHiLL Posted December 9, 2020 Posted December 9, 2020 (edited) We've been running Microsoft's Always-On VPN on a Server 2019 server for a while now and we've been encountering issues today. No clients can connect, throwing the following error message: IKE failed to find a valid machine certificate It's not the client laptop, because that only uses user certificates. When I checked the server, I noticed that the machine certificate has expired, specifically the certificate for the 'VPN Servers' template expired today. It expired today, which explains why users suddenly can't connect. The server has the following GPO applied: Computer Configuration > Policies > Windows Settings > Security Settings > Public Key Policies > Certificate Services Client - Auto-Enrollment Properties Configuration model: Enabled Renew expired certificates, update pending certificates, and remove revoked certificates: Enabled Update certificates that use certificate templates: Enabled With that policy, this VPN certificate should have automatically renewed itself, but I don't know why it hasn't. A GPResult shows that policy has applied and those settings are set. A server restart and gpupdate /force also hasn't fixed it. I can renew the certificate manually, but I want to get to the bottom of it, for when this happens next time the certificate renews. Has anyone come across this before? Edited December 9, 2020 by CHiLL
CHiLL Posted December 9, 2020 Author Posted December 9, 2020 After looking at the permissions on the certificate template, the VPN Servers group does not have auto-enroll checked, and all of the guides (Microsoft, Richard Hicks, 4SysOps, etc) leave it unchecked. I guess this is why it isn't re-enrolling? Is there a reason why we wouldn't want it to do this automatically and do you all have to do it manually?
3s-gtech Posted November 14, 2021 Posted November 14, 2021 @CHiLL How did you renew the cert? I've tried it from the certm console (and left the old one) but it's still not coming back up for clients (maybe they need to check in on the LAN first?)
3s-gtech Posted November 14, 2021 Posted November 14, 2021 @CHiLL How did you renew the cert? I've tried it from the certm console (and left the old one) but it's still not coming back up for clients (maybe they need to check in on the LAN first?) Think I’ve sorted it - I requested a new cert from the CA, set the CN and DNS fields as they were on the old one, renewed with the same Private Key, deleted the old cert and restarted RRAS.
CHiLL Posted November 26, 2021 Author Posted November 26, 2021 Think I’ve sorted it - I requested a new cert from the CA, set the CN and DNS fields as they were on the old one, renewed with the same Private Key, deleted the old cert and restarted RRAS. Sorry it's taken me so long to get back to you, I've had a lot on and no time to cast my mind back! I'm glad you sorted it...I think that's how I sorted but, but I'm honestly struggling to remember. 1
CHiLL Posted December 10, 2021 Author Posted December 10, 2021 This has just happened to us again - and looking at the date, it's exactly a year after it happened last time. So I've had to revisit it. I've found the same thing as you. On the VPN server, the machine certificate (from the VPN Servers template) expired on 9/12/2021. Like you, I renewed the certificate with the same private key and deleted the old certificate. Clients were then able to connect immediately. I'm not sure why this certificate isn't renewing automatically when it expires, despite the server having the Auto-Enrollment Settings GPO configured.
3s-gtech Posted December 10, 2021 Posted December 10, 2021 I've a feeling this is the one certificate that isn't set to auto-renew, from the guides that I followed a year or so ago. The clients do, the server doesn't. I'm not entirely sure how to remedy that, or if it's straightforward. It *may* be possible to do the old self-hosted CA fudge of setting the certificate validity period to 10 years on the template, but I haven't looked. 1
CHiLL Posted December 10, 2021 Author Posted December 10, 2021 Yeah and since the VPN is working, I don't particularly want to make any further changes to it's config!
3s-gtech Posted December 10, 2021 Posted December 10, 2021 Considering it felt like a great deal of luck on my side that actually got our AoVPN setup working (as well as some superb tutorials online) I'm about as willing to mess with it as I would be to kick a male grizzly between the legs.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now