Avatar of burny1
burny1
Flag for South Africa asked on

Problem connecting to VPN server via ssl

Hi all,

Since Apple decided to stop allowing PPTP, we had to reset our VPN server to use SSL / SSTP. I have set up the server as per the guidelines from Microsoft, however I am unable to connect to the server. I get the following error message: The revocation function was unable to check revocation because the revocation server is offline. I have checked all the services on the server and everything seems to be up and running. In the event viewer I get error 18:

The Secure Socket Tunneling Protocol service either could not read the SHA256 certificate hash from the registry or the data is invalid. To be valid, the SHA256 certificate hash must be of type REG_BINARY and 32 bytes in length. SSTP might not be able to retrieve the value from the registry due to some other system failure. The detailed error message is provided below. SSTP connections will not be accepted on this server. Correct the problem and try again.

The system cannot find the file specified.

I do not know which file it is looking for.
Remote AccessSSL / HTTPSNetworkingVPNWindows OS

Avatar of undefined
Last Comment
burny1

8/22/2022 - Mon
masnrock

Here's an article from Microsoft detailing which the key to look for and perhaps fix permissions on: https://technet.microsoft.com/en-us/library/dd315941(v=ws.10).aspx
burny1

ASKER
Apologies for only replying now - been out the office for the last week. Will check and revert.
burny1

ASKER
So I went to the registry, however when I click modify there is no option to change a value to 32. I attach screen shot of what comes up. Any ideas what I need to change?
hash.JPG
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
masnrock

Did you check the permissions?
burny1

ASKER
Yes I changed it. That was when I was able to click on modify.
masnrock

Great. Restart the machine and then try connecting again... What happens?
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
burny1

ASKER
Seems that the error is gone, however now I get a different error: The revocation function was unable to check revocation because the revocation server was offline.
masnrock

What is the name of the CRL file?
burny1

ASKER
Where would I fine the file?
Your help has saved me hundreds of hours of internet surfing.
fblack61
masnrock

Sorry... lost track of the question. Here's an article for you to check out: http://fix.lazyjeff.com/2014/05/revocation-function-was-unable-to-check.html
David Johnson, CD

if you inspect the certificate using the MMC or certmgr.exe , select extensions onlyMMC click on CRL distribution points and you will see the URL.
burny1

ASKER
thanks i will look at this and revert!
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
ASKER CERTIFIED SOLUTION
burny1

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
burny1

ASKER
Solutions offered did not work.