CCS_DataEncryptInit returned error code -1423

  • 3222407
  • 27-Feb-2007
  • 26-Apr-2012

Environment

Novell BorderManager 3.8

Situation

IKE log shows IKE_CCS_RSAPrivateKeyEncrypt: CCS_DataEncryptInit returned error code -1423
Site to Site VPN fails to work
VPN error 1423
Trusted Root Objects were created with Console One and not iManager.
Trusted Root Objects for VPN are corrupt.

Resolution

Delete Trusted Root Object off the server that is giving you the 1423 error and re-import it with iManager.  To do this:

In iManager or Console one, browse to the container with your BorderManager server and find the "TRC - [servername]" container.  Go inside this trusted root container and find the Trusted Root object for the problem server and delete it. You should be able to tell this by the IKE loggiving you the 1423 error when trying to connect to this server.

  1. Open iManager.
  2. Select "Novell Certificate Server".
  3. Select "Create TrustedRoot".
  4. Choose a name to identify the server.
  5. Browse to the "TRC - [server name]" on the server and select it.
  6. Browse to the file of the exported server Certcertificate, from when you exported it the first time.
  7. Click "OK" - it should say "Complete Success".
  8. Click OK.