Forum Discussion

nicholse's avatar
nicholse
Icon for Nimbostratus rankNimbostratus
Sep 08, 2026

APM 17.5.1.9 certcheck (failures, exceptions)

Since updating to 17.5.1.9 instead of getting debug\verbose level logging in f5mcertcheck.txt . I can no longer see details of the cert mapping progress which makes trouble shooting what is happening really difficult from the client side.


Info 2026-09-08 16:10:55:649 current log level = 63

Info 2026-09-08 16:10:55:649 \CertCheck.cpp, ::DllMain, ActiveX control location: "C:\Windows\Downloaded Program Files\f5certchk.dll"

Error 2026-09-08 16:10:56:160 CCertCheckImpl::Verify FindCertificateInStore failed with error code:

Error 2026-09-08 16:10:56:160 \CertCheckImpl.cpp, CCertCheckImpl::Verify, EXCEPTION caught: CCertCheckImpl::Verify - EXCEPTION


I know it found a working cert because its letting me connect but I need visibility into what certs it checked against what policy settings. Before this update I was able to see much more info example:



Info 2026-09-02 17:46:51:362 \CertCheck.cpp, ::DllMain, ActiveX control location: "C:\Windows\Downloaded Program Files\f5certchk.dll"

Info 2026-09-02 17:46:51:873 \CertCheckImpl.cpp, CCertCheckImpl::Verify, certInfo:STORE_NAME:MY&STORE_LOCATION:LocalMachine&ALLOW_ELEVATION:0&MATCH_FQDN:0&SN:&ISSUER:CN=MY Intermediate, O=*, OU=IT, L=Anytown, S=DC, C=US&SAN:, RootCertInfo:IS_TRUSTED:0, Nonce: QUFFM2ozcFVUU1BwZTVVUFRLdUs=

Info 2026-09-02 17:46:51:873 \CertCheckImpl.cpp, CCertCheckImpl::Verify, Store name:"MY", Store location:"LocalMachine", Subject match FQDN:"false", Allow elevation UI:"false", Serial number(HEX):"", Issuer:"CN=MY Intermediate, O=*, OU=IT, L=Anytown, S=DC, C=US", SubjectAltName:""

Info 2026-09-02 17:46:51:875 \certinfo.cpp, CCertInfo::FindCertificateInStoreExt:, Total certs tested: 5

Info 2026-09-02 17:46:51:875 \certinfo.cpp, CCertInfo::MatchCertificate, CN=MY Intermediate, O=Contoso, OU=IT, L=Anytown, S=DC, C=US doesn't match pattern "CN=MY Intermediate, O=*, OU=IT, L=Anytown, S=DC, C=US"

Info 2026-09-02 17:46:51:875 \certinfo.cpp, CCertInfo::MatchCertificate, CN=Microsoft Intune Device Management Device CA doesn't match pattern "CN=MY Intermediate, O=*, OU=IT, L=Anytown, S=DC, C=US"

Info 2026-09-02 17:46:51:875 \certinfo.cpp, CCertInfo::MatchCertificate, CN=Microsoft Intune MDM Device CA doesn't match pattern "CN=MY Intermediate, O=*, OU=IT, L=Anytown, S=DC, C=US"

Info 2026-09-02 17:46:51:875 \certinfo.cpp, CCertInfo::MatchCertificate, CN=MS-Organization-P2P-Access [2025] doesn't match pattern "CN=MY Intermediate, O=*, OU=IT, L=Anytown, S=DC, C=US"

Info 2026-09-02 17:46:51:875 \certinfo.cpp, CCertInfo::MatchCertificate, DC=net + DC=windows + CN=MS-Organization-Access + OU=82dbaca4-3e81-46ca-9c73-0950c1eaca97 doesn't match pattern "CN=MY Intermediate, O=*, OU=IT, L=Anytown, S=DC, C=US"

Info 2026-09-02 17:46:51:875 \certinfo.cpp, CCertInfo::FindCertificateInStoreExt:, Didn't find matched certificate

Info 2026-09-02 17:46:52:593 \CertCheckImpl.cpp, CCertCheckImpl::Verify, certInfo:STORE_NAME:MY&STORE_LOCATION:LocalMachine&ALLOW_ELEVATION:1&MATCH_FQDN:0&SN:&ISSUER:CN=MY Intermediate, O=Contoso, OU=IT, L=Anytown, S=DC, C=US&SAN:, RootCertInfo:IS_TRUSTED:0, Nonce: VkdCRko1WGJoYWVycmgxaDh1TDc=

Info 2026-09-02 17:46:52:593 \CertCheckImpl.cpp, CCertCheckImpl::Verify, Store name:"MY", Store location:"LocalMachine", Subject match FQDN:"false", Allow elevation UI:"true", Serial number(HEX):"", Issuer:"CN=MY Intermediate, O=Contoso, OU=IT, L=Anytown, S=DC, C=US", SubjectAltName:""

Info 2026-09-02 17:46:52:596 \certinfo.cpp, CCertInfo::MatchCertificate, CN=MY Intermediate, O=Contoso, OU=IT, L=Anytown, S=DC, C=US matches pattern CN=MY Intermediate, O=Contoso, OU=IT, L=Anytown, S=DC, C=US(extracted content="")

Info 2026-09-02 17:46:52:596 \certinfo.cpp, CCertInfo::FindCertificateInStoreExt:, Total certs tested: 1

Info 2026-09-02 17:46:52:596 \certinfo.cpp, CCertInfo::FindCertificateInStoreExt:, Found matched certificate

 

No RepliesBe the first to reply