Microsoft-Windows-RasSstp
27 events across 1 channel
Event ID 1: CoId=.
#Description
CoId=CoId:The initial Secure Socket Tunneling Protocol request could not be successfully sent to the server. This can be due to network connectivity issues or certificate (trust) issues. The detailed error message is provided below. Correct the problem and try again. ErrorMessage
Message #
Fields #
| Name | Description |
|---|---|
CoId UnicodeString | |
ErrorMessage UnicodeString |
Event ID 2: CoId=.
#Description
CoId=CoId:The initial Secure Socket Tunneling Protocol (SSTP) response could not be received. There might be intermittent network connectivity issues or the server might not be accepting SSTP connections. The detailed error message is provided below. Correct the problem and try again. ErrorMessage
Message #
Fields #
| Name | Description |
|---|---|
CoId UnicodeString | |
ErrorMessage UnicodeString |
Event ID 3: CoId=.
#Description
CoId=CoId:The HTTP response received from the server-side Secure Socket Tunneling Protocol (SSTP) either does not have the version information or the version is not supported. The HTTP version information received is logged in the data section below. The HTTP response from the SSTP server must contain the version header and the version must be 1.1.
Message #
Fields #
| Name | Description |
|---|---|
CoId UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 4: CoId=.
#Description
CoId=CoId:The server has refused the Secure Socket Tunneling Protocol (SSTP) request. Either a failure response code or no response code was received. The data portion below contains the response code that was received from the server. This is the HTTP status code present in the response. It can be because the web proxy or the SSTP server might be rejecting the connection, the server might not be configured for SSTP or the server might not have a port available for connection.
Message #
Fields #
| Name | Description |
|---|---|
CoId UnicodeString | |
HTTPResponseCode UnicodeString |
Event ID 5: CoId=CoId:The Secure Socket Tunneling Protocol (SSTP) negotiation has failed.
#Event ID 6: CoId=.
#Description
CoId=CoId:The SSTP-based VPN connection to the remote access server was terminated because of a security check failure. Security settings on the remote access server do not match settings on this computer. Contact the system administrator of the remote access server and relay the following information: SHA1 Certificate Hash: SHA1CertificateHash SHA256 Certificate Hash: SHA256CertificateHash
Message #
Fields #
| Name | Description |
|---|---|
CoId UnicodeString | |
SHA1CertificateHash UnicodeString | |
SHA256CertificateHash UnicodeString |
Event ID 7: The Secure Socket Tunneling Protocol service could not open the ConfigStore that is used for storing service-specific information.
#Event ID 8: The Secure Socket Tunneling Protocol (SSTP) service could not initialize the HTTP layer for setting up the configuration.
#Event ID 9: The Secure Socket Tunneling Protocol service could not secure the URL with the new service configuration.
#Description
The Secure Socket Tunneling Protocol service could not secure the URL with the new service configuration. Other applications or services can override the URL reservation. Use 'netsh.exe http add urlacl' command to secure the access control list (ACL) manually. The detailed error message is given at the end of this message. URL: Url ErrorMessage
Message #
Fields #
| Name | Description |
|---|---|
Url UnicodeString | |
ErrorMessage UnicodeString |
Event ID 10: The Secure Socket Tunneling Protocol service could not secure the default URL.
#Description
The Secure Socket Tunneling Protocol service could not secure the default URL. This can prevent the servicing of the SSTP modules. Use 'netsh.exe http add urlacl' command to secure the ACL manually. The detailed error message is given at the end of this message. URL: Url ErrorMessage
Message #
Fields #
| Name | Description |
|---|---|
Url UnicodeString | |
ErrorMessage UnicodeString |
Event ID 11: The Secure Socket Tunneling Protocol (SSTP) service could not find either a Server Authentication certificate or an Any Purpose certificate to be u...
#Description
The Secure Socket Tunneling Protocol (SSTP) service could not find either a Server Authentication certificate or an Any Purpose certificate to be used for HTTPS. Check to see the availability of either a Server Authentication certificate or an Any Purpose certificate which also has a private key. SSTP sessions may not get established. Use ‘netsh.exe http add sslcert’ command to configure the certificate manually or install the appropriate certificate for SSTP use and restart RemoteAccess service.
Message #
Event ID 12: The Secure Socket Tunneling Protocol service could not configure the following certificate for use with Internet Protocol version 4 (IPv4).
#Description
The Secure Socket Tunneling Protocol service could not configure the following certificate for use with Internet Protocol version 4 (IPv4). This might prevent SSTP connections from being established successfully. Correct the problem and try again. Certificate Name - CertificateName ErrorMessage
Message #
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
CertificateName UnicodeString |
Event ID 13: The Secure Socket Tunneling Protocol service could not configure the following certificate for use with Internet Protocol version 6 (IPv6).
#Description
The Secure Socket Tunneling Protocol service could not configure the following certificate for use with Internet Protocol version 6 (IPv6). This might prevent SSTP connections from being established successfully. Correct the problem and try again. Certificate Name - CertificateName ErrorMessage
Message #
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
CertificateName UnicodeString |
Event ID 14: The Secure Socket Tunneling Protocol service could not configure the route to the VPN server, which is required for the proper functioning of the V...
#Description
The Secure Socket Tunneling Protocol service could not configure the route to the VPN server, which is required for the proper functioning of the VPN connection. The detailed error message is given below. Correct the problem and try again. ErrorMessage
Message #
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString |
Event ID 15: The Secure Socket Tunneling Protocol service could not get the network address of the remote server.
#Description
The Secure Socket Tunneling Protocol service could not get the network address of the remote server. This address is required for establishing the route for redirecting the traffic over the VPN interface. The detailed error message is provided below. Correct the problem and try again. ErrorMessage
Message #
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString |
Event ID 16: CoId=.
#Description
CoId=CoId:The Secure Socket Tunneling Protocol server has provided a certificate with an Enhanced Key Usage that is neither Server Authentication nor Any Purpose. This client will not accept the certificate. The connection will be canceled. Contact the server administrator to correct the issue and try again.
Message #
Fields #
| Name | Description |
|---|---|
CoId UnicodeString | |
ErrorMessage UnicodeString |
Event ID 17: The Secure Socket Tunneling Protocol service could not open the Parameters section of the registry to read the configuration values, so SSTP cannot...
#Description
The Secure Socket Tunneling Protocol service could not open the Parameters section of the registry to read the configuration values, so SSTP cannot be initialized. The detailed error message is provided below. Correct the problem and try again. ErrorMessage
Message #
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString |
Event ID 18: The Secure Socket Tunneling Protocol service either could not read the SHA256 certificate hash from the registry or the data is invalid.
#Description
The Secure Socket Tunneling Protocol service either could not read the SHA256 certificate hash from the registry or the data is invalid. To be valid, the SHA256 certificate hash must be of type REG_BINARY and 32 bytes in length. SSTP might not be able to retrieve the value from the registry due to some other system failure. The detailed error message is provided below. SSTP connections will not be accepted on this server. Correct the problem and try again. ErrorMessage
Message #
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString |
Event ID 19: The Secure Socket Tunneling Protocol service either could not read the SHA1 certificate hash from the registry or the data is invalid.
#Description
The Secure Socket Tunneling Protocol service either could not read the SHA1 certificate hash from the registry or the data is invalid. To be valid, the SHA1 certificate hash must be of type REG_BINARY and 20 bytes in length. SSTP might not be able to retrieve the value from the registry due to some other system failure. The detailed error message is provided below. SSTP connections will not be accepted on this server. Correct the problem and try again. ErrorMessage
Message #
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString |
Event ID 20: The Secure Socket Tunneling Protocol service was not able to allocate memory for setting up the configuration for accepting connections.
#Event ID 21: The Secure Socket Tunneling Protocol service was not able to get the hash for the certificate configured with HTTP.
#Event ID 22: The Secure Socket Tunneling Protocol service could not be configured to accept incoming connections.
#Event ID 23: CoId=.
#Description
CoId=CoId:The initial Secure Socket Tunneling Protocol request could not be successfully sent to the server. This can be due to the presence of a web proxy between the client and the server requiring authentication. Proxy authentication is not supported by this version of SSTP.
Message #
Fields #
| Name | Description |
|---|---|
CoId UnicodeString | |
ErrorMessage UnicodeString |
Event ID 24: The certificates bound to the HTTPS listener for IPv4 and IPv6 do not match.
#Description
The certificates bound to the HTTPS listener for IPv4 and IPv6 do not match. For SSTP connections, certificates should be configured for 0.0.0.0:Port for IPv4, and [::]:Port for IPv6. The port is the listener port configured to be used with SSTP. The default listener port is 443.
Message #
Event ID 25: The certificate used for Secure Socket Tunnelling Protocol (SSTP) is missing.
#Description
The certificate used for Secure Socket Tunnelling Protocol (SSTP) is missing. You should configure a new certificate for SSTP or use default configuration.
Message #
Event ID 32: The thumbprint (cert hash) of the certificate used for Secure Socket Tunnelling Protocol (SSTP) param1 is different than the certificate bound param2 to th...
#Description
The thumbprint (cert hash) of the certificate used for Secure Socket Tunnelling Protocol (SSTP) param1 is different than the certificate bound param2 to the Web listener (HTTP.sys). Configure SSTP to use the default certificate or the certificate bound to SSL. You can configure web server applications to use the same certificate used by SSTP
Message #
Fields #
| Name | Description |
|---|---|
param1 | |
param2 |
Event ID 33: CoId=CoId: ?
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 6c260f2c-049a-43d8-bf4d-d350a4e6611a
Defined in sstpsvc.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02