Schannel
31 events across 1 channel
Event ID 36864 — The schannel security package has loaded successfully.
Description
The schannel security package has loaded successfully.
Message #
Event ID 36865 — A fatal error occurred while opening the system ModuleName cryptographic module.
Event ID 36867 — Creating a TLS Type credential.
Event ID 36868 — The TLS Type credential's private key has the following properties.
Description
The TLS Type credential's private key has the following properties.
Message #
Fields #
| Name | Description |
|---|---|
Type UnicodeString | — |
CSPName UnicodeString | — |
CSPType UInt32 | — |
KeyName UnicodeString | — |
KeyType UnicodeString | — Known values
|
KeyFlags HexInt32 | — |
__binLength UInt32 | — |
EncodedCert Binary | — |
Event ID 36869 — The TLS Type credential's certificate does not have a private key information property attached to it.
Event ID 36870 — A fatal error occurred when attempting to access the TLS Type credential private key.
Description
A fatal error occurred when attempting to access the TLS Type credential private key. The error code returned from the cryptographic module is ErrorCode. The internal error state is ErrorStatus.
Message #
Fields #
| Name | Description |
|---|---|
CallerProcessId UInt32 | — |
CallerProcessImageName UnicodeString | — |
Type UnicodeString | — |
ErrorCode HexInt32 | — |
ErrorStatus UInt32 | — |
Event ID 36871 — A fatal error occurred while creating a TLS Type credential.
Event ID 36872 — The TLS Type specified certificate's chain could not be retrieved.
Event ID 36873 — No supported cipher suites were found when initiating a TLS connection.
Event ID 36874 — An Protocol connection request was received from a remote client application, but none of the cipher suites supported by the client application are suppo...
Event ID 36875 — The remote server has requested TLS client authentication, but no suitable client certificate could be found.
Event ID 36876 — The certificate received from the remote server has not validated correctly.
Description
The certificate received from the remote server has not validated correctly. The error code is ErrorCode. The TLS connection request has failed. The attached data contains the server certificate.
Message #
Fields #
| Name | Description |
|---|---|
CallerProcessId UInt32 | — |
CallerProcessImageName UnicodeString | — |
ErrorCode HexInt32 | — |
__binLength UInt32 | — |
pCertificateContext Binary | — |
Event ID 36877 — The certificate received from the remote client application has not validated correctly.
Description
The certificate received from the remote client application has not validated correctly. The error code is ErrorCode. The attached data contains the client certificate.
Message #
Fields #
| Name | Description |
|---|---|
CallerProcessId UInt32 | — |
CallerProcessImageName UnicodeString | — |
ErrorCode HexInt32 | — |
__binLength UInt32 | — |
pCertificateContext Binary | — |
Event ID 36878 — The certificate received from the remote client application is not suitable for direct mapping to a client system account, possibly because the aut...
Event ID 36879 — The certificate received from the remote client application was not successfully mapped to a client system account.
Event ID 36880 — A TLS Type handshake completed successfully.
Description
A TLS Type handshake completed successfully. The negotiated cryptographic parameters are as follows.
Message #
Fields #
| Name | Description |
|---|---|
Type UnicodeString | — |
Protocol UnicodeString | — Known values
|
CipherSuite HexInt32 | — |
ExchangeStrength UInt32 | — |
ContextHandle Pointer | — |
TargetName UnicodeString | — |
LocalCertSubjectName UnicodeString | — |
RemoteCertSubjectName UnicodeString | — |
Event ID 36881 — The certificate received from the remote server has either expired or is not yet valid.
Description
The certificate received from the remote server has either expired or is not yet valid. The TLS connection request has failed. The attached data contains the server certificate.
Message #
Fields #
| Name | Description |
|---|---|
CallerProcessId UInt32 | — |
CallerProcessImageName UnicodeString | — |
__binLength UInt32 | — |
certificateContext Binary | — |
Event ID 36882 — The certificate received from the remote server was issued by an untrusted certificate authority.
Event ID 36883 — The certificate received from the remote server has been revoked.
Event ID 36884 — The certificate received from the remote server does not contain the expected name.
Event ID 36885 — When asking for client authentication, this server sends a list of trusted certificate authorities to the client.
Event ID 36886 — No suitable default server credential exists on this system.
Message #
Fields #
| Name | Description |
|---|---|
CallerProcessId UInt32 | — |
CallerProcessImageName UnicodeString | — |
Example Event #
{
"system": {
"provider": "Schannel",
"guid": "1F678132-5938-4686-9FDC-C8FF68F15C85",
"event_source_name": "",
"event_id": 36886,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T17:05:18.904081+00:00",
"event_record_id": 10649,
"correlation": {},
"execution": {
"process_id": 908,
"thread_id": 3272
},
"channel": "System",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"CallerProcessId": 908,
"CallerProcessImageName": "lsass"
},
"message": ""
}
Event ID 36887 — A fatal alert was received from the remote endpoint.
Event ID 36888 — A fatal alert was generated and sent to the remote endpoint.
Description
A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal alert code is AlertDesc.
Message #
Fields #
| Name | Description |
|---|---|
CallerProcessId UInt32 | — |
CallerProcessImageName UnicodeString | — |
AlertDesc UInt32 | — |
ErrorState UInt32 | — |
TargetName UnicodeString | — |
Event ID 36889 — The TLS Type specified certificate's chain is incomplete.
Event ID 36896 — Verification of the DTLS connection request failed.
Event ID 36897 — DTLS record was rejected because it is outside of current receive window.
Event ID 36898 — A DTLS record was rejected because it is a duplicate of a previously received record.
Event ID 36899 — The retransmission of DTLS handshake messages has been requested.
Event ID 36912 — The key material used to protect TLS Session Tickets was not found at Path.
Event ID 36928 — Could not retrieve an OCSP response.
Description
Could not retrieve an OCSP response.
Message #
Fields #
| Name | Description |
|---|---|
FailureReason UnicodeString | — Known values
|
OCSPResponderURL UnicodeString | — |
ThisUpdate FILETIME | — |
NextUpdate FILETIME | — |
Binary | — |
__binLength UInt32 | — |
Certificate Binary | — |
Example Event #
{
"system": {
"provider": "Schannel",
"guid": "1F678132-5938-4686-9FDC-C8FF68F15C85",
"event_source_name": "",
"event_id": 36928,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T20:17:39.780304+00:00",
"event_record_id": 11772,
"correlation": {},
"execution": {
"process_id": 968,
"thread_id": 9364
},
"channel": "System",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"FailureReason": "REASON_OCSP_RESPONSE_RETRIEVAL_ERROR",
"OCSPResponderURL": "",
"ThisUpdate": "1601-01-01T00:00:00.000000Z",
"NextUpdate": "1601-01-01T00:00:00.000000Z",
"Binary": "308205F9308204E1A00302010202134A000000035FD5C8BB1377E3DC000000000003300D06092A864886F70D01010B0500304831163014060A0992268993F22C6401191606646F6D61696E31153013060A0992268993F22C64011916056C75647573311730150603550403130E45767447656E2D526F6F742D4341301E170D3236303331333230303733395A170D3237303331333230303733395A302431223020060355040313194A442D444330312D323032322E6C756475732E646F6D61696E30820122300D06092A864886F70D01010105000382010F003082010A0282010100C4B1FD366773339375612C77C34FBD4CDD44EBD501E531E6058A81A0531722310F4627071E1692851CAEE5AC56F5DF67F22AA9F06228FE17601C39735A653ABFE74AA8BFF89372359D81AED66FCE0EAAB2F46948D40E71E354404EB95B9C061A1D5FB2933F2D51AAA451815060AA57444EF2525571CE1C0FBDCE9A31FB8807EBE800B14D6F59D60801A58FABF0E0F75AFF73469D8880DBAAE43372F36E9849A732B0C22831F751FBFD1CE2E6D820B3CDFCABC5B10041119C3D7026781A37D5EE30248040A05E2CD89A972F8445D2F51646EE79A779D07429E887BDA9B145130DD467528838F7FE67A3AE5CCFC5A0A6743E34BF2713C362B3301746F8291A456D0203010001A38202FE308202FA302F06092B060104018237140204221E200044006F006D00610069006E0043006F006E00740072006F006C006C00650072301D0603551D250416301406082B0601050507030206082B06010505070301300E0603551D0F0101FF0404030205A0307806092A864886F70D01090F046B3069300E06082A864886F70D030202020080300E06082A864886F70D030402020080300B060960864801650304012A300B060960864801650304012D300B0609608648016503040102300B0609608648016503040105300706052B0E030207300A06082A864886F70D0307301D0603551D0E041604144CE17D561682CA51E7F0A2BE202C6517B6E3AA87301F0603551D2304183016801410FD42F39AB3CAE296A84658AF42919D14C50F273081D20603551D1F0481CA3081C73081C4A081C1A081BE8681BB6C6461703A2F2F2F434E3D45767447656E2D526F6F742D43412C434E3D4A442D444330312D323032322C434E3D4344502C434E3D5075626C69632532304B657925323053657276696365732C434E3D53657276696365732C434E3D436F6E66696775726174696F6E2C44433D6C756475732C44433D646F6D61696E3F63657274696669636174655265766F636174696F6E4C6973743F626173653F6F626A656374436C6173733D63524C446973747269627574696F6E506F696E743081C106082B060105050701010481B43081B13081AE06082B060105050730028681A16C6461703A2F2F2F434E3D45767447656E2D526F6F742D43412C434E3D4149412C434E3D5075626C69632532304B657925323053657276696365732C434E3D53657276696365732C434E3D436F6E66696775726174696F6E2C44433D6C756475732C44433D646F6D61696E3F634143657274696669636174653F626173653F6F626A656374436C6173733D63657274696669636174696F6E417574686F7269747930450603551D11043E303CA01F06092B0601040182371901A01204105B087A99015E754F9C22ED3AF23D348A82194A442D444330312D323032322E6C756475732E646F6D61696E300D06092A864886F70D01010B05000382010100638B3F6E62AA8ED007E58BA1EA5F2C919468F02B0BD1385ACB7189AEE00AE3E6A33D69A7C9A745323F20460348EADDE8AA2C92A8A5D886B89C3D59E36BB25327D490FDAE6CF2EF9ED499BA40C647616CD66BC1EC0415CA48F041EA053FBE5A7F44B2D8708A2BE2C7887AB45A0A9C8DFD51C0A1B2D051085612B7F78ED658741FD0C7FB08410A03050D3AF8E996420A5109B7932EC966074431ADA5F9A51C3C01D376CB68DC3FBAE1125B20A077B2835201328DA641344E31529357E2A9EE7980B35EC6F7F4D1F28F136309C7A2CFFFD24A059D023F7F48242D039504F67A9011C4C32A21BEC6E15CB6DDCADB59B95661C6546935C1D5640BB5F4F4DAA76C182F"
},
"message": ""
}