Some time ago, with cfengine-3.3.5 clients I started getting this error server side:
Jan 2 10:26:33 serv cf3[7732]: Private decrypt failed = padding check failed
Jan 2 10:29:15 serv cf3[7732]: Private decrypt failed = block type is not 02
Jan 2 10:31:47 serv cf3[7732]: Private decrypt failed = padding check failed
The clients could no longer authenticate themselves against the server, and became isolated. I was not able to determine reasons of the error, which seems to happen randomly, at any time, even without policies update. Operating system, architecture, ip subnet didn’t matter in occurrence of the problem.