403.13 error due to? Changing machine name?

From: David Carr (David_Carr_at_NoSpamCanada.Com)
Date: 06/28/05


Date: Mon, 27 Jun 2005 17:25:59 -0700

Hi there,

PC: Win2K Pro sp4 machine running IIS 5

Some weeks ago, I was setting things up to understand the use of
certificates. A server certificate was installed, the Authentication
Methods dialog had everything (i.e. Anonymous and Integrated) unchecked, and
the Secure Communications dialog was changed to
- Require secure channel,
- Accept client certificates, and
- Enable client certificate mapping

For the latter, as a test, a Many-To-1 mapping of any certificate with a
location of 'Vancouver' was mapped to my personal account.

So back then, things seemed to be working as expected, including updating a
CRL generated by a stand-alone CA on a Win2K Server that is in-house.

Now, I always get the error 'HTTP 403.13 - Forbidden: Client certificate
revoked'. Over these weeks I can't remember everything that has happened,
but the only thing that stands out is that I changed the name of my PC.

Thinking that this might be a problem, I have deleted the old server
certificate (which referenced the old name) and obtained a new one from the
CA. The mapping also used the username as OLDMACHINENAME\USER, so this was
updated to reflect the new machine name. I also obtained a new client
certificate through IE.

Unfortunately, none of this has helped and I continue to get the 403.13
error.

If anyone has any suggestion, that would be most appreciated.

Best regards,
David



Relevant Pages

  • RPC over HTTP, Microsoft solution
    ... Exchange Server 2003 RPC over HTTP Deployment Scenarios ... Place a check in the box next to 'Certificate Services' and click 'Yes' ...
    (microsoft.public.exchange.setup)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)
  • Re: Configuring SBS2003 for OWA and RWW
    ... And make sure certificate will not be ... On the Connection Type page, click Broadband, and then click Next. ... next to Preferred DNS server and next to ... If you are using ISA, please go to ISA management console, and navigate ...
    (microsoft.public.windows.server.sbs)
  • Re: Configuring LDAP on Entourage 2004 OS X
    ... Microsoft CSS Online Newsgroup Support ... does not work with a self signed SSL certificate OR with the SSL ... configure the System to allow OMA and "Server ActiveSync" access from the ... Configuring Exchange Server 2003 for Client Access. ...
    (microsoft.public.windows.server.sbs)
  • Re: require client certificates SSL
    ... You can set up your own CA server and issue client authentication ... Best Practices for Implementing a Microsoft Windows Server2003 Public Key ... Implementing and Administering Certificate Templates in Windows Server ... Choose for require client certificates. ...
    (microsoft.public.inetserver.iis.security)