Re: Server certificate instance refuses
From: krish shenoy[MS] (kshenoy_at_online.microsoft.com)
Date: 06/26/03
- Next message: e-head: "Is Global Catalog Server Required for login to Single Domain Trees ?"
- Previous message: Allyn Llyr: "Outlook express on windows 2000"
- In reply to: Arek Lichwa: "Server certificate instance refuses"
- Next in thread: Arek Lichwa: "Re: Server certificate instance refuses"
- Reply: Arek Lichwa: "Re: Server certificate instance refuses"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 26 Jun 2003 10:19:40 -0700
1) The Server certificate should chain up to a trusted root on the client
machine
2) The client certificate should chain up to a trusted root on the server
machine
The easiest way to verify this is to export the cert to a file and copy it
to the other machine and see if it chains correctly
If you have added some trusted roots for the current user then make sure
that the same roots are also added to the local machine trusted root store
since SSL will use the local machine context and not the current user
context
-- This posting is provided "AS IS" with no warranties and confers no rights. Use of any included samples is subject to the terms specified at http://www.microsoft.com/info/copyright.htm" "Arek Lichwa" <arek_lichwa@yahoo.com> wrote in message news:ex5w6h#ODHA.1072@TK2MSFTNGP10.phx.gbl... > Hello! > I got a warning message in eventlog (win2000 server) > "the server certificate for instance '72' does not chain up to a trusted > root certificate" > It happens when client application with own certificate trying to connect to > aspx application (the aspx script enforces SSL 128bit encyption and requires > client certificate) on server 72 instance and web server refuses connection > with http403 error (exactly refuses the client certificate) > > I'd appriciate for any help or any pointings > with kind regards Arek > >
- Next message: e-head: "Is Global Catalog Server Required for login to Single Domain Trees ?"
- Previous message: Allyn Llyr: "Outlook express on windows 2000"
- In reply to: Arek Lichwa: "Server certificate instance refuses"
- Next in thread: Arek Lichwa: "Re: Server certificate instance refuses"
- Reply: Arek Lichwa: "Re: Server certificate instance refuses"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|