Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > New "Root Certificates Update" stops web sites

Reply
Thread Tools Display Modes

New "Root Certificates Update" stops web sites

 
 
Brian W
Guest
Posts: n/a

 
      02-01-2007
The 01-29-2007 release of "Root Certificates Update" has stopped my Windows
Server 2003 SP1 certificate required web sites. In the DoD we require
certificate based access requirements for web sites and the latest root
certificates update seems like it may pose a big problem for the DoD.
Hopefully my issue is isolated to just my one server, which fortunately
happened to be a development server ... thus the test. My certificate store
went from 129 trusted root certificates to 230+. Below is the event log entry:

Event Type: Warning
Event Source: Schannel
Event Category: None
Event ID: 36885
Description: When asking for client authentication, this server sends a list
of trusted certificate authorities to the client. The client uses this list
to choose a client certificate that is trusted by the server. Currently, this
server trusts so many certificate authorities that the list has grown too
long. This list has thus been truncated. The administrator of this machine
should review the certificate authorities trusted for client authentication
and remove those that do not really need to be trusted.

My solution was to match the certificate store of another server and delete
all the new certificates added fro the new update. Anyone else having this
issue?

-brian-

 
Reply With Quote
 
 
 
 
mltllt@gmail.com
Guest
Posts: n/a

 
      02-01-2007
On Feb 1, 5:49 am, Brian W <Bri...@discussions.microsoft.com> wrote:
> The 01-29-2007 release of "Root Certificates Update" has stopped my Windows
> Server 2003 SP1 certificate required web sites. In the DoD we require
> certificate based access requirements for web sites and the latest root
> certificates update seems like it may pose a big problem for the DoD.
> Hopefully my issue is isolated to just my one server, which fortunately
> happened to be a development server ... thus the test. My certificate store
> went from 129 trusted root certificates to 230+. Below is the event log entry:
>
> Event Type: Warning
> Event Source:Schannel
> Event Category: None
> Event ID: 36885
> Description: When asking for client authentication, this server sends a list
> of trusted certificate authorities to the client. The client uses this list
> to choose a client certificate that is trusted by the server. Currently, this
> server trusts so many certificate authorities that the list has grown too
> long. This list has thus been truncated. The administrator of this machine
> should review the certificate authorities trusted for client authentication
> and remove those that do not really need to be trusted.
>
> My solution was to match the certificate store of another server and delete
> all the new certificates added fro the new update. Anyone else having this
> issue?
>
> -brian-


I had the same problem Brian.
My clients would not be prompted for their SmartCard (Cert) but
instead started gettting error 403.7
I searched for any information to try and resolve this, before I
finally came across the Event ID 36885 in the System event logs.
Once I fixed the problem I came across your post.
Hopefully others out there will find this helpful.
Matt


 
Reply With Quote
 
Greg
Guest
Posts: n/a

 
      02-02-2007
We also had the same problem. As you pointed out, the list is too large. We
"fixed" it by removing a lot of the foreign root trusts. All it did was cut
the list number down.

I hope MS is seeing this.

Greg

"Brian W" wrote:

> The 01-29-2007 release of "Root Certificates Update" has stopped my Windows
> Server 2003 SP1 certificate required web sites. In the DoD we require
> certificate based access requirements for web sites and the latest root
> certificates update seems like it may pose a big problem for the DoD.
> Hopefully my issue is isolated to just my one server, which fortunately
> happened to be a development server ... thus the test. My certificate store
> went from 129 trusted root certificates to 230+. Below is the event log entry:
>
> Event Type: Warning
> Event Source: Schannel
> Event Category: None
> Event ID: 36885
> Description: When asking for client authentication, this server sends a list
> of trusted certificate authorities to the client. The client uses this list
> to choose a client certificate that is trusted by the server. Currently, this
> server trusts so many certificate authorities that the list has grown too
> long. This list has thus been truncated. The administrator of this machine
> should review the certificate authorities trusted for client authentication
> and remove those that do not really need to be trusted.
>
> My solution was to match the certificate store of another server and delete
> all the new certificates added fro the new update. Anyone else having this
> issue?
>
> -brian-
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
A "USER" cannot install WGA through auto-update, this stops everyt Rob Windows Update 2 10-16-2006 05:16 PM
Windows Update stops at "Checking for the latest version..." fmfnavydoc Windows Update 1 02-24-2005 02:31 AM
Windows Update stops at "checking for latest version..." Brian Windows Update 3 08-29-2004 01:13 AM
Re: Root directory of SUS "C:\" cluttered with 100's of update directo Torgeir Bakken \(MVP\) Windows Update 0 07-27-2004 04:46 PM
Windows Update stops at the "downloading" bit - found fixes don't work Mark Hanford Windows Update 0 11-21-2003 01:19 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59