Security certificate validation fails - Windows Server (2024)

  • Article

This article provides workarounds for an issue where security certificate that's presented by a website isn't issued when it has multiple trusted certification paths to root CAs.

Original KB number: 2831004

Symptoms

When a user tries to access a secured website, the user receives the following warning message in the web browser:

There is a problem with this website's security certificate.

The security certificate presented by this website was not issued by a trusted certificate authority.

After the user clicks Continue to this website (not recommended), the user can access the secured website.

Cause

This issue occurs because the website certificate has multiple trusted certification paths on the web server.

For example, assume that the client computer that you're using trusts Root certification authority (CA) certificate (2). And the web server trusts Root CA certificate (1) and Root CA certificate (2). Additionally, the certificate has the following two certification paths to the trusted root CAs on the web server:

  1. Certification path 1: Website certificate - Intermediate CA certificate - Root CA certificate (1)
  2. Certification path 2: Website certificate - Intermediate CA certificate - Cross root CA certificate - Root CA certificate (2)

When the computer finds multiple trusted certification paths during the certificate validation process, Microsoft CryptoAPI selects the best certification path by calculating the score of each chain. A score is calculated based on the quality and quantity of the information that a certificate path can provide. If the scores for the multiple certification paths are the same, the shortest chain is selected.

When Certification path 1 and Certification path 2 have the same quality score, CryptoAPI selects the shorter path (Certification path 1) and sends the path to the client. However, the client computer can verify the certificate only by using the longer certification path that links to Root CA certificate (2). So the certificate validation fails.

Workaround

To work around this issue, delete or disable the certificate from the certification path that you don't want to use by following these steps:

  1. Log on to the web server as a system administrator.

  2. Add the Certificate snap-in to Microsoft Management Console by following these steps:

    1. Click Start > Run, type mmc, and then press Enter.
    2. On the File menu, click Add/Remove Snap-in.
    3. Select Certificates, click Add, select Computer account, and then click Next.
    4. Select Local computer (the computer this console is running on), and then click Finish.
    5. Click OK.
  3. Expand Certificates (Local Computer) in the management console, and then locate the certificate on the certificate path that you don't want to use.

    Note

    If the certificate is a root CA certificate, it is contained in Trusted Root Certification Authorities. If the certificate is an intermediate CA certificate, it is contained in Intermediate Certification Authorities.

  4. Delete or disable the certificate by using one of the following methods:

    • To delete a certificate, right-click the certificate, and then click Delete.
    • To disable a certificate, right-click the certificate, click Properties, select Disable all purposes for this certificate, and then click OK.
  5. Restart the server if the issue is still occurring.

Additionally, if the Turn off Automatic Root Certificates Update Group Policy setting is disabled or not configured on the server, the certificate from the certification path that you don't want to use may be enabled or installed when the next chain building occurs. To change the Group Policy setting, follow these steps:

  1. Click Start > Run, type gpedit.msc, and then press Enter.

  2. Expand Computer Configuration > Administrative Templates > System > Internet Communication Management, and then click Internet Communication settings.

  3. Double-click Turn off Automatic Root Certificates Update, select Enabled, and then click OK.

  4. Close the Local Group Policy Editor.

Status

This behavior is by design.

Security certificate validation fails - Windows Server (2024)
Top Articles
Top 5 Things You Should Never Do at an Auction - JD's Realty
Lowest Acceptable Bid Definition | Law Insider
NOAA: National Oceanic & Atmospheric Administration hiring NOAA Commissioned Officer: Inter-Service Transfer in Spokane Valley, WA | LinkedIn
Swimgs Yuzzle Wuzzle Yups Wits Sadie Plant Tune 3 Tabs Winnie The Pooh Halloween Bob The Builder Christmas Autumns Cow Dog Pig Tim Cook’s Birthday Buff Work It Out Wombats Pineview Playtime Chronicles Day Of The Dead The Alpha Baa Baa Twinkle
Uhauldealer.com Login Page
Chicago Neighborhoods: Lincoln Square & Ravenswood - Chicago Moms
Greedfall Console Commands
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
St Als Elm Clinic
How To Get Free Credits On Smartjailmail
Irving Hac
Mivf Mdcalc
Best Cav Commanders Rok
Southland Goldendoodles
Azeroth Pilot Reloaded - Addons - World of Warcraft
Wisconsin Women's Volleyball Team Leaked Pictures
About Us | TQL Careers
Craigslist Farm And Garden Cincinnati Ohio
Dtab Customs
All Obituaries | Buie's Funeral Home | Raeford NC funeral home and cremation
10 Fun Things to Do in Elk Grove, CA | Explore Elk Grove
18889183540
Marine Forecast Sandy Hook To Manasquan Inlet
Yisd Home Access Center
Everything To Know About N Scale Model Trains - My Hobby Models
Milwaukee Nickname Crossword Clue
Cardaras Funeral Homes
Culver's.comsummerofsmiles
Usa Massage Reviews
Jesus Calling Feb 13
Sacramento Craigslist Cars And Trucks - By Owner
Gt7 Roadster Shop Rampage Engine Swap
Gncc Live Timing And Scoring
Puffin Asmr Leak
Lawrence Ks Police Scanner
"Pure Onyx" by xxoom from Patreon | Kemono
The Menu Showtimes Near Amc Classic Pekin 14
Garrison Blacksmith's Bench
Edward Walk In Clinic Plainfield Il
The Bold And The Beautiful Recaps Soap Central
Wsbtv Fish And Game Report
Bones And All Showtimes Near Johnstown Movieplex
Search All of Craigslist: A Comprehensive Guide - First Republic Craigslist
Express Employment Sign In
Tsbarbiespanishxxl
Actor and beloved baritone James Earl Jones dies at 93
Alpha Labs Male Enhancement – Complete Reviews And Guide
Memberweb Bw
Sound Of Freedom Showtimes Near Amc Mountainside 10
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
Ty Glass Sentenced
Lorcin 380 10 Round Clip
Latest Posts
Article information

Author: Tuan Roob DDS

Last Updated:

Views: 5880

Rating: 4.1 / 5 (62 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Tuan Roob DDS

Birthday: 1999-11-20

Address: Suite 592 642 Pfannerstill Island, South Keila, LA 74970-3076

Phone: +9617721773649

Job: Marketing Producer

Hobby: Skydiving, Flag Football, Knitting, Running, Lego building, Hunting, Juggling

Introduction: My name is Tuan Roob DDS, I am a friendly, good, energetic, faithful, fantastic, gentle, enchanting person who loves writing and wants to share my knowledge and understanding with you.