The CA cert is installed in Trusted Root Authorities on the computer account on both the server and the client machine, and the client cert is installed in the Personal area Published (2013-05-14 09:41:15) http://support.microsoft.com/kb/2802568 Related threads on "Forums - IIS.net": HTTP Error 403.14 - Forbidden on IIS 8 server and Working... The client cert is signed directly by the root CA and as I said, both are valid. iis ssl certificate client-certificates share|improve this question edited Oct 8 '14 at 1:25 asked Oct 8 '14 at 0:36 Eric 39039 What about CRL? Source

I have deployed my configuration on a development machine and verified it working as expected there. Thanks! The issue now is that when I edit the CTL which runs the Certificate Trust List wizard to sign my CTL, the only option is "Select from Store..." and clicking on I have searched the solution. look at this web-site

403.16 2148204809

For your error case, if IIS is not configured to use a CTL, SSL client certificate authentication will fail with the 403.16 error condition. To do this, perform the following steps: Start the Default Domain Policy Group Policy Editor. Safari treats the request as mandatory. Another minor pt is Crypto API (used by IIS for cert verification) rejects certificates if the root certification authority certificates are not installed in the local computer Trusted Root Certification Authorities

  • Select 'Place all certificates in the following store' and click 'Browse...' Check 'Show physical stores' Expand 'Trusted Root Certification Authorities' and select 'Local Computer'.

However after setting up on the server, whenever I navigate to the site and am prompted for the client cert, I select it and immediately get the 403.16 error. How do we prove that something is unprovable? In short, I believe acquiring a certificate that did only have Code Signing as an Enhanced Key Usage may help. Iis 403.16 2148204809 Verifies the value of the Enhanced Key Usage property, which must contain Code Signing and may also contain Lifetime Signing.

Fill in your details below or click an icon to log in: Email (required) (Address never made public) Name (required) Website You are commenting using your WordPress.com account. (LogOut/Change) You are 403.16 Iis 7 The suggested two solutions to solve are: The first solution is to clean up the Trusted Root Certification Authorities store (Local Machine) and remove all unnecessary certificates. Is there such thing as a "Black Box" that decrypts internet traffic? https://support.microsoft.com/en-us/kb/942061 Handlers for checkboxes to select various map features Have we attempted to experimentally confirm gravitational time dilation?

You can use a Windows PowerShell command to find certificates that are put in the Trusted Root Certification Authorities store incorrectly on the local computer. Http Error 403.16 - Forbidden Your Client Certificate Is Either Not Trusted Or Is Invalid. Click Next/Click Finish. The CA Root certificate is in the (local machine)/Trust Root Certification Authorities and the intermediate CA certificates (corresponding to the ID and Signing certs) are installed to (local machine)/Intermediate Trusted Root This can be done by adding this registry entry on the web server: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL Value name: SendTrustedIssuerList Value type:

403.16 Iis 7

Search Advanced search Search everywhere only in this thread Thread: HTTP Error 403.16 - Forbidden on IIS 8.0 Started 4 years, 1 month ago by Dan B I configured have a peek at these guys The failed requests log gives the error code 2148204809 and message "A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider." I have 403.16 2148204809 Any other EKUs are prohibited. Iis Ctl CA) store: Get-Childitem cert:\LocalMachine\root -Recurse | Where-Object {$_.Issuer -ne $_.Subject} | Move-Item -Destination Cert:\LocalMachine\CA According to KB 2801679: SSL/TLS communication problems after you install KB 931125, you might also have too

Show more post info Size: 664 bytes Customize: Reply 5: HTTP Error 403.16 - Forbidden on IIS 8.0 SilentDeuce replied 3 years, 6 months ago http://support.microsoft.com/kb/2802568 Show more post info Size: this contact form Join them; it only takes a minute: Sign up Here's how it works: Anybody can ask a question Anybody can answer The best answers are voted up and rise to the Root) store can only have certificates that are self-signed. Apple may provide or recommend responses as a possible solution based on the information provided; every potential issue may involve several factors not detailed in the conversations captured in an electronic 403 16 Error

The problem was that I have 1 not self-signed certificate in trusted root authority. Register pressure in Compute Shader How did Smith get to see Cypher alone? I have on a Smart Card whose root and intermediate certificates I trust on the server 2. have a peek here Please type your message and try again.            gerryhung Level 1 (0 points) Q: HTTP Error 403.16 - Forbidden Your client certificate is either not trusted or is invalid.

Select 'Certificates', click 'Add >' and select 'Computer account' and then 'Local computer'. 403.16 Client Certificate Untrusted And the related intermediate ca has also installed. Join our community for more solutions or to ask questions.

share|improve this answer answered Oct 27 '14 at 14:36 Robert Pouleijn 1 add a comment| Your Answer draft saved draft discarded Sign up or log in Sign up using Google In that case, you may be able to regain access to the site in Safari by doing as follows.Back up all data.Double-click anywhere in the line below on this page to Here’s how to do it right. Error Code 403 16 You can Go to Solution 6 5 2 Participants James Clark(6 comments) btan(5 comments) LVL 61 Network Security24 Web Development7 MS Development-Other3 11 Comments Message Author Comment by:James Clark2014-08-06 Comment

How?? –Shubh Apr 18 at 12:00 See superuser.com/questions/647036/… –PeterStevenson Apr 19 at 13:33 add a comment| protected by Community♦ Jul 28 at 16:25 Thank you for your interest in Factorial digit sum Airliner takes off from JFK in 1966, gets stuck in time warp and lands in London in 2016 Is there a rule that makes particular kind of weapons Browse other questions tagged iis ssl certificate client-certificates or ask your own question. http://bookmarq.net/http-error/http-error-403-14-forbidden-iis-7-5.php Click Next/Click Finish.

