{"id":1962,"date":"2017-03-22T07:24:20","date_gmt":"2017-03-22T07:24:20","guid":{"rendered":"http:\/\/obieta.com\/?p=1962"},"modified":"2017-03-22T07:24:20","modified_gmt":"2017-03-22T07:24:20","slug":"resolving-iis-403-17-issues","status":"publish","type":"post","link":"http:\/\/obieta.com\/?p=1962","title":{"rendered":"Resolving IIS 403.17 Issues"},"content":{"rendered":"<p>Windows 2012 introduced stricter certificate store validations. the Trusted Root Certification Authorities (i.e. Root) store can only have certificates that are self-signed. If that store contains non-self-signed certificates, client certificate authentication under IIS returns with a 403.16 error code.<\/p>\n<p>To solve the problem, you have to remove all non-self-signed certificates from the root store. This PowerShell command will identify non-self-signed certificates:<\/p>\n<pre><code>Get-Childitem cert:\\LocalMachine\\root -Recurse | \n    Where-Object {$_.Issuer -ne $_.Subject}\n<\/code><\/pre>\n<p>In my situation, we moved these non-self-signed certificates into the Intermediate Certification Authorities (i.e. CA) store:<\/p>\n<pre><code>Get-Childitem cert:\\LocalMachine\\root -Recurse | \n    Where-Object {$_.Issuer -ne $_.Subject} | \n    Move-Item -Destination Cert:\\LocalMachine\\CA\n<\/code><\/pre>\n<p>According to <a href=\"https:\/\/support.microsoft.com\/en-us\/kb\/2801679\">KB 2801679: SSL\/TLS communication problems after you install KB 931125<\/a>, you might also have too many trusted certificates.<\/p>\n<blockquote><p>[T]he maximum size of the trusted certificate authorities list that the Schannel security package supports is 16 kilobytes (KB). Having a large amount of Third-party Root Certication Authorities will go over the 16k limit, and you will experience TLS\/SSL communication problems.<\/p><\/blockquote>\n<p>The solution in this situation is to remove any certification authority certificates you don&#8217;t trust, or <a href=\"https:\/\/support.microsoft.com\/en-us\/kb\/2464556\">to stop sending the list of trusted certifiation authorities by setting the <code>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\@SendTrustedIssuerList<\/code> registry entry to 0<\/a> (the default, if not present, is 1).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Windows 2012 introduced stricter certificate store validations. the Trusted Root Certification Authorities (i.e. Root) store can only have certificates that are self-signed. If that store contains non-self-signed certificates, client certificate authentication under IIS returns with a 403.16 error code. To solve the problem, you have to remove all non-self-signed certificates from the root store. This [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"_links":{"self":[{"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/posts\/1962"}],"collection":[{"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/obieta.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1962"}],"version-history":[{"count":0,"href":"http:\/\/obieta.com\/index.php?rest_route=\/wp\/v2\/posts\/1962\/revisions"}],"wp:attachment":[{"href":"http:\/\/obieta.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1962"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/obieta.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1962"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/obieta.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1962"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}