IIS 7.0: Why does Require Client Certificates cause error 500 and "page cannot be displayed"

5,210

The solution can be found here and is related to MS KB977377. The choices are

  • Remove MS update KB977377

or

  • Change the vlaue of HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\DisableRenegoOnServer to 0
Share:
5,210

Related videos on Youtube

Greg Askew
Author by

Greg Askew

Zero stones? Zero crates!

Updated on September 17, 2022

Comments

  • Greg Askew
    Greg Askew almost 2 years

    I have two Windows 2008 x86 servers running IIS 7.0, one site on each server; both sites are SSL-enabled, using DoD-issued certificates. Both sites are accessible via https over port 443, but fail the moment Client Certificates are set to Require or Accept. IIS log records error 500.0.64 but nothing else.

    I have several Windows 2008 IIS 7 x64 servers that require client certificates and they are working as expected; it's just the two x86 servers that are being problematic.

    • Admin
      Admin almost 14 years
      Do you need client certificates? Your description sounds like you are just wanting SSL-encryption.
    • Admin
      Admin almost 14 years
      Yes, I need to configure the servers to Require Certificates from clients. The servers in question have a valid SSL-cert installed; that part is working. It's just when the Client Certificates option is enabled that users can no longer access the site.
    • Admin
      Admin almost 11 years
      Unless there is a genuine fault, it sounds like the server can't validate the client's cert (e.g.: chaining issue), or it can't perform a CRL check, or it can't access the signing CA. This could be me barking up the wrong tree...