Client Certificate Window Doesn't Display All Certificates (306180)



The information in this article applies to:

  • Microsoft Internet Information Server 4.0

This article was previously published under Q306180
We strongly recommend that all users upgrade to Microsoft Internet Information Services (IIS) version 6.0 running on Microsoft Windows Server 2003. IIS 6.0 significantly increases Web infrastructure security. For more information about IIS security-related topics, visit the following Microsoft Web site:

SYMPTOMS

When it connects to your Internet Information Server (IIS) 4.0 server, a browser that needs to provide a client certificate may not show client certificates that originate from a certain Certification Authority. This may occur even after you have imported the Certification Authority root certificate into the IIS 4.0 server's Trusted Root Certification Authorities certificate store.

CAUSE

The IIS 4.0 server to which you are connecting does not have the Certificate Authority's root certificate installed correctly.

RESOLUTION

To resolve this problem, follow these steps to reinstall the Certificate Authority's root certificate on the IIS computer:
  1. On the IIS server, start Microsoft Internet Explorer.
  2. On the Tools menu, click Internet Options.
  3. On the Content tab, click Certificates.
  4. Click the Trusted Root Certification Authorities tab, and remove any certificates that point to the Certificate Authority that issued the client certificates. To do this, select the certificate that you want to remove, click Remove, and then click Yes for each dialog box that you receive.
  5. Click Close, then click OK to clear any remaining dialog boxes.
  6. Obtain a copy of the Certificate Authority root certificate. For additional information, click the article number below to view the article in the Microsoft Knowledge Base:

    218445 How to Configure Certificate Server for Use with SSL on IIS

  7. Right-click the Certificate Authority root certificate and click Install.
  8. After the Certificate Manager Import Wizard has started, click Next.
  9. Select Place all certificates into the following store.
  10. Click Browse, and then click Show physical stores.
  11. Expand Trusted Root Certification Authorities, select Local Computer, and then click OK.
  12. Click Next, and then click Finish.
  13. Restart your Web server computer.

MORE INFORMATION

For additional information, click the article numbers below to view the articles in the Microsoft Knowledge Base:

231718 Client Certificates May Not Appear in Internet Explorer

216782 Internet Explorer Displays a Blank Personal Certificate List


Modification Type:MinorLast Reviewed:6/23/2005
Keywords:kbpending kbprb KB306180