Certificate Mapping Does Not Check End Entity and Path Length Constraints (326329)



The information in this article applies to:

  • Microsoft Internet Information Services 5.0

This article was previously published under Q326329

SYMPTOMS

If you configure Internet Information Services (IIS) to require Secure Sockets Layer (SSL), a client certificate, and a specific root certificate, IIS does not seem to check the complete certificate chain for pathlength=0 and end identity constraints.

RESOLUTION

This problem was corrected in Microsoft Windows 2000 Service Pack 3.

STATUS

Microsoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article.

Modification Type:MinorLast Reviewed:9/27/2005
Keywords:kbHotfixServer kbQFE kbbug kbfix kbWin2000PreSP3Fix kbWin2000sp3fix KB326329