Clients receive a "500 Server" error message if a Web server requires a Certificate Revocation List in ISA Server 2004 (891510)
The information in this article applies to:
- Microsoft Internet Security and Acceleration Server 2004, Standard Edition
SYMPTOMSIf you use Microsoft Internet Security and Acceleration (ISA) Server 2004 to publish a secure sockets layer (SSL) Web site of a Web server, clients may receive the following error message: Error Code: 500 Internal Server Error. The certificate is revoked. (-2146885616) CAUSEThis problem occurs if the following conditions are true: - Certificate Revocation List (CRL) checks are enabled in ISA Server 2004.
For additional information about how to enable CRL checks in ISA Server 2004, see the "More Information" section later in this article.
- SSL Client Certificate authentication is enabled on the Web Publishing Rule.
For additional information about how to enable SSL Client certificate authentication in ISA Server 2004, see the "More Information" section later in this article.
- The root certificate where the SSL Server Certificate on the ISA Server 2004 Web Listeners is derived from has no CRL distribution points.
For additional information about how to verify that the root certificate has no CRL distribution points, see the "More Information" section later in this article.
RESOLUTIONService pack information To resolve this problem, obtain and install the latest service pack for Internet Security and Acceleration Server 2004.
For additional information, click the following article number to view the article in the Microsoft Knowledge Base:
891024
How to obtain the latest ISA Server 2004 service pack
WORKAROUNDTo work around this problem, manually download the CRL, and then install it to the local computer certificate store.
Note Because the CRL is valid only for a limited time, you must periodically retrieve a new CRL.
To install a CRL to the local computer certificate store, follow these steps: - Log on to the computer as a member of the local administrators group.
- Open the Certificates snap-in for the computer account. To do this, follow these steps:
- Click Start, click Run, type mmc, and then click OK.
- On the File menu, click Add/Remove Snap-in. The Add/Remove Snap-in dialog box appears.
- In the Standalone tab, click Add. The Add Standalone Snap-in dialog box appears.
- In the Available Standalone Snap-ins list, click Certificates, and then click Add.
- Click Computer account, and then click Next.
- Click Local computer, and then click Finish.
- Click Close, and then click OK.
- Expand Certificates, right-click Intermediate Certification
Authorities, click All Tasks, and then click Import.
- Follow instructions in the wizard to complete the installation.
STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.
Modification Type: | Major | Last Reviewed: | 3/2/2005 |
---|
Keywords: | kbfix kbBug KB891510 kbAudITPRO |
---|
|