Go Back   StudyChaCha 2024 2025 > StudyChaCha Discussion Forum > General Topics

  #2  
Old April 5th, 2016, 06:53 PM
Super Moderator
 
Join Date: Nov 2011
Default Re: IAS Error Code 266

As per your demand here is the Solution of IAS Error Code 266

Solution-

Click Start, click Run, type regedit, and then click OK.

Locate and then click the following registry subkey

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SecurityProviders\SCHANNEL

On the Edit menu, point to New, and then click DWORD Value.

Type SendTrustedIssuerList, and then press ENTER to name the registry entry.

Right-click SendTrustedIssuerList, and then click Modify.

In the Value data box, type 0 if that value is not already displayed, and then click OK.

This problem may occur if the Web server or the IAS server contains many entries in the trusted root certification list.

The server sends a list of trusted certificate authorities to the patron if the following conditions are true:

The server uses the Transport Layer Security (TLS)/SSL protocol to encrypt network traffic.

Client certificates are needed for authentication during the authentication handshake process.

This list of trusted certificate authorities represents the authorities from which the server may accept a client certificate.

To be authenticated by the server, the client must have a certificate that is present in the chain of certificates to a root certificate from the server's list.

Currently, the maximum size of the trusted certificate authorities list that the Schannel security package supports is 12,228 (0x3000) bytes.

Schannel creates the list of trusted certificate authorities by searching the Trusted Root Certification Authorities store on the local computer.

Every certificate that is trusted for client authentication reasons is added to the list.

If the size of this list exceeds 12,228 bytes, Schannel logs Warning event ID 36855.

Then, Schannel truncates the list of trusted root certificates and sends this truncated list to the client computer.

When the client computer receives the truncated list of trusted source certificates, the client computer may not have a certificate that exists in the chain of a trusted certificate issuer.

For example, the client computer may have a certificate that corresponds to a trusted root certificate that Schannel truncated from the list of trusted certificate authorities.

Therefore, the IAS server cannot authenticate the client.
__________________
Answered By StudyChaCha Member
Reply With Quote
Reply




All times are GMT +6. The time now is 08:45 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
Search Engine Friendly URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8