Troubleshooting: TLS 1.2 Communication Fails Due to an Oversized Trusted Root Certificate Authority List

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    Web clients cannot connect to a SecureAuth IdP Appliance over TLS 1.2, because the appliance's Trusted Root Certification Authorities container has grown too large.

     

    Cause

    The Schannel security package supports a maximum trusted certificate authority list size of 16 kilobytes (KB). If the Windows Trusted Root Certification Authorities container holds enough third-party root certificate authorities to exceed that 16 KB limit, TLS communication fails.

    When this condition is present, the appliance logs an entry similar to:

    Log: System
    Source: Schannel
    Event ID: 36885
    Message: When asking for client authentication, this server sends a list of trusted certificate authorities to the client. The client uses this list to choose a client certificate that is trusted by the server. Currently, this server trusts so many certificate authorities that the list has grown too long. This list has thus been truncated. The administrator of this machine should review the certificate authorities trusted for client authentication and remove those that do not really need to be trusted.

     

    Resolution

    Pare down the Trusted Root Certification Authorities container to stay within the 16 KB Schannel limit. Removing a critical root certificate could negatively impact SecureAuth IdP, Microsoft IIS, or Windows Server, so back up the appliance before making any changes, and leave the following certificates in place:

    • Every certificate required by the Windows Server operating system to function correctly.
    • The SecureAuth Root Certificates: SecureAuth Root Certificate Authority, SecureAuth G3 Root Certificate Authority, and MFA Root 3.
    • Any root certificates required by your own organization.

    For further background, see:

     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.