Version Affected: All
Overview
Web clients cannot connect to a SecureAuth IdP Appliance over TLS 1.2, because the appliance's Trusted Root Certification Authorities container has grown too large.
Cause
The Schannel security package supports a maximum trusted certificate authority list size of 16 kilobytes (KB). If the Windows Trusted Root Certification Authorities container holds enough third-party root certificate authorities to exceed that 16 KB limit, TLS communication fails.
When this condition is present, the appliance logs an entry similar to:
Log: System
Source: Schannel
Event ID: 36885
Message: When asking for client authentication, this server sends a list of trusted certificate authorities to the client. The client uses this list to choose a client certificate that is trusted by the server. Currently, this server trusts so many certificate authorities that the list has grown too long. This list has thus been truncated. The administrator of this machine should review the certificate authorities trusted for client authentication and remove those that do not really need to be trusted.
Resolution
Pare down the Trusted Root Certification Authorities container to stay within the 16 KB Schannel limit. Removing a critical root certificate could negatively impact SecureAuth IdP, Microsoft IIS, or Windows Server, so back up the appliance before making any changes, and leave the following certificates in place:
- Every certificate required by the Windows Server operating system to function correctly.
- The SecureAuth Root Certificates: SecureAuth Root Certificate Authority, SecureAuth G3 Root Certificate Authority, and MFA Root 3.
- Any root certificates required by your own organization.
For further background, see:
- SSL/TLS communication problems after you install KB 931125
- TLS/SSL connection fails with the Schannel event logged
- SecureAuth CA Public Certificates
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.