Link to home
Start Free TrialLog in
Avatar of Wibble_
Wibble_

asked on

SCCM on 2008r2 - 403 forbidden errors

Trying to install SCCM on 2008r2.

Client installs are failing trying to download https://SCCM.DOMAIN.LOCAL/CCM_Client/ccmsetup.cab 

Browsing to that url gives a 403 forbidden message
Manually creating a test.html file in the same folder also gives a 403 error.
Placing same test file in the root iis folder works fine.
The same 403 error is seen when visiting all sites (CCM_CLIENT CCM_Incoming CCM_Outgoing CCM_System etc..).
IUSR user has ntfs permissions to read & execute, read & list folder contents
anonymous auth is enabled, and the user IUSR is selected.

Strangely, there is nothing in the C:\inetpub\logs\FailedReqLogFiles folder.
entries in the LogFiles folder look like this (when using IE):

2010-03-26 11:39:17 172.16.2.11 GET /CCM_CLIENT - 443 - 10.4.0.2 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+5.1;+Trident/4.0;+InfoPath.1;+.NET+CLR+1.1.4322;+.NET+CLR+2.0.50727;+.NET+CLR+3.0.04506.648;+.NET+CLR+3.5.21022;+.NET+CLR+3.0.4506.2152;+.NET+CLR+3.5.30729) 403 7 5 4
Avatar of pcfreaker
pcfreaker
Flag of Venezuela, Bolivarian Republic of image

There are two things commun, first the default site on the documents tab should be added and on the first line if posible on that web site.
The other is to have the permissions under the website, as read, write, execute scripts under the home directory site.
Follow this.
http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/21079107-1740-470e-a933-23a45494b8ba.mspx?mfr=true
Let me know.
Rgds.
Avatar of Wibble_
Wibble_

ASKER

I've tried adding 'everyone' with full permissions to the ntfs folder, and to the home drirectory (default web site) site

I'ts not a script problem, as I cant access https://SCCM.DOMAIN.LOCAL/CCM_Client/foo.html , a plain html file I created.

still the 403
Avatar of Wibble_

ASKER

This is an actual request (not me from a browser)

2010-03-26 14:53:40 172.16.2.11 GET /CCM_Client/ccmsetup.cab - 443 - 172.16.20.189 ccmsetup 403 13 2148081683 7

Would that suggest that it's a 403.13, i.e. Client certificate has been revoked on the Web server?
ASKER CERTIFIED SOLUTION
Avatar of pcfreaker
pcfreaker
Flag of Venezuela, Bolivarian Republic of image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Wibble_

ASKER

It was a CRL problem. Re-issuing the root certificate fixed it.

TY :-)
Oh I see!... you did have an active CRL. Good thing you manage to fix it quickly!
Thanks and Rgds.