Why does IIS Give clients 403 Forbidden Errors?
Posted on 2011-09-26
Points of My Scenario
1. I am admin of a IIS7 web server on Windows Server 2008 R2.
2. Clients connect to the server's website using HTTPS
3. When the website is configured to "Require SSL" and to accept client certificates, clients (browsers) get a HTTP 403 Forbidden error when connecting by HTTPS.
4. When the "Require SSL" setting is removed from the website, clients can successfully connect, although using HTTPS again.
QUESTION: If clients are using HTTPS in both cases, why do they fail when the website is configured to "Require SSL"?