Solved

Server 2008 R2 Terminal server rejecting ALL certificates as invalid

Posted on 2014-11-23
4
233 Views
Last Modified: 2014-12-14
I have a 2008r2 Terminal server that is categorically rejecting ANY certificate it encounters.  Certs that I know for certain are valid.  Everything I can find is related to specific applications, but this is happening across all browsers, and every application that uses SSL.  Malware scans come up clean.  I reset the security providers using IISCrypto (https://www.nartac.com/Products/IISCrypto/), mostly out of desperation.

I'm nearly ready to roll this system back, but I'm not certain of when the behavior started.

The eventviewer is full of Event 36882 SChannel errors that state:
"The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The SSL connection request has failed. The attached data contains the server certificate."

Again, this is happening with every cert encountered by the system regardless of source or issuing CA.
0
Comment
Question by:Enphyniti
  • 2
  • 2
4 Comments
 
LVL 24

Expert Comment

by:VB ITS
ID: 40460948
First thing I'd check is to make sure the date and time is set correctly on the server.

Next step would be to re-synchronize the Trusted Root Certificates on your server as it sounds like something has happened to your Trusted Root CAs. Click on the Microsoft Fix it link on this page underneath For Windows 8.1, Windows 8, Windows 7, Windows Server 2012 R2, Windows Server 2012 or Windows Server 2008 R2: http://support.microsoft.com/kb/931125
0
 
LVL 16

Assisted Solution

by:Enphyniti
Enphyniti earned 0 total points
ID: 40461001
Time and date are good.  The Fixit didn't appear to work.

What I've done as a stopgap to get things working again was to export the Trusted Root CA store from another server and import it directly on the system in question.  That appears to have mitigated the issue for now, but I fear the underlying update capability is still broken and will cause me issues down the road.

The weird thing is that these systems are all spun up off of templates and configured via policy.  All patches are applied in groups, so my source server and the server having this issue *should* be identical.

Anyway, I'll leave this open for a while in case anyone has any idea what the underlying issue is, but the fire is out for now.
0
 
LVL 24

Accepted Solution

by:
VB ITS earned 500 total points
ID: 40461033
OK good, at least we know the issue was with your Trusted Root CA store. My next recommendation was going to be to clear out the current certificates in your Trusted Root CA store by exporting them first, then copying over certificates from a working machine.
The weird thing is that these systems are all spun up off of templates and configured via policy.  All patches are applied in groups, so my source server and the server having this issue *should* be identical.
Only thing I can think of is if a Windows Update did not install itself correctly. It's been known from time to time that an update can break one machine but not another.

Definitely keep an eye out on this server over the next few days in case there's an issue with the certificate update mechanism on your TS.
0
 
LVL 16

Author Closing Comment

by:Enphyniti
ID: 40498676
Well, it's been a few weeks and the steps taken above are still working.  I don't know if I'll have an issue with this system at a later date or not, but for now at least, it's easier to import certs from another system than it is to dig through thousands of updates to determine if one of them needs to be re-applied.

If it continues to be a problem, I will probably scrap the system and deploy a new one.  Thanks for your help.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Imagine a situation that you have installed SSL (http://en.wikipedia.org/wiki/Secure_Sockets_Layer) Certificate on your Cisco ASA (Cisco Adaptive Security Appliance) firewall. Installation of SSL certificate on ASA is an another topic for which you …
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now