Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

TLS 1.2 throws Event 36888 Schannel

Posted on 2016-08-31
3
Medium Priority
?
200 Views
Last Modified: 2016-10-16
At some customer, we have the following issue:

Situation:
Server 2012 R2 (RDS)
Internet Explorer 11

Some websites are causing system errors: Event 36888 Schannel (eg: www.tweakers.net)
A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.

If we remove the tick in front of " Use TLS 1.2" in the advanced options of Internet Explorer, the error does no longer appear.

One site in particular throws has a login option which throws this error dozens of times, resulting in the website temporary being unavailable.

Removing the tick in front of "Use TLS 1.2" is not an option while it makes other websites no longer available.

What can we do to resolve this issue.
Can we resolve this ourselves, or must it be done by the owner of the website ?
0
Comment
Question by:Loyall
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 84

Assisted Solution

by:Dave Baldwin
Dave Baldwin earned 2000 total points
ID: 41777844
I don't believe that web site has a problem.  'tweakers.net' gets an A+ rating from SSL Labs and I don't have any trouble connecting to it with IE11 on my win 7 machine.
https://www.ssllabs.com/ssltest/analyze.html?d=tweakers.net

Maybe your 'Root Certificates' are not up to date.  https://support.microsoft.com/en-us/kb/3004394
0
 
LVL 2

Accepted Solution

by:
Loyall earned 0 total points
ID: 41780173
Hi Dave,

Thank you for your respons.
We see the problem on all 2012 R2 servers. On RDS servers, who are covered by a lot of policies, but also on other member servers, who only have a WSUS policy.
On windows 10 clients we don't see the issue appear.
So, it looks like a OS/IE problem.
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Ever visit a website where you spotted a really cool looking Font, yet couldn't figure out which font family it belonged to, or how to get a copy of it for your own use? This article explains the process of doing exactly that, as well as showing how…
By default Outlook 2016 displays only one time zone in the Calendar. The following article explains how to display two time zones in one calendar view.
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

661 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question