Solved

TLS 1.2 throws Event 36888 Schannel

Posted on 2016-08-31
3
33 Views
Last Modified: 2016-10-16
At some customer, we have the following issue:

Situation:
Server 2012 R2 (RDS)
Internet Explorer 11

Some websites are causing system errors: Event 36888 Schannel (eg: www.tweakers.net)
A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.

If we remove the tick in front of " Use TLS 1.2" in the advanced options of Internet Explorer, the error does no longer appear.

One site in particular throws has a login option which throws this error dozens of times, resulting in the website temporary being unavailable.

Removing the tick in front of "Use TLS 1.2" is not an option while it makes other websites no longer available.

What can we do to resolve this issue.
Can we resolve this ourselves, or must it be done by the owner of the website ?
0
Comment
Question by:Loyall
3 Comments
 
LVL 83

Assisted Solution

by:Dave Baldwin
Dave Baldwin earned 500 total points
ID: 41777844
I don't believe that web site has a problem.  'tweakers.net' gets an A+ rating from SSL Labs and I don't have any trouble connecting to it with IE11 on my win 7 machine.
https://www.ssllabs.com/ssltest/analyze.html?d=tweakers.net

Maybe your 'Root Certificates' are not up to date.  https://support.microsoft.com/en-us/kb/3004394
0
 
LVL 2

Accepted Solution

by:
Loyall earned 0 total points
ID: 41780173
Hi Dave,

Thank you for your respons.
We see the problem on all 2012 R2 servers. On RDS servers, who are covered by a lot of policies, but also on other member servers, who only have a WSUS policy.
On windows 10 clients we don't see the issue appear.
So, it looks like a OS/IE problem.
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I'm a big fan of Windows' offline folder caching and have used it on my laptops for over a decade.  One thing I don't like about it, however, is how difficult Microsoft has made it for the cache to be moved out of the Windows folder.  Here's how to …
When you start your Windows 10 PC and got an "Operating system not found" error or just saw  "Auto repair for startup" or a blinking cursor with black screen. A loop for Auto repair will start but fix nothing.  You will be panic as there are no back…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question