IAS Cert Failures



Despite what I think is the right config, our IAS connections are failing
with "AcquireCredentialsHandle" failed...I can see this in logs generated
with net diag RAS set tracing * enable ...

[2504] 14:38:05:175: SetupMachineChangeNotification
[2504] 14:38:05:175: State change to Initial
[2504] 14:38:05:175: EapTlsBegin: Detected PEAP authentication
[2504] 14:38:05:175: MaxTLSMessageLength is now 16384
[2504] 14:38:05:175: CRYPT_E_NO_REVOCATION_CHECK will not be ignored
[2504] 14:38:05:175: CRYPT_E_REVOCATION_OFFLINE will not be ignored
[2504] 14:38:05:175: The root cert will not be checked for revocation
[2504] 14:38:05:175: The cert will be checked for revocation
[2504] 14:38:05:175: EapPeapBegin done
[2504] 14:38:05:175: EapPeapMakeMessage
[2504] 14:38:05:175: EapPeapSMakeMessage
[2504] 14:38:05:175: PEAP:PEAP_STATE_INITIAL
[2504] 14:38:05:175: EapTlsSMakeMessage
[2504] 14:38:05:175: EapTlsReset
[2504] 14:38:05:175: State change to Initial
[2504] 14:38:05:175: GetCredentials
[2504] 14:38:05:175: Flag is Server and Store is local Machine
[2504] 14:38:05:175: GetCachedCredentials Flags = 0x4061
[2504] 14:38:05:175: No Cert Name. Guest access requested
[2504] 14:38:05:175: AcquireCredentialsHandle failed and returned 0x8009030e


We have identical IAS configs working on other Server 2003 boxes, no
problems. All have a verisign machine cert in the computers store.

The only difference is the non working server is 2003 SP1. Any suggestions?

jerry.


.



Relevant Pages

  • Summary: DNS problem on Solaris 9
    ... difference between my working server and the one I have here. ... > HEADER: ... > AUTHORITY RECORDS: ... Here is my config. ...
    (SunManagers)
  • Re: CAS two backend 2003 sp2 servers
    ... what tool do i use to do export the config from the working server? ... the page never stops loading, users can click the folders, but again the ... Both 2003 backend servers are on the same ...
    (microsoft.public.exchange.admin)