A certification chain processed correctly, but one of the CA certificates is not trusted by the policy provider.

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Anyone know what this error is?

On the server under IAS Remote access Policies, under EAP Methods I have
"Smart Card or other certificate" selected, on the client I have under
"Authentication" I have "Smart Card or other certificate" selected and under
that I have "Use Certificate on this computer" I am getting the below error,

The root certificate is "trusted" on both the client and server, and the
chain shows up with no problems if I click on any of the certs. Anyone got
any ideas?


Full Event log

Event Type: Warning
Event Source: IAS
Event Category: None
Event ID: 2
Date: 6/2/2005
Time: 10:19:28 AM
User: N/A
Computer: LCS1
Description:
User Bob was denied access.
Fully-Qualified-User-Name = Users/Bob
NAS-IP-Address = 192.168.1.17
NAS-Identifier = <not present>
Called-Station-Identifier = <not present>
Calling-Station-Identifier = 00-12-17-e1-22-39
Client-Friendly-Name = wireless
Client-IP-Address = 192.168.1.17
NAS-Port-Type = Wireless - IEEE 802.11
NAS-Port = 0
Proxy-Policy-Name = Use Windows authentication for all users
Authentication-Provider = Windows
Authentication-Server = <undetermined>
Policy-Name = Wireless
Authentication-Type = EAP
EAP-Type = Smart Card or other certificate
Reason-Code = 295
Reason = A certification chain processed correctly, but one of the CA
certificates is not trusted by the policy provider.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 12 01 0b 80 ...?


.



Relevant Pages

  • Re: Checkpoint smart defance as IPS
    ... *any* SSL/TLS communication without tampering anything on the client ... website a client visits on-the-fly. ... don't have private key for the certificate on that website. ...
    (Security-Basics)
  • Re: Checkpoint smart defance as IPS
    ... *any* SSL/TLS communication without tampering anything on the client ... website a client visits on-the-fly. ... don't have private key for the certificate on that website. ...
    (Security-Basics)
  • Re: Cannot request computer certificate.
    ... >problem since you can not request a certificate while logged onto the CA. ... Verify that you can ping it by name and IP address from the client ... >> Kerberos, or dns. ... >> List of NetBt transports currently bound to the Redir ...
    (microsoft.public.windows.server.security)
  • Re: The message must contain a wsa:To header
    ... My client app is not generating a trace file. ... the client is not applying the WSE policy at all because of an ... at ApplicationMessagingWS.Dispatch(String messageType, String ... look for a certificate with this subject name in the certificate store ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: Cannot request computer certificate.
    ... I would verify that the certificate services service is running and set to ... Verify that you can ping it by name and IP address from the client ... > Kerberos, or dns. ... > List of NetBt transports currently bound to the Redir ...
    (microsoft.public.windows.server.security)