Article ID: 248058 - Last Review: November 21, 2006 - Revision: 1.3 Error message: HTTP 403.13 Forbidden: client certificate revokedThis article was previously published under Q248058 SYMPTOMS
When you attempt to access an Internet resource, one of the following error messages may be displayed in the Web browser:
HTTP 403.13 Forbidden: Client certificate revoked The page requires a valid client certificate CAUSEAn HTTP 403.13 error message is returned when a resource that the user is attempting to access requires a valid client certificate that the server recognizes. This client certificate must be installed in the Web browser, because it is used to authenticate the user of that browser as a valid user of the resource. The error message can also occur if IIS is unable to contact the server that stores the Certificate Revocation List (CRL) when checking for revoked certificates. If a CRL server is unreachable, the certificates are presumed to be revoked. RESOLUTION
In the Web browser that is displaying the error, install a certificate from a recognized Certificate Authority (CA). If a certificate from a valid CA is installed, then contact that CA to verify the certificate has not been revoked, and that their CRL store is online.
If the certificate was created with Microsoft's Certificate Server, you will want to verify that the IIS server is able to directly see the Certificate Server. You can verify the path under the CRL Distribution Points and verify that the path is accessible from the IIS server. To do this, follow these steps:
MORE INFORMATION
For more information on how to quickly install a certificate from a recognized Certificate Authority (CA), click the following article number to view the article in the Microsoft Knowledge Base:
297681
(http://support.microsoft.com/kb/297681/
)
Error message: This security certificate was issued by a company that you have not chosen to trust
For more information on using Digital Certificates with Microsoft Internet Explorer, see the following Knowledge Base article:
195724
(http://support.microsoft.com/kb/195724/
)
Description of digital certificates
For more information on Certificate Revocation List (CRL) and IIS 5.0, see the following Knowledge Base article:
289749
(http://support.microsoft.com/kb/289749/
)
Certificate Revocation Lists (CRLs) and IIS 5.0 frequently asked questions
The Security & Cryptography
(http://msdn.microsoft.com/workshop/c-frame.htm#/workshop/security/)
section of Microsoft's Online Web Workshop site provides detailed information about encryption and secure Internet communications.An online seminar entitled Fundamental Cryptography and Certificates on the Internet (http://microsoft.com/Seminar/Includes/Seminar.asp?url=/seminar/1033/Crypto_certs/portal.xml) is available for viewing at Microsoft's Seminar Online site. | Article Translations
|

Back to the top
