Article ID: 2501777 - View products that this article applies to.
Consider the following scenario:
502 Proxy Error. An unknown error occurred while processing the certificate. (-2146893017)
This issue occurs because Forefront TMG 2010 sends an empty client certificate to the web server in the initial SSL handshake.
When a request that contains an empty client certificate is sent, some web servers accept and renegotiate the client certificate. However, other web servers may return an SSL error when the web server receives an empty client certificate, and Forefront TMG does not correctly handle the server error. Therefore, the error message that is mentioned in the "Symptoms" section is generated.
Note An example of a web server that accepts and renegotiates an empty client certificate is an IIS web server.
To resolve this issue, follow these steps:
Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.
For more information, click the following article number to view the article in the Microsoft Knowledge Base:
982550For more information about software update terminology, click the following article number to view the article in the Microsoft Knowledge Base:
(http://support.microsoft.com/kb/982550/ )FIX: Error message occurs when you try to access a web server that requires a client certificate if HTTPS inspection is enabled in Forefront TMG 2010: "Error Code: 502 Proxy Error. The message received was unexpected or badly formatted. (-2146893018)"
(http://support.microsoft.com/kb/824684/ )Description of the standard terminology that is used to describe Microsoft software updates
Article ID: 2501777 - Last Review: February 25, 2011 - Revision: 1.0