Select the product you need help with
Summary of changes to the CryptoAPI certificate chain validation logic in Q835732 on Windows 2000 Service Pack 2 or later versionsArticle ID: 887195 - View products that this article applies to. INTRODUCTIONThis article contains a summary of the changes that are made to the CryptoAPI certificate chain validation logic in the following security update for Microsoft Windows 2000 Service Pack 2 (SP2) or later versions: 835732 The information in this article also applies to the following hotfix:
(http://support.microsoft.com/kb/835732/
)
MS04-011: Security Update for Microsoft Windows
329433 However, the Q329433 hotfix has been superseded by Q835732.
(http://support.microsoft.com/kb/329433/
)
A revoked certificate is selected if a certification authority in the chain has two certificates
MORE INFORMATIONCryptoAPI uses the Winhttp.dll library for network retrieval instead of the Wininet.dll library. Therefore, the following conditions may occur:
When it processes certificates with the Authority Information Access (AIA) extension, CryptoAPI will only process a maximum of five URLs for each certificate or 10 URLs for each certificate chain. CryptoAPI also limits the amount of data that is retrieved for each certificate chain to 100,000 bytes. These limitations are intended to reduce the potential use of AIA references in denial of service attacks. Cross-certificate discovery and inclusion are supported through the Cross Certificate Distribution Point extension (xDP). The following features are also supported:
841632
(http://support.microsoft.com/kb/841632/
)
You receive a "403.13 client certificate revoked" error message after you install the MS04-11 security update
841641
(http://support.microsoft.com/kb/841641/
)
IIS returns a "403.13 Client Certificate Revoked" error message after you install MS04-011 because of Wininet proxy settings
841642
(http://support.microsoft.com/kb/841642/
)
Errors with client certificates occur after you install the MS04-011 security update on an IIS 5.0 computer
835732
(http://support.microsoft.com/kb/835732/
)
MS04-011: Security Update for Microsoft Windows
329433
(http://support.microsoft.com/kb/329433/
)
A revoked certificate is selected if a certification authority in the chain has two certificates
Properties |


Back to the top








