The page requires a valid client certificate
The error message can also occur if IIS is unable to contact the server that stores the Certificate Revocation List (CRL) when checking for revoked certificates. If a CRL server is unreachable, the certificates are presumed to be revoked.
If the certificate was created with Microsoft's Certificate Server, you will want to verify that the IIS server is able to directly see the Certificate Server. You can verify the path under the CRL Distribution Points and verify that the path is accessible from the IIS server. To do this, follow these steps:
- In the Certificates Snap-in, expand Certificates, and then expand Personal.
- Under the Certificates folder, double-click the certificate you are verifying, and then click the Details tab.
- Verify the paths under the CRL Distribution Points.
- Check the paths by trying to access them through Windows Explorer, (from Start, click Run or Internet Explorer).
- If the paths are not accessible from the IIS server, then it is necessary to rectify the connection to allow the IIS server to connect to the Certificate Server.
Article ID: 248058 - Last Review: Jul 31, 2012 - Revision: 1