FIX: Error message occurs when you try to access a web server that requires a client certificate if HTTPS inspection is enabled in Forefront TMG 2010: "Error Code: 502 Proxy Error. The message received was unexpected or badly formatted. (-2146893018)"

Symptoms

Consider the following scenario:In this scenario, you cannot access the web server and receive the following error message:
Error Code: 502 Proxy Error. The message received was unexpected or badly formatted. (-2146893018)

Cause

This issue occurs because Forefront TMG 2010 sends an empty client certificate to the web server during the initial SSL handshake. Some web servers like IIS web servers accept and renegotiate the client certificate when a request that contains an empty client certificate is sent. However, other web servers may return an SSL error when the web server receives the empty client certificate. This behavior causes Forefront TMG not to correctly handle the server error.

Resolution

Microsoft provides programming examples for illustration only, without warranty either expressed or implied. This includes, but is not limited to, the implied warranties of merchantability or fitness for a particular purpose. This article assumes that you are familiar with the programming language that is being demonstrated and with the tools that are used to create and to debug procedures. Microsoft support engineers can help explain the functionality of a particular procedure, but they will not modify these examples to provide added functionality or construct procedures to meet your specific requirements.

To resolve this problem, follow these steps:

Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

References

For more information about software update terminology, click the following article number to view the article in the Microsoft Knowledge Base:
824684 Description of the standard terminology that is used to describe Microsoft software updates
Properties

Article ID: 982550 - Last Review: Jun 22, 2010 - Revision: 1

Feedback