View Single Post
Old 01-15-2004, 02:21 PM   #23
hugh Z. [MS]
 
Posts: n/a
Re: IIS4 no longer requests client certs issued by our CA!

Hi Craig,

Here is the more information about this hotfix 831225.
(http://hotfixv4.microsoft.com/Window.../PKG66582/1381
/free/148706_ENU_i386_zip.exe)

After installing security patch MS03-041 in NT 4.0 OptionPack + SP6a (IIS
4.0) box, some CA Root Certificates became unrecognizable, in result
clients could not get through SSL access by using "client certificate
mapping" or "client certificates required".

The issue is related to MS03-041 installed on some certain NT4 OS with the
customer CA configured.
MS03-041 addressed some security vulnerability.
http://www.microsoft.com/technet/tre...hnet/security/
bulletin/ms03-041.asp
Vulnerability in Authenticode Verification Could Allow Remote Code
Execution (823182)

We need to install 831225 to test it or remove Q823182 to see whether it is
working. But removing 823182 (MS03-041) will cause some security issue.

I hope the info above is helpful.

Thank you for choosing Microsoft

Hugh Zhu (MCSE, MCSD, MCAD .Net)
Developer Support Engineer (IIS)

This posting is provided “AS IS” with no warranties, and confers no rights.
You assume all risk for your use. © 2002 Microsoft Corporation. All rights
reserved.


  Reply With Quote