<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Certificates on Jon's Notes</title><link>https://4c4806b4.configjon-blog.pages.dev/category/certificates/</link><description>Recent content in Certificates on Jon's Notes</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 06 Apr 2019 00:00:00 +0000</lastBuildDate><atom:link href="https://4c4806b4.configjon-blog.pages.dev/category/certificates/index.xml" rel="self" type="application/rss+xml"/><item><title>Management Point Root CA Trust Issue (HTTP 403)</title><link>https://4c4806b4.configjon-blog.pages.dev/management-point-root-ca-trust-issue-http-403/</link><pubDate>Sat, 06 Apr 2019 00:00:00 +0000</pubDate><guid>https://4c4806b4.configjon-blog.pages.dev/management-point-root-ca-trust-issue-http-403/</guid><description>&lt;p&gt;I was setting up a Configuration Manager environment in HTTPS mode and I was running into issues with the server selecting a client authentication certificate.&lt;/p&gt;
&lt;p&gt;I was seeing these messages in the &lt;strong&gt;MPControl.log&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="https://4c4806b4.configjon-blog.pages.dev/management-point-root-ca-trust-issue-http-403/images/Certificate_Error-1024x243.png"&gt;&lt;/p&gt;
&lt;p&gt;I was seeing this message in the &lt;strong&gt;IIS log&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="https://4c4806b4.configjon-blog.pages.dev/management-point-root-ca-trust-issue-http-403/images/IIS_Error-1.png"&gt;&lt;/p&gt;
&lt;p&gt;I was getting a &lt;strong&gt;2148204809&lt;/strong&gt; error which translates to &lt;strong&gt;A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.&lt;/strong&gt; That told me something was wrong with the root CA trust. Some searching online brought up a few useful posts on the subject.&lt;/p&gt;</description></item></channel></rss>