AD FS Client Certificate Error 403.16 - Client Certificate Untrusted or Invalid.


hello,

iam trying login sharepoint site client certificate ad fs. if request sharepoint site iam getting redirected ad fs getting http 403.16 error iis of ad fs!

all certificates importet trusetd certificate store of sharepoint , ad fs server.

for ad fs ssl connection iam using digicert wildcard certificate (*.domain.com) - during ad fs role configuration ive configured certificate fqdn "adfs.doman.com" (just example). 

the client certificate iam generating ad ca. here have created own rootca. client certificate generated own rootca. -> maybe error causing??? habe on 1 side digicert wildcard certificate ssl on oher site self created client certificate ad ca.

thanks,

ralf

hi ralf,

http 403.16 means client certificate untrusted or invalid.

this error can occur if choose client certificate created certificate authority (ca) not trusted iis computer.

>>the client certificate iam generating ad ca. here have created own rootca. client certificate generated own rootca. -> maybe error causing???

have imported root certificate of ca into all servers' trusted certificate authorities? if no, please import it.

here link certificate requirement of adfs, may helpful.

https://technet.microsoft.com/en-us/library/dd807040.aspx?f=255&mspperror=-2147217396

besides, questions adfs, you may refer experts following forum professional support:

claims based access platform (cba), code-named geneva forum

http://social.msdn.microsoft.com/forums/vstudio/en-us/home?forum=geneva

best regards.


steven lee please remember mark replies answers if , unmark them if provide no help. if have feedback technet support, contact tnmff@microsoft.com.



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS