Click here to get back home

schannel error 36870 (extended 0x80090016)

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
schannel error 36870 (extended 0x80090016) CanSpam 09-04-2007
Posted by CanSpam on September 4, 2007, 9:26 am
Please log in for more thread options
Hello experts,
I am having the following problem on two of my freshly reinstalled =
servers Win2003 Standard SP1:

Event Type: Error
Event Source: Schannel
Event Category: None
Event ID: 36870
Date: 9/3/2007
Time: 5:24:45 PM
User: N/A
Computer: GUIS1
Description:
A fatal error occurred when attempting to access the SSL server =
credential private key. The error code returned from the cryptographic =
module is 0x80090016.

I have installed a corporate CA into Machine\Trusted Root, and a server =
SSL certificate that is signed by the CorpCA, into Machine\Personal. =
They both look valid in mmc snap-in, not expired. I also tried to =
remove-reinstall them to no avail. I also tried to give Full Access to =
the Administrator and the SYSTEM on All Users/Application =
Data/Microsoft/Crypto/RSA/MachinKeys.

I ran certutil and it only shows some problematic Microsoft/Verisign =
(expired) certs, not mine corporate.
I cannot take server online to renew them.

What next in troubleshooting chain?



Posted by jwgoerlich on September 5, 2007, 11:06 am
Please log in for more thread options
Try granting Everyone read access to the MachineKeys folder, in
addition to what you have already granted Administrators and System.

J Wolfgang Goerlich


Microsoft Article 278381, Default permissions for the MachineKeys
folders
http://support.microsoft.com/kb/278381

> Hello experts,
> I am having the following problem on two of my freshly reinstalled servers
Win2003 Standard SP1:
>
> Event Type: Error
> Event Source: Schannel
> Event Category: None
> Event ID: 36870
> Date: 9/3/2007
> Time: 5:24:45 PM
> User: N/A
> Computer: GUIS1
> Description:
> A fatal error occurred when attempting to access the SSL server credential
private key. The error code returned from the cryptographic module is 0x80090016.
>
> I have installed a corporate CA into Machine\Trusted Root, and a server SSL
certificate that is signed by the CorpCA, into Machine\Personal. They both look
valid in mmc snap-in, not expired. I also tried to remove-reinstall them to no
avail. I also tried to give Full Access to the Administrator and the SYSTEM on
All Users/Application Data/Microsoft/Crypto/RSA/MachinKeys.

>
> I ran certutil and it only shows some problematic Microsoft/Verisign (expired)
certs, not mine corporate.
> I cannot take server online to renew them.
>
> What next in troubleshooting chain?



Posted by CanSpam on September 6, 2007, 3:34 am
Please log in for more thread options
Hi Wolfgang, your advice is insecure.
I solved the problem by granting NETWORK SERVICE the same permissions on =
Machinekeys folder as to SYSTEM.
Citrix XTE service is run under the NETWORK SERVICE account and it was =
not accepting SSL relayed connections. Now all is fine.

> Try granting Everyone read access to the MachineKeys folder, in
> addition to what you have already granted Administrators and System.
>=20
> J Wolfgang Goerlich
>=20
>=20
> Microsoft Article 278381, Default permissions for the MachineKeys
> folders
> http://support.microsoft.com/kb/278381
>=20
>> Hello experts,
>> I am having the following problem on two of my freshly reinstalled =
servers Win2003 Standard SP1:
>>
>> Event Type: Error
>> Event Source: Schannel
>> Event Category: None
>> Event ID: 36870
>> Date: 9/3/2007
>> Time: 5:24:45 PM
>> User: N/A
>> Computer: GUIS1
>> Description:
>> A fatal error occurred when attempting to access the SSL server =
credential private key. The error code returned from the cryptographic =
module is 0x80090016.
>>
>> I have installed a corporate CA into Machine\Trusted Root, and a =
server SSL certificate that is signed by the CorpCA, into =
Machine\Personal. They both look valid in mmc snap-in, not expired. I =
also tried to remove-reinstall them to no avail. I also tried to give =
Full Access to the Administrator and the SYSTEM on All Users/Application =
Data/Microsoft/Crypto/RSA/MachinKeys.
>>
>> I ran certutil and it only shows some problematic Microsoft/Verisign =
(expired) certs, not mine corporate.
>> I cannot take server online to renew them.
>>
>> What next in troubleshooting chain?
>=20
>

Posted by jwgoerlich on September 6, 2007, 8:10 am
Please log in for more thread options
Good to know that this can be solved by granting the lesser privilege,
thank you for the feedback.

J Wolfgang Goerlich

> Hi Wolfgang, your advice is insecure.
> I solved the problem by granting NETWORK SERVICE the same permissions on
Machinekeys folder as to SYSTEM.
> Citrix XTE service is run under the NETWORK SERVICE account and it was not
accepting SSL relayed connections. Now all is fine.
>
>
>
> > Try granting Everyone read access to the MachineKeys folder, in
> > addition to what you have already granted Administrators and System.
>
> > J Wolfgang Goerlich
>
> > Microsoft Article 278381, Default permissions for the MachineKeys
> > folders
> >http://support.microsoft.com/kb/278381
>
> >> Hello experts,
> >> I am having the following problem on two of my freshly reinstalled servers
Win2003 Standard SP1:
>
> >> Event Type: Error
> >> Event Source: Schannel
> >> Event Category: None
> >> Event ID: 36870
> >> Date: 9/3/2007
> >> Time: 5:24:45 PM
> >> User: N/A
> >> Computer: GUIS1
> >> Description:
> >> A fatal error occurred when attempting to access the SSL server credential
private key. The error code returned from the cryptographic module is 0x80090016.
>
> >> I have installed a corporate CA into Machine\Trusted Root, and a server SSL
certificate that is signed by the CorpCA, into Machine\Personal. They both look
valid in mmc snap-in, not expired. I also tried to remove-reinstall them to no
avail. I also tried to give Full Access to the Administrator and the SYSTEM on
All Users/Application Data/Microsoft/Crypto/RSA/MachinKeys.

>
> >> I ran certutil and it only shows some problematic Microsoft/Verisign
(expired) certs, not mine corporate.
> >> I cannot take server online to renew them.
>
> >> What next in troubleshooting chain?- Hide quoted text -
>
> - Show quoted text -



Similar ThreadsPosted
Schannel error 36870 (private key rights) January 8, 2008, 11:47 am
An extended error has occurred. Failed to save Local Policy Database. August 15, 2005, 2:45 pm
Wny Does Windows Want Write Extended Attributes for Users? August 4, 2005, 1:31 am
un/pwd error using network profile - no error with local profile March 23, 2007, 1:23 pm
Write Attributes and Write Extended Attributes October 31, 2005, 1:30 am
SBS.RWW Error October 9, 2005, 9:08 am
Lsass.exe error 128 September 4, 2005, 5:18 pm
Certificate Error September 7, 2006, 4:59 pm
Runtime Error 75 November 21, 2006, 7:53 am
Help with AutoEnrollment Error 15 March 22, 2007, 10:21 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap