Server 2008 SChannel 36870 error
I've searched and found that the information I've found doesn't exactly fity my situation.I have a web server (Server 2008 Standard SP2 (not R2)) that hosts multiple sites on different IPs (so no sharing of ports). This Server was upgraded from 2003. On this server I have multiple SSL certs, mostly just junk. We use a wildcard certificate for all sites on this server.Problem:Whenever I reboot the server I get the following errors in this order:Log Name: SystemSource: SchannelDate: 11/24/2009 5:11:30 PMEvent ID: 36870Task Category: NoneLevel: ErrorKeywords: ClassicUser: N/AComputer: WEB.DOMAIN.localDescription:A fatal error occurred when attempting to access the SSL server credential private key. The error code returned from the cryptographic module is 0x8009030d.Log Name: SystemSource: Microsoft-Windows-HttpEventDate: 11/24/2009 5:11:30 PMEvent ID: 15300Task Category: NoneLevel: WarningKeywords: ClassicUser: N/AComputer: WEB.DOMAIN.localDescription:SSL Certificate Settings deleted for Port : 0.0.0.0:443 .Log Name: SystemSource: Microsoft-Windows-HttpEventDate: 11/24/2009 5:11:30 PMEvent ID: 15301Task Category: NoneLevel: WarningKeywords: ClassicUser: N/AComputer: WEB.DOMAIN.localDescription:SSL Certificate Settings created by an admin process for Port : 0.0.0.0:443 .Log Name: SystemSource: Microsoft-Windows-HttpEventDate: 11/24/2009 5:11:30 PMEvent ID: 15300Task Category: NoneLevel: WarningKeywords: ClassicUser: N/AComputer: WEB.DOMAIN.localDescription:SSL Certificate Settings deleted for Port : 0.0.0.0:443 .What this results in is the SSL cert selection for the DefaultSite binding being deleted. Not the binding it self, just which cert it uses. I can go in to IIS and reselect the cert and then SSL will work fine until the next reboot. The same cert is used on multiple sites on the same server, but none of them experience this problem. When I view the cert via the Certifcates MMC the cert & its chain all are shown as Ok.I'm completely at a loss.
December 7th, 2009 8:02pm

Not being able to access the cert private key is usually a permissions problem.This is probably the root cause of your problem.The easiest thing to try is to delete the certficate and reimport it.Then set the server to use it again and reboot.See if you still get the: "failed to access private key" error.
Free Windows Admin Tool Kit Click here and download it now
December 7th, 2009 8:15pm

I'll give that a whirl.The only flaw I see in that logic is that if that was the case, why doesn't this happen to all the other sites on the server that use the exact same key? There are 4 other sites that use this exact same cert that do not experience this problem.
December 7th, 2009 9:59pm

Things happen....I had a similar issue with a certificate that I'd been using for a while, then one day I could no longer use it...I looked in the logs and I was getting that private key error.I deleted it, reimported and it worked.Don't ask how they get messed, I guess....
Free Windows Admin Tool Kit Click here and download it now
December 8th, 2009 2:49am

Tried that. No change.
December 9th, 2009 1:18am

Hi DGentry,If the private key is not configured with the proper ACL for the network service, you usually see the above events .
Free Windows Admin Tool Kit Click here and download it now
December 9th, 2009 5:39am

Okay, then why is the problem only with "DefaultSite" and not any of the OTHER sites that use that cert?How do I check the ACL?Thanks for the help.
December 9th, 2009 6:00pm

Okay, edited the ACL. No change.
Free Windows Admin Tool Kit Click here and download it now
December 16th, 2009 1:26am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics