Schannel Error Event ID 36877

Every time a client connects to our server, this error is being generated. I noticed a batch of them when the server was rebooted and every morning when the client computers boot up.

"The certificate received from the remote client application has not validated correctly. The error code is 0x80090325. the attached data contains the client certificate."

I checked the content as indicated and it appears to be the user certificate issued by the front-end server to each user sip address. The dates are valid on the certificates but when viewing the certificate on the PC client, it shows "Windows does not have enough information to verify this certificate".

We are not experiencing any problems with our clients, but would like to prevent our logs from getting filled up with this error. Since I haven't found any mention of this error in relation to Lync, I have to assume it isn't common.

January 26th, 2013 11:01pm

Hello,

As I understand its happennig only a client.

- Have you tried to change client from domain to workgroup and  re adding to domain?

- Please try to install certificate manually and overwrite it.

http://social.technet.microsoft.com/Forums/en/w7itprogeneral/thread/aa2776a5-a8ef-4241-bd71-0a0d672e18b0

Regards

Free Windows Admin Tool Kit Click here and download it now
January 26th, 2013 11:54pm

The error is generated in the front end server logs every time a client initiates a connection. No errors appear on the actual client.

A certificate is issued by the front end server for each sip user on a computer and is placed in the users personal certificate store. I am not sure how adding and removing the PC from the domain will impact a non-domain certificate.

I guess I could delete the certificate and see if Lync will recreate it. Not sure how to manually generate one for Lync communications.

January 27th, 2013 12:10am

Hi,

Where do you request the certificate from, enterprise root CA or public CA?

If all users' lync clients cause this issue, maybe something wrong with the certificate on Lync FE server. Please request a new certificate and install it on the Lync FE server again.

Free Windows Admin Tool Kit Click here and download it now
January 29th, 2013 5:47am

The certificate was self-generated by Lync.
January 31st, 2013 3:46am

Did you solved this?

I can see the same Events whenever a Client Login to Lync.

Something I couldn't try until now is Fixing the availability of CRL (Certificate Revocation List). It is blocked due a Proxy issue.

I didn't forced the People to fix their Proxy issue, as Lync seems to work normally.

Free Windows Admin Tool Kit Click here and download it now
January 15th, 2014 6:52pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics