Microsoft KB Archive/285069

= How do I fix the blank certificate list displayed when I browse to an IIS 5.0 Web site? =

Article ID: 285069

Article Last Modified on 3/9/2006

-

APPLIES TO


 * Microsoft Internet Information Services 5.0

-



This article was previously published under Q285069



SUMMARY
This article answers the following question:

How can I fix the empty or blank client or personal certificate list that is displayed when I browse to an Internet Information Server (IIS) 5.0 Web site?



MORE INFORMATION
The empty or blank certificate list is usually displayed because either you have no client certificates or you have no client certificates that are trusted by IIS. A third, less common reason stems from a corrupted Certificate Trust List (CTL) on the client or IIS computer.

The CTL is built from certificates in the Trusted Root Certification Authorities certificate store and corruption is usually in the form of two or more certificates with the same Issuer identity. These duplicate identities are usually caused by repetitive installations of root certificates or certificates that are installed to the wrong certificate store.

To eliminate duplicate certificates, follow these steps:  Locate the thumbprint of the root Certificate Authority (CA) certificate that was used to sign (that is, verify) the personal or client certificate that you want to use.  In Internet Explorer on the client computer, on the Tools menu, click Internet Options. Click the Content tab, and then click Certificates. Select the Personal certificate store. Double-click the client certificate that you are trying to use. Click the Certification Path tab. Double-click the top certificate in the path.</li> Click the Details tab.</li> Scroll down to the Issuer and Thumbprint extensions and make a note of these values. You will use these to identify and remove duplicate identities on the client computer and IIS server.</li></ol> </li> On the client computer, remove duplicate certificates. <ol style="list-style-type: lower-alpha;"> In Internet Explorer on the client computer, on the Tools menu, click Internet Options.</li> Click the Content tab, and then click Certificates.</li> Select the Trusted Root Certification Authorities certificate store.</li> Double-click the client certificate that you are attempting to use.</li> Compare the Issuer and Thumbprint fields to the client certificate Issuer and Thumbprint fields. Delete any certificates that MATCH the client certificate's Issuer but that DO NOT match the client certificate's Thumbprint.

Note Also delete any certificates that have different Issuer and Subject (that is, Issued To and Issued By) fields, because all certificates in this store must be &quot;self-signed&quot; (that is, they must have the same Issuer and Subject).</li></ol> </li> On the IIS computer, add the Certificates (Local Computer) Microsoft Management Console (MMC) snap-in. <ol style="list-style-type: lower-alpha;"> Open a new Management Console. To do this, click Start, click Run, type Mmc.exe, and click OK.</li> On the Console menu, click Add/Remove Snap-in.</li> Click Add.</li> Double-click Certificates, select Computer Account, and then click Next.</li> In the Select Computer dialog box, select Local Computer, click Finish, and then click Close to close the Add Standalone Snap-in dialog box.</li></ol> </li> On the IIS computer, remove duplicate certificates. <ol style="list-style-type: lower-alpha;"> <li>Expand the Certificates (Local Computer) node.</li> <li>Expand the Trusted Root Certification Authorities node.</li> <li>Expand the Certificates node.</li> <li>Double-click the client certificate that you are attempting to use.</li> <li>Compare the Issuer and Thumbprint fields to the client certificate Issuer and Thumbprint fields and delete any certificates that MATCH the client certificate's Issuer but that DO NOT match the client certificate's Thumbprint.

Note Also delete any certificates that have different Issuer and Subject (that is, Issued To and Issued By) fields, because all certificates in this store must be &quot;self-signed&quot; (that is, they must have the same Issuer and Subject).</li></ol> </li></ol>

Additional query words: blank empty certificate personal client require

Keywords: kbhowto kbfaq KB285069

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.