all groups > iis security > april 2004 >
You're in the

iis security

group:

schannel errors after installing MS04-11, MS04-12


schannel errors after installing MS04-11, MS04-12 Will
4/30/2004 1:15:34 PM
iis security:
Platform (both servers are configured as below)
Windows 2000 Server/IIS5
Service Pack 4
Verisign 128 bit Premium SSL ID

After installing MS04-11 and -12 I began getting schannel errors in event
viewer. I installed both patches at teh same time so I'm not sure which may
be the culprit. I have pasted the entire entry below. Based on the text of
the error I am guessing this is due to older browsers attempting to connect
to the site. I am able to make SSL connections from Windows 2000 IE6 and
Netscpe 7.2 clients as well as OSX/IE 5.2, OSX/Netscape 7.01. Has anyone
else seen this? Thanks.

Event Type: Error
Event Source: Schannel
Event Category: None
Event ID: 36874
Date: 4/25/2004
Time: 7:33:10 AM
User: N/A

Description:
An SSL connection request was received from a remote client application, but
none of the cipher suites supported by the client application are supported
by the server. The SSL connection request has failed.

Re: schannel errors after installing MS04-11, MS04-12 Rob H
5/2/2004 8:59:32 PM
I'm getting the same thing too, not sure which browsers are affected but
i've seen the error several times in my event log since installing the
updates. I've heard uninstalling will correct this, but i would not
uninstall those updates quite yet. We were hacked last week, they used
the MS04-011 vulnerablility. We're still waiting for a Microsoft
resolution or fix. If anyone knows how to fix this (without
uninstalling the updates), please post your fix.

*** Sent via Developersdex http://www.developersdex.com ***
Re: schannel errors after installing MS04-11, MS04-12 Will
5/7/2004 12:01:07 PM
Rob
It looks like the errors are due to an exploit that attempts to use one of the holes fixed by MS04-011. This explains why I only got the errors after the patch - because the exploit was only created after the patch came out. Previously I didn't notice that the errors in the event logs on both servers occur at the same time - again because it is a network exploit and both my servers are on the same subnet so they got hit at the same time. This also explains why I couldn't replicate any failed attempts when I connected with various browsers - they really are not failed browser attempts

AddThis Social Bookmark Button