Site icon EfmSoft

What does HRESULT 0x80090359 (SEC_E_ISSUING_CA_UNTRUSTED_KDC) mean?

 
Previous Next
SEC_E_REVOCATION_OFFLINE_KDC SEC_E_KDC_CERT_EXPIRED

SEC_E_ISSUING_CA_UNTRUSTED_KDC

Trust failure for the KDC certificate chain

For PKINIT, the client must accept the certificate that proves the identity of the Key Distribution Center. This status means that the issuing CA for that KDC certificate did not lead to an acceptable trust decision on the affected machine. It is not the same as an unreachable CRL or an expired certificate: the chain itself is not trusted for this use.

A seemingly correct certificate can still fail if the DC selected a different certificate than expected, an intermediate certificate is missing, the root is absent from the relevant trust store, the issuing CA is not published in the locations required by the AD smart card deployment, or the certificate profile does not satisfy the KDC role.

Establish which chain Windows used

References


Looking for a different code? Search another status or error code.

Exit mobile version