Knowledge Base

Can't Connect to SSL-Enabled Site and/or Server Stops Responding

Article ID: 184321

Article Last Modified on 6/23/2005


APPLIES TO


This article was previously published under Q184321
We strongly recommend that all users upgrade to Microsoft Internet Information Services (IIS) version 6.0 running on Microsoft Windows Server 2003. IIS 6.0 significantly increases Web infrastructure security. For more information about IIS security-related topics, visit the following Microsoft Web site:

SYMPTOMS

On a Web site that has Secure Sockets Layer (SSL) enabled, either of the following problems may occur:

WORKAROUND

To work around this problem, try the following (each option is described in more detail below):

Verify That Schannel.dll Is Current

Verify that you are you have the latest version of Schannel.dll, the PCT/SSL Security Provider, for your version of Internet Information Server (IIS).

For IIS 3.0, Schannel.dll has the following file properties:
For IIS 4.0, Schannel.dll has the following file properties:

Verify that the ISAPI Filter Sspifilt.dll Is Installed

The active copy of Sspifilt.dll should be located in the \Winnt\System32\Inetsrv directory.

For IIS 3.0:

The following registry entry should be present and include the path to the active Sspifilt.dll file:

HKEY_Local_Machine\System\CurrentControlSet\Services\W3SVC\Parameters\Filter Dlls

For IIS 4.0:

From the Master Properties of the WWW service, on the ISAPI Filters tab, verify that there is an entry pointing to the active copy of the Sspifilt.dll file. This entry should be loaded and running (as indicated by a green up-arrow).

Remove and Reinstall Certificate Key

  1. For Internet Information Server version 3.0 (IIS), you may want to reinstall Service Pack 3 to ensure that all files are current.
  2. Using Key Manager, export the Certification Authority (CA) key (also known as a certificate) to a backup file.
  3. Delete the key, then close Key Manager. When prompted to "Commit all changes now?", click Yes.
  4. Stop and start the World Wide Web Publishing Service.
  5. In Key Manager, import the key you backed up in Step 2 of this procedure.
  6. Close Key Manager, being sure to again click Yes when you are prompted to "Commit all changes now?"
  7. Stop and start the World Wide Web Publishing Service.

Additional query words: https hang hangs hung fails akz

Keywords: kbprb KB184321