IBCM Server_Internal CA Web Server Authentication Certificated > External VAPT >> Intermediate Certificate Missing / Chain In-Complete

Deepak Verma 1 Reputation point
2020-09-17T10:48:50.287+00:00

Team,

We are using Internal CA web server authentication certificate with IBCM Server....configured in IIS.

Clients are happily connecting to server.

But during a recent VAPT assessment , We get a RED MARK for IBCM public FQDN.

It says : Certificate is not Trusted.....Chain is In-Complete......Intermediate Certificate is missing.

Kindly suggest.

Microsoft Configuration Manager
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Jason Sandys 31,186 Reputation points Microsoft Employee
    2020-09-17T21:55:07.48+00:00

    Suggest what exactly?

    This isn't specific to ConfigMgr in any way and needs to be addressed with your PKI folks. Basically, it means that the certificate for your intermediate CA is not accessible. That's a PKI specific issue because the PKI isn't publishing the certificate to the Internet.


  2. Amandayou-MSFT 11,051 Reputation points
    2020-09-21T06:10:52.95+00:00

    Here is the article about the details of deploying PKI Certificates for your reference:
    https://www.prajwaldesai.com/deploy-pki-certificates-for-sccm-2012-r2/
    Note: the above links are not from MS, and just for your reference.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments