Client Certificate Authentication for XMS but the Client Certificate Request

Anonymous
2023-12-05T14:32:20+00:00

After configuring Client Certificate Authentication for XMS but the Client Certificate Request on the both the XMS and Issuing Server is returning a HTTP Response 403 Frobidden

com.zenprise.zdm.pki.spi.IssuingServiceException: Could not sign CSR
    at com.zenprise.zdm.pki.internal.util.AbstractIssuingAdapter.issueDirect(AbstractIssuingAdapter.java:147)
    at com.zenprise.zdm.pki.internal.util.AbstractIssuingAdapter.issueCredential(AbstractIssuingAdapter.java:92)
    at com.citrix.cdg.CommonDeviceGatewayBiz.getAgUserAuthCredential(CommonDeviceGatewayBiz.java:195)
Caused by: com.sparus.nps.pki.CertificateSigningException: Could not sign certificate
    at com.zenprise.zdm.pki.util.MsCertSrvSigningService.signRequest(MsCertSrvSigningService.java:107)
    at com.zenprise.zdm.pki.util.CredentialCaFactory$CredentialCa.sign(CredentialCaFactory.java:204)
    at com.zenprise.zdm.pki.internal.util.AbstractIssuingAdapter.issueDirect(AbstractIssuingAdapter.java:137)
Caused by: java.io.IOException: Cannot obtain certificate from certsrv authority: 403 Forbidden
    at com.sparus.nps.pki.connector.MsCertSrvConnector.generateClientIdentity0(MsCertSrvConnector.java:252)
    at com.sparus.nps.pki.connector.MsCertSrvConnector.generateClientIdentity(MsCertSrvConnector.java:207)
    at com.zenprise.zdm.pki.util.MsCertSrvSigningService.signRequest(MsCertSrvSigningService.java:90)

Windows Server Devices and deployment Set up, install, or upgrade

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2023-12-06T03:06:43+00:00

    Hello عبدالله محمد ابراهيم

    Thank you for posting on the Microsoft Community Forums.

    Based on the description, I understand that your issue is related to XMS.

    XMS belongs to Citrix, please contact Citrix to resolve your problem.

    Kind regards,

    Lei

    0 comments No comments