Forum Discussion
Exchange 2013 The certificate key algorithm is not supported
Hi.
1. Please check to enable TLS 1.2 and cipher by the IIS Crypto tool.
Technical reference details about encryption
https://docs.microsoft.com/en-us/microsoft-365/compliance/technical-reference-details-about-encryption?view=o365-worldwide
2. Please check the same on your client's PC.
PS. I recommend reviewing or creating GPO for TLS 1.2 and cipher
Server cipher suites and TLS requirements
https://docs.microsoft.com/en-us/power-platform/admin/server-cipher-tls-requirements
Exchange Server TLS guidance, part 1: Getting Ready for TLS 1.2
- Oleg_KovalenkoDec 30, 2021Brass Contributor
Russell,
Please check and install .NET Framework 4.8 and all windows update.After the update, please check TLS .Net.
Transport Layer Security (TLS) best practices with the .NET Framework https://docs.microsoft.com/en-us/dotnet/framework/network-programming/tls
Update and configure the .NET Framework to support TLS 1.2
https://docs.microsoft.com/en-us/mem/configmgr/core/plan-design/security/enable-tls-1-2-client#bkmk_net- Dominic RussellJan 05, 2022Copper Contributor
As mentioned, it was working few months back, so TLS 1.2 is already activated and working. The server is 2012R2. I installed .Net 4.8 just in case it would make any difference, but not. How to troubleshoot what is the error exactly and what triggers it? It would be preferable to pinpoint the source of the issue instead of trying settings and installation of programs...
Interesting fact I forgot to mention, the login screen appears correctly, it is after logging in that the web page shows this error.
- Oleg_KovalenkoJan 11, 2022Brass ContributorHi Russel.
Please check your cert store and certificate.
Check store.
Example. https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/technical-reference/ad-fs-and-keyspec-property
Test TLS connection
https://techcommunity.microsoft.com/t5/azure-paas-blog/ssl-tls-connection-issue-troubleshooting-test-tools/ba-p/2240059
Maybe you have the certificate expired or use 1024 bit
https://www.comodo.com/e-commerce/ssl-certificates/upgrade-ssl-certificate-to-2048-bit-before-31-december.php