Lync client constantly signs in and out

If SCHANNEL is sending a truncated list of trusted root certificate authorities to the Lync client during the TLS/SSL handshake process, this can explain why your Lync clients are randomly signing in and out.

Here’s the chain of events on more detail:

  1. The UC server passes its certificate trust list (CTL) of installed certification authority information to the UC client that requests the secure TLS connection.
  2. The CTL is truncated as per the design limitations of the Windows Server Schannel component.
  3. The UC client that requested the secure TLS connection does not receive certification authority information that matches the entries that are contained in its installed certification authority list.
  4. The TLS connection attempt fails with the error that is described in the “Symptoms” section.

To check this look in your Lync FE servers system event log for the following warning:
—-
EVENT ID: 36885
When asking for client authentication, this server sends a list of trusted certificate authorities to the client. The client uses this list to choose a client certificate that is trusted by the server. Currently, this server trusts so many certificate authorities that the list has grown too long. This list has thus been truncated. The administrator of this machine should review the certificate authorities trusted for client authentication and remove those that do not really need to be trusted.
—-

The easiest way to fix this is to configure SCHANNEL on the Lync FE’s not to send this list:

  1. Click Start, click Run, type regedit, and then click OK.
  2. Locate and then click the following registry subkey – KEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSecurityProvidersSCHANNEL
  3. On the Edit menu, point to New, and then click DWORD Value.
  4. Type SendTrustedIssuerList, and then press ENTER to name the registry entry.
  5. Right-click SendTrustedIssuerList, and then click Modify.
  6. In the Value data box, type 0 if that value is not already displayed, and then click OK.
  7. Exit Registry Editor.

You shouldn’t need to reboot the server for this to take effect.

For more information and other options on how to resolve this see Microsoft article –
http://support.microsoft.com/kb/2464556

 

Andrew Morpeth
Andrew Morpethhttps://ucgeek.co/author/amorpeth/
Andrew is a Modern Workplace Consultant specialising in Microsoft technologies based in Auckland, New Zealand; Andrew is a Director and Professional Services Manager at Lucidity Cloud Services and a Microsoft MVP.

Related Articles

NZ to get native Microsoft Teams calling

New Zealand (NZ) is set to get native Microsoft Teams calling by July 2021 - this feature allows you to replace your telephony solution with Microsoft Teams. Microsoft Teams calling for NZ further reduces the barrier to using Microsoft Teams as a telephony replacement solution for New Zealand businesses.

Microsoft Teams Calling Options for Telephony Replacement

Microsoft Teams Calling provides telephony replacement capability that could replace your PABX or any other solution you may have. This article takes you through the options and when to use them, and the licencing you will require to activate this feature for your users.
00:13:43

Skype for Business Response Groups Made Easy

Call Flow Manager for Skype for Business and Lync makes creating and managing Response Groups easy! No more bouncing between interfaces to configure a simple call flow. Call Flow Manager brings all the functionality of the Response Group service into a single user interface

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Andrew Morpeth
Andrew Morpethhttps://ucgeek.co/author/amorpeth/
Andrew is a Modern Workplace Consultant specialising in Microsoft technologies based in Auckland, New Zealand; Andrew is a Director and Professional Services Manager at Lucidity Cloud Services and a Microsoft MVP.

Latest Articles

NZ to get native Microsoft Teams calling

New Zealand (NZ) is set to get native Microsoft Teams calling by July 2021 - this feature allows you to replace your telephony solution with Microsoft Teams. Microsoft Teams calling for NZ further reduces the barrier to using Microsoft Teams as a telephony replacement solution for New Zealand businesses.

Microsoft Teams Calling Options for Telephony Replacement

Microsoft Teams Calling provides telephony replacement capability that could replace your PABX or any other solution you may have. This article takes you through the options and when to use them, and the licencing you will require to activate this feature for your users.
00:13:43

Skype for Business Response Groups Made Easy

Call Flow Manager for Skype for Business and Lync makes creating and managing Response Groups easy! No more bouncing between interfaces to configure a simple call flow. Call Flow Manager brings all the functionality of the Response Group service into a single user interface
00:13:30

Office 365 Backup with Synology NAS

There are many reasons that you may want to back up your Office 365 data. The most common reasons I see are data sovereignty...

Microsoft 365 Feature Roundup Dec 2020

Feature Roundup Presentation Microsoft 365 key feature releases and announcements for June to December 2020, in an easy to digest PowerPoint format.