Schannel Event id 36887 - alert code 42 - every 10 seconds

Hello,
We 've just installed a new Lync 2013 front end server  (standard) on Windows 2012 R2, migrating from Lync server 2010.
After moving users to new pool, we got many Schannel errors - every 10 seconds.
event id 36887
"A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 42"
No user is complaining about any trouble but I would like to get ride of those errors.
Thanks in advance for any input.
Pierro.

Most likely these are the certificates that were assigned from your lync 2010 to your clients and are not trusted by lync 2013. you can verify that by using get-csclientcertificate and see the certificates assgined to users.

Similar Messages

  • Schannel errors on three of my DC's; Event ID 36887, Alert 46

    I too am recieving the elusive schannel errors on three of my DC's, Event ID 36887, Alert 46. They only happen occasionally, at seemingly arbitrary times.
    All three are Domain Controllers only; no IIS installed, no Exchange servers. No one logs in to these and browses from them (yes, I checked the event logs). There are no third party browsers installed. I have even tried disabling TLS
    in the IE settings, no luck (not sure how or wy that would even work).
    I have read as many forum posts as I can on this, and am still no closer to understanding what is going on.
    How do I track this down?
    EventID : 36887
    MachineName : DCXY.Domain.us
    Data : {}
    Index : 27206
    Category : (0)
    CategoryNumber : 0
    EntryType : Error
    Message : The following fatal alert was received: 46.
    Source : Schannel
    ReplacementStrings : {46}
    InstanceId : 36887
    TimeGenerated : 3/26/2012 7:21:36 AM
    TimeWritten : 3/26/2012 7:21:36 AM
    UserName : NT AUTHORITY\SYSTEM
    Thanks!

    I REALLY NEED HELP! I AM NEW TO THIS LAPTOP, AND I DO NOT UNDERSTAND THIS IN MY EVENT VIEWER, IT SHOWS FATAL ERROR:
    Provider
    Name]
    Schannel
    Guid]
    {1F678132-5938-4686-9FDC-C8FF68F15C85}
    EventID
    36887
    Version
    0
    Level
    2
    Task
    0
    Opcode
    0
    Keywords
    0x8000000000000000
    TimeCreated
    SystemTime]
    2014-01-12T21:23:37.220815100Z
    EventRecordID
    5190
    Correlation
    Execution
    ProcessID]
    660
    ThreadID]
    6336
    Channel
    System
    Computer
    5CD3182MR2
    Security
    UserID]
    S-1-5-18
    EventData
    AlertDesc
    40
    I REALLY NEED HELP WITH THIS I AM ON A NEW LAPTOP AND DONT UNDERSTAND!! PLEASE ADVISE OR HELP!!

  • Schannel errors on our Primary DC's; Event ID 36887, Alert 46

    I have one of my 4 Domain Controllers that is getting this EventID 36887 error every 60 seconds since our DC cert auto-renewed itself.  The internal CA is running on an non-DC server.  How do I determine what's triggering this alert so that I can
    squash it?  This alert is from the System Event logs on our Primary 2008 R2 DC (ORLDC01.cnlgroup.com).
    Log Name:      System
    Source:        Schannel
    Date:          1/13/2014 5:06:56 PM
    Event ID:      36887
    Task Category: None
    Level:         Error
    Keywords:     
    User:          SYSTEM
    Computer:      ORLDC01.cnlgroup.com
    Description:
    The following fatal alert was received: 46.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Schannel" Guid="{1F678132-5938-4686-9FDC-C8FF68F15C85}" />
        <EventID>36887</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2014-01-13T22:06:56.581253200Z" />
        <EventRecordID>493191</EventRecordID>
        <Correlation />
        <Execution ProcessID="552" ThreadID="1848" />
        <Channel>System</Channel>
        <Computer>ORLDC01.cnlgroup.com</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="AlertDesc">46</Data>
      </EventData>
    </Event>

    Hi,
    Based on my research, the error code which means certificate_unknown(46), to find out what triggered this alert. I think you need capture a network trace while getting this error. More information please refer below article:
    How to use Network Monitor to capture network traffic
    http://blogs.msdn.com/b/ssasfaq/archive/2012/09/17/how-to-use-network-monitor-to-capture-network-traffic.aspx
    If there have no impact related this error, we can safely ignore this error. Otherwise, to address this error we might need capture ETL trace and networks trace. It is not an efficient way to work in this community since we may need more resources, if need
    further troubleshooting I would like to suggest you submit a service request to MS Professional tech support service so that a dedicated Support Professional can further assist with this request.
    Please visit the below link to see the various paid support options that are available to better meet your needs.
    http://support.microsoft.com/default.aspx?id=fh;en-us;offerprophone
    Thanks

  • Charging alert continues every second while charging

    My iPad bleeps every second now when plugged into its charger. First time it's occurred, charging from 14%... Any fixes, ideas, solutions?

    Try turning it off.
    Try resetting it,  hold down the sleep and home keys, past when you see the red power down slider and until you see the silver apple. Let it reboot and see if that helps.
    I've also gotten that chirping to go away by simply unplugging and replugging the charger.

  • Schannel event ID 36888 , alert 43, internal error state 252

    When i go to certain sites in IE, i get the following error and IE reports that it could not connect to the site.
    Any ideas where to start looking.
    I'm running Windows 7 Pro X64 Sp1
    - <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    - <System>
    <Provider
    Name="Schannel"
    Guid="{1F678132-5938-4686-9FDC-C8FF68F15C85}" />
    <EventID>36888</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated
    SystemTime="2012-12-03T21:55:46.193662500Z" />
    <EventRecordID>26882</EventRecordID>
    <Correlation
    />
    <Execution
    ProcessID="808" ThreadID="6052" />
    <Channel>System</Channel>
    <Computer>redearl-toy</Computer>
    <Security
    UserID="S-1-5-18" />
    </System>
    - <EventData>
    <Data Name="AlertDesc">43</Data>
    <Data Name="ErrorState">252</Data>
    </EventData>
    </Event>

    Hi,
    Whether this issue only occurred with this website. Have you tried using another computer or other browser to test the issue.
    If this issue only occurred with specific website, it is better to contact the website for more help.
    In addition, here is a thread for your reference:
    http://social.technet.microsoft.com/Forums/en-US/windowsserver2008r2general/thread/6b0d1a30-753d-491e-b2b2-dc1a1111dd51
    Regards,
    Vincent Wang
    TechNet Community Support

  • Event ID 36887, Schannel 45

    Hi,
    I've been noticing the following in the Event Log:
    Event 36887, Schannel
    The following fatal alert was received: 45
    Log Name - System
    Source - Schannel
    Event ID - 36887
    Level - Error
    User - System
    OpCode: Info
    It points to an expired certificate, the thing is there are no expired certificates on this server.  The one SSL cert that I do have (for our RMM tool/IIS) is good until 2017 and has been on the system since 2012.
    I ran DigiCert's utility for finding expired certificates to confirm this.
    We thought it may be related to ConnectWise (our PSA) and had that certificate re-issued (although it was good for a couple more years also) and it made no change.  I get the errors about once per 5 minutes on this server.  It's running Server
    2008 R2 and is fully patched.
    Any ideas on how I can track down what certificate, if any, is causing this error?
    Thanks,
    Marc

    Hi Marc,
    I am sorry for the delay.
    Are there any related error messages logged under Application Logs?
    If not, then we can safely ignore this message, please refer to some related links below:
    event id 36887, alert 45
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/6cd9c7dd-140a-4779-9d8e-1059f7769cba/event-id-36887-alert-45?forum=winserversecurity
    36887 Event Id
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/4b138f13-5c5c-43f5-80b5-bcc50bc4be60/36887-event-id?forum=winservergen
    SSL/TLS Alert Protocol & the Alert Codes
    http://blogs.msdn.com/b/kaushal/archive/2012/10/06/ssl-tls-alert-protocol-amp-the-alert-codes.aspx
    I hope this helps!
    Best Regards,
    Amy Wang

  • Event ID 36887 Schannel - fatal alert code 49

    Use process explorer and refer to the PID in the event log. This should at least tell you what program is creating the event, narrowing down the cause a bit.

    Windows Server 2012 R2 Hyper-V VM Fileserver.
    Have these errors happening consistently in event viewer every 2 to 3 minutes.
    Am not running web server, just a file server.
    Any ideas on how to track this down?
    Not seeing much info on 36887 with code "49"
    Anyone else had/solved this problem?
    This topic first appeared in the Spiceworks Community

  • Updating JTable every second, want to ignore these events in my listener

    I have a JTable that I update every second using
    table.getModel().setValueAt(data, row, col);I'm also reacting to when the user clicks on a row in a the table, using a ListSelectionListener:
    public class MyTableListener implements ListSelectionListener {
              public void valueChanged(ListSelectionEvent e) {
                   if (e.getValueIsAdjusting()) return;
                   //do stuff
    }And of course I've done this:
    table.getSelectionModel.addListSelectionListener(new MyTableListener());Problem is, every time I update the table data it generates an event handled by valueChanged() above. I need to prevent this.
    Do I need a customized table model for this?
    Thanks!

    Found the problem: I forgot I was using JXTable, not JTable. Here's my example:
    import javax.swing.*;
    import javax.swing.event.*;
    import javax.swing.table.*;
    import java.awt.*;
    import org.jdesktop.swingx.*;
    public class Test {
         JXTable table = null;//change this to JTable to fix
         public class MyTableListener implements ListSelectionListener {
              public void valueChanged(ListSelectionEvent e) {
                   System.out.println("event="+e.toString());
         public Test()
              JFrame frame  = new JFrame();
              String columns[] = {"one", "two"};
              Object data[][] = {{0, 0}, {0, 0}, {0, 0}};
              table = new JXTable(data, columns);//change this to JTable to fix
              table.getSelectionModel().addListSelectionListener(new MyTableListener());
              frame.add(new JScrollPane(table, JScrollPane.VERTICAL_SCROLLBAR_AS_NEEDED, JScrollPane.HORIZONTAL_SCROLLBAR_AS_NEEDED),
                          BorderLayout.CENTER);
              startThread();
              frame.setVisible(true);
         public static void main (String args[]) {
              Test test = new Test();
         public void startThread()
              class RefreshThread extends Thread {
                   public void run() { try {
                             while(true) { SwingUtilities.invokeLater(new Runnable() {public void run() {
                                       updateTable();
                                  sleep(1*1000);
                        } catch (Exception e) {e.printStackTrace();}
              RefreshThread rt = new RefreshThread();
              rt.start();
         public void updateTable()
              TableModel model = table.getModel();
              try {
                   for(int row = 0; row < model.getRowCount(); row++)
                        model.setValueAt(System.currentTimeMillis(), row, 0);
                        model.setValueAt(System.currentTimeMillis(), row, 1);
              } catch (Exception e) {
                   e.printStackTrace();
    }When I change it to a JTable, valueChanged() is not called every time I programmatically update the table.
    If it's a JXTable, valueChanged() is called with every update. Annoying!
    To compile/run the JXTable version you'll need something like
    java -cp swingx-1.0.jar:. TestAs for the events themselves, I added print statements with e.toString() and the events are not distinguishable from user interaction. I wonder if this is a JXTable bug or feature.
    Thanks!

  • Alert beep every 2 seconds after latest update

    Just installed the latest update and after restart there is an alert beep every 2 seconds! Anyone else experiencing this?

    Check the RAM in about your Mac, the beep sometimes indicares trouble. Look at the console report and see of RAM is being allocated correctly. POst back with results.
    Ray

  • Multiple MSExchange RBAC events every second (event ids 264, 268, 270)

    Hi,
    Every second our Exchange 2013 server is writing multiple MSExchange RBAC events to the Application Event Logs, event ID 264, 268 and 270.  It has been doing this all day.
    The contents of the events are:
    264 - (Process w3wp.exe, PID 15836) "User: [email protected] Org:  got the VanriantConfigurationSnapshot"
    268 - (Process w3wp.exe, PID 15836) "Cmdlet: New-TransportRule, parameters (EncryptMessage,DecryptMessage) are disabled."
    270 - (Process w3wp.exe, PID 15836) "Cmdlet: Set-TransportRule, parameters () are enabled."
    Can anybody suggest why it is writing so many events in such a short space of time?

    Hi,
    Please check whether all the logs refer to the same user
    [email protected]
    If so, I suggest we use process monitor to see what did the user do:
    http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx
    Thanks,
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Simon Wu
    TechNet Community Support

  • Event log 36887

    I receive the following event.....
    A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 42. I cannot find much information on this. does anyone have any insight?
    Thank you

    Hi,
    Did there run IIS on the server? This error message indicates the computer received an SSL fatal alert message from the server. It may be caused by accessing web site or the installation of third party web browsers or others. Did you remember any specific
    operation that had been done before this issue occurred? For examples, install any third-party application or others? Please refer to following thread and check if can help you.
    Event ID: 36887 Source: Schannel, Error: The following
    fatal alert was received: 0.
    In addition, please also refer to following KB and enable Schannel event logging, then check if get more clues.
    How to enable Schannel event logging in IIS
    If any update, please feel free to let me know.
    Hope this helps.
    Best regards,
    Justin Gu
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • ToolBoxTools.addEventListener only works every second time

    Hi!
    Our layouts pretty often click on the "page tool" by mistake and it happened a few times, that they changes the size of the page without even noticing. Because there is no way to remove the tool from the toolbar (I guess?), I wanted to write a script, that at least shows a message, that the page tool ("Seitenwerkzeug" in german) was selected. Unfortunately the event listener only works every second time:
    1. indesign starts > selection tool is active
    2. click on page tool > message appears > page tool is active
    3. click on "another tool1" > "another tool1" is active
    4. click on "another tool2" > "another tool1" is active
    5. click on page tool > nothing happens, the icon of the page tool is active, but the icon of the "another tool2" is still active, too, and "another tool2" is still activated
    6. click on "another tool3" > "another tool3" is active
    7. click on page tool > message appears > page tool is active
    8. ......
    Any idea why that is?
    My script:
    #targetengine myToolListener
    app.toolBoxTools.addEventListener ("afterAttributeChanged", changeToolAlert);
    function changeToolAlert() {
        if(app.toolBoxTools.currentToolName == "Seitenwerkzeug") {
            alert ("Message", "Title");
        exit(); //i tried with and without this!
    At the beginning I tried to use an confirm message instead of an alert, which had the same problem and I thought it might be because the changing doesn't work... but it seems I can't even work with the information without something "crashing" in the background?
    My previous confirm Function:
    function changeToolConfirm() {
        if(app.toolBoxTools.currentToolName == "Seitenwerkzeug") {
            var confirmDialog = confirm("Do you really want to activate the page tool?", true);
            if(!confirmDialog) {
                app.toolBoxTools.currentTool = UITools.SELECTION_TOOL;
    I really hope someone has an idea
    Best,
    Anke

    Hi Anke,
    The problem, I think, comes from the fact that the Page Tool selection event (which you listen to via afterAttributeChanged) needs some time to complete. Since the alert() or confirm() instruction gives the focus to a new modal window before the event life-cycle is finished, the GUI becomes instable, the PageTool icon state is not properly restored, and your event management goes wrong.
    A way to solve this might be to queue a temporary IdleEvent listener once the Page Tool selection event is caught. That is, we do not initiate any modal dialog as long as the GUI is refreshing.
    Something like this:
    //====================================================
    // PageToolDisclaimer.jsx
    //====================================================
    // Should be useable as a startup script, no #targetengine required
    // NB - MutationEvent is known to create a global 'evt' variable
    // so we don't seem to need a persistent session engine here :-)
    // That's why the active script File is used as the event handler
    (function(/*File*/EVENT_HANDLER, /*str*/TASK_NAME, /*uint*/TASK_TIME, /*str*/PAGE_TOOL_NAME)
        var t;
        // Installer
        if( !(t=app.toolBoxTools.eventListeners).length )
            t.add(MutationEvent.AFTER_ATTRIBUTE_CHANGED, EVENT_HANDLER);
            return;
        // IdleEvent handler (--> confirm)
        if( (t=app.idleTasks.itemByName(TASK_NAME)).isValid )
            t.eventListeners.everyItem().remove();
            t.remove();
            if( !confirm("***WARNING***\rDo you really want to activate the page tool?", true) )
                app.toolBoxTools.currentTool = UITools.SELECTION_TOOL;
            return;
        // PageTool event handler
        if( ('evt' in $.global) && 'currentToolName'==evt.attributeName && PAGE_TOOL_NAME==evt.attributeValue )
            evt.stopPropagation();
            app.idleTasks.add({name:TASK_NAME, sleep:TASK_TIME})
                  .addEventListener(IdleEvent.ON_IDLE, EVENT_HANDLER);
    })(app.activeScript, 'WaitPageTool', 400, app.translateKeyString('$ID/Page Tool'));
    Hope that helps.
    @+
    Marc

  • [SCOM 2007 R2] Alert on every failed SQL job

    We want alert on every failed SQL Agent job.  However, we only get one alert.
    We check that SQL 2000 would alert on every failed SQL job, but SQL 2005 & 2008 didn't behavior like that.
    What should we do?
    Thanks.

    Hello Matt,
    For auditing purposes we need to email every sql job failure and sql job success.  What I've seen is if the out of box "A(n) sql job failed to complete sucessfully", it will generate only one alert until the alert is manually resolved.
    And the alert if generated from a server with many Sql instances, it will generate for each windows event the same alert for each instance.
    If I create a rule and use "sql jobs" as the "rule target" for each application event every job generates an alert.
    So, if we use "Last Run Status", when it's working, I've seen that if two failures are generated within the frequency interval specified "600" seconds by default only one alert is generated.
    The MOM rule that uses this criteria from the Application event log:
    Event Number equals '208'
     Source Name matches regular expression 'SQLServerAgent|SQLAgent.*'
     Parameter 1 doesn't match wildcard 'OnePoint - *'
     Parameter 3 matches regular expression '^(失败|Fehler|Failed|Error|Échec|Non[ ]riuscito|失敗|失敗|실패)$'  
    As far as I can tell works fine. 
    One other respondent recommends using "windows computer" as the "rule target".  I think this will have the same problem as the ootb rule and only generate an alert once.
    I think potentially a rule that uses "agent job" as the rule target would work if in the criteria, we could add "description" contains "job name".   But the gui doen't expose "event description" as a criteria.
    Any help would be appreciated.
    Thanks,
    Paul

  • Flex starting the video every second

    So I need some help, badly...
    I have a flex video player setup, and it's working great as
    long as I am pulling a video from the local drive like so:
    this.myVideoDisplay.source = "assets/media/testvidflash.flv";
    This plays great, works great, looks great... However if I
    change that single line of code to:
    this.myVideoDisplay.source =
    "rtmp://mydomain.com/media/video/public/testvidflash.flv";
    Then I get the video playing, but every second or so it
    starts another copy of the video in the background and I get this
    ever increasing echo.
    As best we can tell, the video file on the rtmp works fine in
    every other flash player we have tested, and I can create a new swf
    in CS3 and it works fine.
    Does anyone have any ideas?

    Mamata,
    thank you very much for your reply.
    What you say all make sence, and now I understand it better,
    I have a couple of more questions:
    1. When you say the network capability, you mean the viewer side or the server side?
    2. I read somwhere that the fms 3,5 has a feature of recognizing the users end speed and automatically adjusting the strem rate. So, it's eather I misunderstood the meaning of it, or this feature needs to be "switched on" somehow?
       Thank you

  • Write to measuremen​t file VI - every second, is that too fast ?

    I use the write to measurement file VI to save 5 values + a comment to a file. The VI is in a loop. The VI adds new values to the same file every time it is called. In one of the tutorials it is said "VIs can be more efficient if you avoid opening and closing the same files frequently". I understand that; the write to measurement file VI does open and close the same file every time it is called.
    I want the VI called every second to save new data. Tests I did with this rate did show problems. However, what is meant by frequently? Every second? Every millisecond? So my question is: is saving every 1 second, like I want, likely to cause problems, or isn't that time period hardly a problem? Or is there a better solution (although this VI gives me all possibilities I want, including saving a comment and saving to multiple files with nice filenames; I would really like to use this VI).
    -- flying dutchman --
    Attachments:
    write every second.jpg ‏25 KB

    The answer lies halfway between mine and Nukem's answers.  Instead of storing all values in a shift register until the end, you simply store them, for say 1 hour, and append to the file.  This also enables you to save some of your data in the event of a power failure or something.
    Use a nested for loop, the inner loop will run for say, 50 or 100 iterations, storing values in a shift register array.  Upon exiting this loop, the data is appended to your file.  The outer for loop will run for how many iterations out need.  
    For some simple examples, lets say you need 10,000 loops and you want to save every 100 iterations.  Have the inner loop run 100 times and the outer loop run 100 times.  

Maybe you are looking for

  • File Sender channel stopped polling on FTP site

    Dear all, We have many file to Idoc interfaces running in production and all are they good. Yesterday we faced one issue, one of the interface's sender communication channel stopped polling and didn't picked the files from FTP. There was no error on

  • My 5180 wont print on board screen says print cartridges refer to documentat​ion

    my 5180 won't print,on board screen,icon and says printer cartridges-refer to printer documentation.I did no help.I believe ink levels are good.

  • Issues with a SGE2000 switch

    It seems that the SGE2000 switch will lose the connections of systems after some period of time. I will ping a system and it will be slow or will not reply at all. See example below: C:\>ping 10.1.16.16 Pinging 10.1.16.16 with 32 bytes of data: Reply

  • Fatal error due to / in the value

    Hi XI Gurus I have follwing scenario: Mail ---> XI ---> R-3 In the few mails, i am receiving the <b></</b> as a part of node value. For ex. <Root> <Child>4534DECEFFDA1911E1</font> </Child> </Root> Please guide me to sort out this issue. Regards Piyus

  • Formating SQL Plus

    Hello, How do I remove # from my report ? TABLESPACE USED (MB) FREE (MB) TOTAL (MB) PER_FREE DLY_DATA 132,320 4,175 136,495 3 % CONFIG 7,621 749 8,370 9 % FDATA 210,299 4,234 214,533 2 % CONFIG_DATA 12,324 468 12,792 4 % CONFIG_IDX 3,793 303 4,096 7