The status code a refused OpenSecureChannel carries on the wire, given the
certificate manager's verdict on the client certificate.
Part 4 Table 104 (OpenSecureChannel service result codes) lists what a
client may be told. A client can act on these, so they pass through:
BadCertificateTimeInvalid: the certificate is out of its validity period,
BadCertificateUseNotAllowed: the certificate is not an application
instance certificate,
BadCertificateRevocationUnknown: the certificate's own CA has no
revocation list; the CTT accepts it (Security Certificate Validation
042 and 043).
Everything else is BadSecurityChecksFailed: an untrusted, revoked or badly
signed certificate must not learn from the answer what the server's trust
list holds. That includes BadCertificateIssuerRevocationUnknown, the
verdict when an issuer of the chain cannot be checked for revocation:
Errata 1.04.12 says a server should answer BadSecurityChecksFailed there,
and the CTT (Security Certificate Validation 002) warns about the precise
code (FEAT-44).
The status code a refused OpenSecureChannel carries on the wire, given the certificate manager's verdict on the client certificate.
Part 4 Table 104 (OpenSecureChannel service result codes) lists what a client may be told. A client can act on these, so they pass through:
Everything else is BadSecurityChecksFailed: an untrusted, revoked or badly signed certificate must not learn from the answer what the server's trust list holds. That includes BadCertificateIssuerRevocationUnknown, the verdict when an issuer of the chain cannot be checked for revocation: Errata 1.04.12 says a server should answer BadSecurityChecksFailed there, and the CTT (Security Certificate Validation 002) warns about the precise code (FEAT-44).