How do I fix apps that use schannel failing to reach the revocation servers?

quak 0 Zuverlässigkeitspunkte
2026-01-25T04:05:00.15+00:00

Various applications like the rust compiler toolchain as well as Battle.net client and others use the windows schannel to connect to the internet.

For some obscure reason they cannot validate if the certificate used for the TLS connection is still valid. The connection fails and both the windows event log and the apps error log tell you the sever to check for revocations cannot be reached.

I checked both crl and ocsp servers with curl and the browser, I can also ping them and the name resolution works fine as well.

There isn't an obvious connection issue.

I looked around the internet and couldn't find any obvious setting that I might have changed without remembering the details.

I am looking for pointers.

Windows für Zuhause | Windows 10 | Internet und Konnektivität
0 Kommentare Keine Kommentare

1 Antwort

Sortieren nach: Am hilfreichsten
  1. Ian-Ng 14,180 Zuverlässigkeitspunkte Externe Microsoft-Mitarbeiter Moderator
    2026-01-26T18:19:47.74+00:00

    Please be aware that you are posting on a German forum. However, your post's content is in English rather than German. As a result, I will reply to you in English. 


    Hi @quak,   

    Welcome to Microsoft Q&A forum. 

    Regarding the issue described, where applications using the Windows Schannel security package fail to reach revocation servers typically comes from a failure in the OS's native networking stack rather than a general loss of internet connectivity. 

    Because Schannel often operates under a "fail-closed" policy, an inability to verify a certificate’s status via CRL or OCSP leads to an interrupted connection. Kindly follow technical pointers that are recommended for troubleshooting:

    1. Resetting WinHTTP proxy settings 

    Applications like the Rust toolchain and Battle.net frequently depend on WinHTTP settings, which are distinct from the standard WinInet settings used by most web browsers. A lingering or incorrect proxy configuration here can block Schannel's access to revocation endpoints. 

    • Firstly, verify by executing netsh winhttp show proxy in an admin Command Prompt. 
    • If an unintended proxy is present, execute netsh winhttp reset proxy. 

    2. Then clear revocation caches 

    Windows maintains local caches for CRLs and OCSP responses. If these caches contain corrupted or outdated data, Schannel may fail to initiate a fresh connection to the revocation server. 

    Execute the following commands in an administrative Command Prompt: 

    • certutil -urlcache crl delete 
    • certutil -urlcache ocsp delete 

    3. Address SSL inspection and interception 

    Third-party security software (e.g., Antivirus "Web Shields") often intercepts TLS traffic by injecting its own certificates. Therefore, temporarily disable HTTPS or SSL scanning within the security software to determine if the connection failure persists. 

    4. Application-Specific workarounds 

    For development environments where network restrictions are rigid, you may bypass these checks at the application level. 

    • Rust/Cargo: Modify the .cargo/config.toml file to include: 

    I hope this information is helpful. Please follow these steps and let me know if it works for you.

    War diese Antwort hilfreich?


Ihre Antwort

Antworten können von Fragestellenden als „Angenommen“ und von Moderierenden als „Empfohlen“ gekennzeichnet werden, wodurch Benutzende wissen, dass diese Antwort das Problem des Fragestellenden gelöst hat.