Try changing the IP-Port combination to check if the website is accessible or not.

This is meant for troubleshooting SSL Server certificates issue only. I am under the assumption the reader is well-versed in SSL Handshake and the Server Authentication process during the SSL handshake.

It is important to know that every certificate comprises of a public key (used for encryption) and a private key (used for decryption). Description of the Secure Sockets Layer (SSL) Handshake: Description of the Server Authentication Process during the SSL Handshake: The following error message is seen while browsing the website over https: The first thing that has to be checked is whether the website is accessible over http. If not, then you need to have the website working on http first and that's a seperate issue (not covered in this troubleshooter).

However, I still get "Page cannot be displayed" error while accessing over https.

When a client connects and initiates an SSL negotiation, looks in its SSL configuration for the "IP: Port" pair to which the client connected. After all this if you are still unable to browse the website on https, then capture a network trace either from the client or server.

This material is provided for informational purposes only. This document will help you in troubleshooting SSL issues related to IIS only.

Client Certificates troubleshooting will not be covered in this document.While running the SSLDiag tool you may get the following error: You have a private key that corresponds to this certificate but Crypt Acquire Certificate Private Key failed There will also be a SChannel warning in the system event logs as shown below: The first 2 steps check the integrity of the certificate.Once we have confirmed that there are no issues with the certificate, a big problem is solved.The MS12-006 update implements a new behavior in schannel.dll, which sends an extra record while using a common SSL chained-block cipher, when clients request that behavior.The other change was in Wininet.dll, part of the December Cumulative Update for Internet Explorer (MS11-099), so that IE will request the new behavior.Check if the server certificate has the private key corresponding to it. Select the thumbprint section and click on the text below.Refer the below picture: If private key is missing, then you need to get a certificate containing the private key, which is essentially a . There is a command that we could try to run in order to associate the private key with the certificate: If the association is successful, then you would see the following window: Note: 1a 1f 94 8b 21 a2 99 36 77 a8 8e b2 3f 42 8c 7e 47 e3 d1 33 is the thumbprint of the certificate. Do a "Ctrl A" and then "Ctrl C" to select and copy it.Now let's assume the website is accessible over http and we get the above error when trying to browse over https.The problem is seen because the SSL handshake failed and hence the error message was seen. We will follow a step-by-step approach to solve this problem.Below is a snapshot for your reference: Note: This command doesn't succeed always.If this fails, then you need to get a certificate containing the private key from the CA. Windows Server 2003: Download X64 Download X86 For IIS 7 and IIS 7.5, use vijaysk's SSL Diagnostics tool.

