If you get errors when clients are trying to access PKI restricted web pages similar to this:
[Thu Mar 14 09:19:58 2013] [error] [client 72.73.17.34] Certificate Verification: Error (20): unable to get local issuer certificate
It usually means a windows update has messed up the certificate chain in your internet explorer.
You can see this by going to
Tools -> Internet Options -> Content Tab
Certificates Button.Select your certificate
Click View Button
Then Click Certificate Path Tab
IF this shows 6 entries — or more than 3 — this is causing your problem.
To fix it:
Run the attached program:
FBCA_crosscert_remover_v106.exe
Restart your browser and check to see that you now only have 3 entries in the train.