3.1.5 Message Processing Events and Sequencing Rules

In the TLS negotiation, the client provides the "Local Certificate" exposed by [MS-BPAU] section 3.2.1.1. Whenever the client establishes a TLS session in order to send a message, it MUST verify that the server certificate has the following characteristics:

If any verification test fails, the client MUST terminate the TLS session as detailed in [RFC2246] section 7.3 and react as to a connection failure.