Re: .Net client and SSL mutual authentication : 403 Forbidden, client certificate not sent

From: Dominick Baier [DevelopMentor] (dbaier_at_pleasepleasenospamdevelop.com)
Date: 10/10/05

  • Next message: Gery D. Dorazio: "Re: Where is the user impersonation token stored?"
    Date: Mon, 10 Oct 2005 09:50:03 -0700
    
    

    Hello Mfenetre,

    So your client is running as network service? this means that the cert has
    to be in the Local Machine/MY store - is that the case?

    ---------------------------------------
    Dominick Baier - DevelopMentor
    http://www.leastprivilege.com

    > Hello Dominick,
    >
    > Yes it works with IE or Firefox.
    > That's what makes me think that in my .Net client the client
    > certificate is not used/sent.
    > Perhaps it doesn't have access to the private key but I've followed
    > this article :
    > http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnnet
    > sec/html/SecNetHT13.asp
    >
    > and granted access to the "Network Service" :
    >
    > WinHttpCertCfg.exe -g -c LOCAL_MACHINE\MY -s "CreditCardClientSSL" -a
    > "Network Service"
    >


  • Next message: Gery D. Dorazio: "Re: Where is the user impersonation token stored?"

    Relevant Pages

    • Re: IIS website - only allow users with client cert from our CA. P
      ... Rootyou wish to permit certificates issued from for access to your site. ... our CA's client cert? ... I only have a server certificate from our CA ...
      (microsoft.public.inetserver.iis.security)
    • Re: IIS website - only allow users with client cert from our CA. Possi
      ... > Why does IIS allow me to see my website when it doesn't have ... > our CA's client cert? ... I only have a server certificate from our CA ...
      (microsoft.public.inetserver.iis.security)
    • RE: Certificate logon on Unix
      ... I don't know of any package but there is prolly one out there you should ... The good news is that getting fulle client ... and server side authentication is pretty easy so it will work as a quick ... setup your CA and make the root cert Pbk available to everyone. ...
      (Security-Basics)
    • Re: Radius Server
      ... > so I'm guessing the client needs the Server Certificate, ... > export it from the server and import it to the client. ... >> But if you deployed EAP-TLS, you need a server cert and a client ...
      (microsoft.public.windows.server.networking)
    • Re: EAP-TLS / Radius & AD
      ... I'm especially interested in the part "IAS authenticating the client by ... >> What checks must the authentication server perform against AD to be ... > the cert, ...
      (microsoft.public.internet.radius)