Re: Certification anonymous dialog (once again)

From: Andreas Klein [MSFT] (andrekl_at_online.microsoft.com)
Date: 06/30/03


Date: Mon, 30 Jun 2003 15:59:07 +0200


Hi Arek,

can you please confirm that the certificate the client sends has the client
auth OID listed in it's enhanced key usage attribute?

I take it that the client owns the complete keyset and not only the
certificate. Correct?

Basically I think you are almost there.
- The server certificate is working as https://servername gets you back a
response.
- You are saying that the CA that gave out the client certificate is in the
trusted root CA store of the server computer.
- You have enabled "accept client cert" on the website.

This all boils down to a problem with the client cert you use and/or the
client application. Can you use IE as the client to test the keyset/cert?

-- 
Mit freundlichen Grüßen /  Kind Regards,
Andreas Klein
Microsoft Services
Die Inhalte der in dieser Newsgroup eingestellten Nachrichten stammen von
Dritten. Microsoft kann daher für die Richtigkeit und Vollständigkeit der
Inhalte keine Haftung übernehmen.
This posting is provided "AS IS" with no warranties, and confers no rights.


Relevant Pages

  • Re: Cannot request computer certificate.
    ... >problem since you can not request a certificate while logged onto the CA. ... Verify that you can ping it by name and IP address from the client ... >> Kerberos, or dns. ... >> List of NetBt transports currently bound to the Redir ...
    (microsoft.public.windows.server.security)
  • Re: The message must contain a wsa:To header
    ... My client app is not generating a trace file. ... the client is not applying the WSE policy at all because of an ... at ApplicationMessagingWS.Dispatch(String messageType, String ... look for a certificate with this subject name in the certificate store ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: L2TP/IPSec from XP client to Windows 2003 Server
    ... ie no valid cert found on client - contacted Microsoft ... Windows Server 2003 Certificate Authority running ... The next step is to install Certificate Services on the Windows Server ... From Networks Connections on the client, ...
    (microsoft.public.security)
  • Re: Cannot request computer certificate.
    ... I would verify that the certificate services service is running and set to ... Verify that you can ping it by name and IP address from the client ... > Kerberos, or dns. ... > List of NetBt transports currently bound to the Redir ...
    (microsoft.public.windows.server.security)
  • SNA 3270 to IP TN3270 Conversion =?ISO-8859-1?Q?=96?= Data Stream Encryption
    ... asked them on their thoughts regarding data stream encryption, ... which means that all data is encrypted before it is sent to the client. ... certificate and the keys from three different places: ... SSL client authentication provides additional authentication and access ...
    (bit.listserv.ibm-main)