IIS SSL and Clien Certificates

anonymous_at_discussions.microsoft.com
Date: 02/19/04


Date: Thu, 19 Feb 2004 08:56:24 -0800

Hi Brian,

Well, if you figure it out please tell me, too. I am having
the same problem. Check out my question "Cannot establish
certificate chain for client authentication" posted here a
few days back.

The only way to get it to work for me right now (ie, client
gets a non-blank list) is to have the RootCA signs the
client cert.

SSL-er

>-----Original Message-----
>We are trying to migrate our Certificate Services from a
>third party to in house. I have created the following
>hierarchy:
>
>RootCA
> |
>SubCA
> |
>Website with issued
>certificate from SubCA
>
>
>Now I think everything is setup correctly, I have the Root
>Certificate installed on the server and the Root
>Certificate is part of the IIS CTL list (this is IIS 5.0
>on Windows 2000). Problem is that when the client
>retrieves a Certificate from the SubCA then attempts to
>navigate to the Website requiring client certificates,
>they get a Blank List of Certificates to choose from.
>
>Has anyone encountered this and know how to fix it? Any
>suggestions welcome, thanks in advance.
>
>-Brian
>.
>



Relevant Pages

  • Re: Quick Start certificate
    ... Where do I specify what the root path is. ... Then run the client. ... Did you give your web server identity permission to ... It's done through the certificate tool that's installed ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: Require Certificates
    ... Make sure the root CA is trusted on both client and on IIS server. ... > Empty certificate selection list is usually a sign of missing private key. ... >> certified the web site and imported the Root CA cert. ...
    (microsoft.public.win2000.security)
  • Re: RPC-HTTPS Certificate Question
    ... same as the public domain, "domain.com", I don't get the relay problem. ... > to the trusted root store, not the client certificate. ...
    (microsoft.public.exchange.setup)
  • Re: Cannot request computer certificate.
    ... >problem since you can not request a certificate while logged onto the CA. ... Verify that you can ping it by name and IP address from the client ... >> Kerberos, or dns. ... >> List of NetBt transports currently bound to the Redir ...
    (microsoft.public.windows.server.security)
  • Re: The message must contain a wsa:To header
    ... My client app is not generating a trace file. ... the client is not applying the WSE policy at all because of an ... at ApplicationMessagingWS.Dispatch(String messageType, String ... look for a certificate with this subject name in the certificate store ...
    (microsoft.public.dotnet.framework.webservices.enhancements)

Quantcast