Client certificate authentication problem

From: Aleix (anonymous_at_discussions.microsoft.com)
Date: 03/24/04

  • Next message: Karl Levinson [x y] mvp: "** READ THIS BEFORE POSTING - answers to frequently asked questions 2004.03.24"
    Date: Wed, 24 Mar 2004 01:43:12 -0800
    
    

    Hi,

    I've followed the Microsoft Knowledge Base Article 301429,
    where it explains how to install a client certificate so
    when using a ServerXMLHTTP request object and the server
    asks for a valid certificate everythings goes as it should.

    But I've found some problems.

    - To install a client certificate to the IWAM user, I need
    adminitrator privileges, that's fine, I give them to the
    user and he can install the certificate and it's private
    key. Then I do a Synciwam.vbs from the IWAM user and
    everything works fine.

    - As the article says, I disable IWAM administrator
    privileges.

    - Then, I reboot the machine, and the client
    authentication fails, it keeps on saying "A client
    certificate is needed...". So, I do a Synciwam.vbs from my
    administrator (because IWAM is not and administrator
    anymore), but this does not work. What really happens is
    that my IWAM client certificate is removed! Note: It is
    not removed if I keep the administrator privileges on the
    IWAM user.

    The question is? How can I avoid the problem of the
    authomatic client certificate removal? Am I doing
    something wrong? Which are the correct steps to follow?

    Any little help would be kindly appreciated.

    Btw, I'm running a Windows 2000 Professional.

    Best regards,

    aleix


  • Next message: Karl Levinson [x y] mvp: "** READ THIS BEFORE POSTING - answers to frequently asked questions 2004.03.24"

    Relevant Pages

    • Client authentication from ASP problem
      ... >I've followed the Microsoft Knowledge Base Article ... >- To install a client certificate to the IWAM user, ... >administrator (because IWAM is not and administrator ...
      (microsoft.public.inetserver.asp.components)
    • Client authentication from ASP problem
      ... - To install a client certificate to the IWAM user, ... administrator (because IWAM is not and administrator ...
      (microsoft.public.inetserver.asp.components)
    • Using SSL Client Certificate in asp.net
      ... I was trying to access a web service which requires the ... I had a client certificate installed. ... Then I tried to install ... be able to access the local machine store. ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Problem with CA certificate ("Invalid Policy") on XP Only
      ... I have a client certificate, issued by a CA who is a sub-CA of the root ... When I install the root CA and sub-CA certs (in Trusted and ... But, when I then install the client certificate, the sub-CA cert ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Mutual Authentication
      ... I am not using active directory ... and I am not an administrator so I have no idea what I am looking for. ... mutual authentication must be turned on to allow the client certificate to ... Matt ...
      (microsoft.public.inetserver.iis.security)