Only show "identify" certificates.

From: ib (ib_at_discussions.microsoft.com)
Date: 08/10/04


Date: Mon, 9 Aug 2004 17:33:03 -0700

Need help with possibly IIS configuration.

As you know there are usually multiple client certificates on a DoD CAC
card. One is an identity certificate (e.g., Issued by: DOD CLASS 3 CA-5),
the others are E-mail certificates (e.g., Issued by: DOD CLASS EMAIL CA-6).

I configured an IIS server which requires client certificates and also
checks for revoked certificates. It’s working fine where a user can only
connect with a valid and non-revoked client certificate. However, I want to
refine this configuration.

Currently when a user hits the IIS server, she is presented with a list of
her client certificates which include all identify and e-mail certificates.
To limit confusion to the user, I want the user to only see identity
certificates and not the e-mail certificates.

Any suggestions on how to accomplish this is greatly appreciated.

-- 
ismael


Relevant Pages

  • Re: Digital Certificates Concepts needed (newbie to Crypto)
    ... > authentication via smartcards that will hold client certificates. ... Do we have to have a online connection / request to the CA? ...
    (microsoft.public.platformsdk.security)
  • Re: IEEE 802.1x & EAP-TLS design based on Windows 2000 Server
    ... Enterprise CA because of political factors (internal customer ... politics, the AD is managed by different departments, and so on), so ... > auto-installation of the users' certificates. ... You want to use client certificates, ...
    (Focus-Microsoft)
  • Digital Certificates Concepts needed (newbie to Crypto)
    ... authentication via smartcards that will hold client certificates. ... After correct authentication subsequent requests are authorized via ... Do we have to have a online connection / request to the CA? ...
    (microsoft.public.platformsdk.security)
  • RE: IEEE 802.1x & EAP-TLS design based on Windows 2000 Server
    ... The only real gotcha is the fact that the standalone CAs don't really do ... autoenrollment, etc), but that was almost 5 years ago, so forgive me if the ... auto-installation of the users' certificates. ... > If you need to use client certificates - create new Enterprise Subordinate ...
    (Focus-Microsoft)
  • Only show Identity certificates
    ... Need help with possibly IIS configuration. ... As you know there are usually multiple client certificates on a DoD CAC ...
    (microsoft.public.inetserver.iis.security)