Client certificate problem

From: Felix Planjer (felix.planjer_at_yellowred.nl)
Date: 12/14/04


Date: Tue, 14 Dec 2004 11:04:23 +0100

Hi,

We're developing an application that will run on IIS 5, with server and
client certificates. I have some issues setting this up.

We have our own Certificate Authority installen (seperate box) and
generated a server certifictae for our webserver. HTTPS works fine.

Then, we generated a client certificate (on the same CA) and installed
this on the client. Whe we set the webserver to 'require client
certificate' we allways get the error 'The page requires a client
certificate'. Also, when I set IE to display a box with client certs,
the box is empty.

When I go to a different server, which has a server certificate
generated from the same CA, the installed client certificate works fine.

Can anyone shed some light on the problem we are facing here?

Also, I'd like to know how the browser selects the client certificate
that has to be send to the server?

regards, Felix



Relevant Pages

  • Strange IIS 5 problem with client certificates
    ... We are having a strange IIS 5.0 problem involving client certificates. ... We have a system with a central server running Win2K and IIS 5.0, ... HTTPS, authenticate themselves via client certificate, and then POST data to ...
    (microsoft.public.inetserver.iis.security)
  • Windows Mobile + https + clientcertificates?
    ... I am trying to write an application which communicates with a webservice via SOAP, from a Windows Mobile 6 device. ... Additionally, the server certificate on the test server is self-signed, and so the client application needs to be able to ignore server certificate errors, and also supply the correct client certificate. ...
    (microsoft.public.windowsce.app.development)
  • Re: Windows Mobile + https + clientcertificates?
    ... On the Windows Mobile device, I've successfully obtained the certificate via the crypto APIs, and called the SetOption, with no apparent error. ... However, it still fails (the SendRequest actually says it succeeds, but I have an HTTP status of 500, internal server error, and no results). ... Additionally, the server certificate on the test server is self-signed, and so the client application needs to be able to ignore server certificate errors, and also supply the correct client certificate. ...
    (microsoft.public.windowsce.app.development)
  • Re: TLS Handshake issue
    ... on the server certficate if I do not supply the MANUAL_VALIDATION flag? ... certificate and then sent my client certificate? ... should get SEC_E_CERT_EXPIRED if the server cert is expired. ...
    (microsoft.public.platformsdk.security)
  • Re: unable to connect using https
    ... > I have IIS5 running on same server as the certificate ... > server, all latest patches. ... > to the local default webserver and am able to edit the ... > port 443 in website and advanced. ...
    (microsoft.public.inetserver.iis.security)

Quantcast