Re: creating multiple client certificates



On Jul 14, 6:21 am, Alastair <Alast...@xxxxxxxxxxxxxxxxxxxxxxxxx>
wrote:
Hi David, Thank you for taking the time to reply.

Simplistically I thought you produce a certificate on the iis server, this
can then (or from CA) produce a client cert that can then be exported and
copied/installed on the clients. When the client (with cert installed) tries
to connect via https the server checks if the client has the cert, if so it
connects, if not the connection is refused. Thus stopping the users from
getting onto the application from just 'any' pc - just the ones with a client
certificate pre-installed by us.

Am I able to generate and copy just one client certificate for this purpose?

Thanks again,
Alastair.


A certificate can be created anywhere by anyone. The question is
whether the users of the certificate trust the authenticity of the
certificate.

The issue is that there is no server-side feature which "checks if the
client has the cert" to authorize/deny the user's connection attempt,
so your usage scenario will require custom code.


//David
http://w3-4u.blogspot.com
http://blogs.msdn.com/David.Wang
//
.



Relevant Pages

  • BUG?: Cant disable "Trusted" for Certificates Issued by MS Certificate Server
    ... Server: Win2K Advanced Server SP4, ... Client: Win2K Pro SP4, ... cert for IIS with MS Certificate Server, ... Certificate Server whenever I tried to connect from IE to IIS. ...
    (microsoft.public.platformsdk.security)
  • BUG?: Cant disable "Trusted" for Certificates Issued by MS Certificate Server
    ... Server: Win2K Advanced Server SP4, ... Client: Win2K Pro SP4, ... cert for IIS with MS Certificate Server, ... Certificate Server whenever I tried to connect from IE to IIS. ...
    (microsoft.public.inetserver.iis.security)
  • BUG?: Cant disable "Trusted" for Certificates Issued by MS Certificate Server
    ... Server: Win2K Advanced Server SP4, ... Client: Win2K Pro SP4, ... cert for IIS with MS Certificate Server, ... Certificate Server whenever I tried to connect from IE to IIS. ...
    (microsoft.public.win2000.security)
  • Re: Cant disable "Trusted" for Certificates Issued by MS Certificate Server
    ... What usages does the root certificate of your MS Certificate Server have ... > I have been preparing to configure the above server for SSL with server> and client authentication for awhile. ... > Then, using the IIS server certificate wizard, I deleted the original MS> Certificate Server-issued server cert, then created a new server> certificate request, which I then sent to my commerical CA one night. ...
    (microsoft.public.platformsdk.security)
  • Re: Cant disable "Trusted" for Certificates Issued by MS Certificate Server
    ... What usages does the root certificate of your MS Certificate Server have ... > I have been preparing to configure the above server for SSL with server> and client authentication for awhile. ... > Then, using the IIS server certificate wizard, I deleted the original MS> Certificate Server-issued server cert, then created a new server> certificate request, which I then sent to my commerical CA one night. ...
    (microsoft.public.inetserver.iis.security)