Client Certificate

From: BC (btcchan_at_hotmail.com)
Date: 06/01/04


Date: Mon, 31 May 2004 22:52:54 -0400

Hi everybody,

I am building a HTTPS web application for our own staff to access the
company's web server through the Internet. The web server is running IIS
5.0 on a W2K box. The web server is installed with a server certificate,
and the user's browser needs a client certificate to be authenticated by the
server. The HTTPS web server is configured with Many-to-one mapping
specifying that a certificate meets certain criteria (for instance, a
specific Certificate Authority - CA - issued by our own Microsoft
certificate server). My question is whether an authorized person can use a
pseudo Proxy server or other tools to fake a web page message containing the
HTTP header of a valid client certificate. Will the web server be able to
tell whether the challenged browser does not contain the valid client
certificate, when the challenge message is being sent back to that fake web
page.

Thanks a lot.

BC



Relevant Pages

  • Re: Evading Client-Certificate Authentication
    ... Im not one to argue semantics, but "stumbling" upon a web server during ... customer needs to generate a client certificate for you. ... stunnel can use and viola - instant client certificate proxy. ... >whilst in the middle of a Penetration Test I stumbled on a web server only ...
    (Pen-Test)
  • Re: Issues with SSL on Win CE 5.0
    ... the HKCU certificate store. ... and tell the web server to use it. ... The old cert was in. ...
    (microsoft.public.windowsce.embedded)
  • Re: Issues with SSL on Win CE 5.0
    ... the HKCU certificate store. ... and tell the web server to use it. ... The old cert was in. ...
    (microsoft.public.windowsce.embedded)
  • Re: IIS 6 behavior on checking clients certificates (again)
    ... >> against the Web server certificate as the certfile. ... >> Do the same test at the Web server against the client certificate as the ... > certificate I saw that almost everything is Ok excepting expired Delta CRL ...
    (microsoft.public.windows.server.security)
  • Re: Issues with SSL on Win CE 5.0
    ... the HKCU certificate store. ... and tell the web server to use it. ... The old cert was in. ...
    (microsoft.public.windowsce.embedded)