IIS 5 and client certificates - odd behaviour

From: Clive (no.email_at_dummy.domain)
Date: 05/15/04


Date: Sat, 15 May 2004 15:56:18 +0100

I hope someone can help me out before Monday - I have a problem at work that
is driving me nuts!

We have an IIS server on our test system that has pages setup to accept
client certificates. We have the root certificate of the CA issuing the
client certs in our IIS root certificate store. The client machine we are
using for testing has a client certificate is issued by an intermediate CA
two levels sub-ordinate to the root CA.

When we access the protected page on our test system the IE certificate
popup appears, but it is blank. We can go to our live web site and visit the
protected pages the IE popup correctly lists the client certificate.

I initially thought that it might be to do with the intermediate
certificates not being loaded onto the test machine, but as far as I can see
our live system does not have any of the intermediate certificates
installed, only the root.

I am familiar with how the IE popup works i.e. IIS sends a list of trusted
root certs and IE displays a list of all client certs matching the list.

Can anyone offer an explanation as to why the behaviour is different even
though the configuration of the live and test IIS servers appears to be the
same from a certificate point of view.

Thanks,

- Clive



Relevant Pages

  • Re: SSL client certificate authentication
    ... The list is populated by IE based on the list of root CA certs that the IIS ... > 2> When I install the microsoft certificate services, ... > client certificate is installed in the client machine and gets stored ... > * In the Anonymous access and authentication control section, ...
    (microsoft.public.win2000.security)
  • RE: HTTP 403.16 - Forbidden: Client certificate untrusted or invalid
    ... certificate from the CA onto the IIS server. ... I understand that you've looked into the "Trust Only Enterprise Root ... Stores" option but did you install the root cert from the CA onto your IIS ... Q252657 IIS 5.0: HTTP 403.16 Forbidden: Client certificate Untrusted ...
    (microsoft.public.inetserver.iis.security)
  • Re: creating multiple client certificates
    ... configured as ssl on the iis server. ... vulnerable to any security problems by opening the firewall port through to ... your usage of Client Certificate does not improve security. ...
    (microsoft.public.inetserver.iis.security)
  • IIS certificate chain doesnt contain root CA cert in Server Hello
    ... I have a question about IIS certificate chain. ... How to make IIS server to ... the chain except root CA cert. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Schannel CertificateChainValidation failing
    ... I am not fully up to speed with certs (root, end entity, ... valid Windows trusted root cert. ... You've enabled certificate revocation checking, and the validation code ...
    (microsoft.public.platformsdk.security)