Click here to get back home

IIS 6 behavior on checking clients' certificates (again 2)

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
IIS 6 behavior on checking clients' certificates (again 2) Vsevolod 09-29-2005
Posted by Vsevolod on September 29, 2005, 12:40 am
Please log in for more thread options
Hello !
It's me again with the same pquestion or the problem. I was forced to ask
you about subj because my last post is unanswered yet.
After numerious tests I determined IIS 6 can't build certificate chain
without presence of intermediate certificates in Intermediate Certificate
storage of Local Computer where IIS 6 runs. It doesn't take these
certificates from url pointed in AIA extension of client certificate. Though
it takes Base and Delta CRL from URLs pointed in CDP extension. BTW IIS 6 can
omit check certificate revocation status if we set CertCheckMode parameter
not equal 0.
In this case if resources that are pointed in CDP extension are unavailable
we get the error: HTTP 403.13.
In the article "Troubleshooting Certificate Status and Revocation" I have
read
"To improve performance, the CryptoAPI will store subordinate CA
certificates in the Intermediate Certification Authorities store so that
future requests for the certificate can be satisfied from the store, rather
than accessing the certificate through a URL".
I have determinated : IIS 6 doesn't work as written in the article but
certutil does.

How can you explain this ? Where is I mistaking ?
Sorry again.

Best regards,
Vsevolod.



Similar ThreadsPosted
Different IIS 5 & IIS 6 behavior on checking clients' certificates September 5, 2005, 11:55 pm
IIS 6 behavior on checking clients' certificates (again) September 16, 2005, 4:47 am
bypass traverse checking August 9, 2005, 3:35 pm
Checking group security October 5, 2007, 10:31 am
What security policies effect tasklist.exe password prompt behavior? February 29, 2008, 9:29 am
clients separated from DC by firewall June 7, 2007, 5:22 pm
Radius with dynamic dns clients September 25, 2008, 4:14 pm
Auto-renewing certs w/ VPN clients February 15, 2006, 9:44 am
Win2003 Server automated password changes. What about Mac clients March 7, 2008, 12:32 pm
vista domain clients no longer see USB drives June 9, 2008, 7:05 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap