Welcome to HostingForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Client certificate mapping question

 
   Web Hosting Problem Solving Community! (Home) -> IIS RSS
Next:  IIS 6.0 on Windows 2003  
Author Message
Bob

External


Since: Jan 17, 2006
Posts: 1



(Msg. 1) Posted: Tue Jan 17, 2006 8:09 pm
Post subject: Client certificate mapping question
Archived from groups: microsoft>public>inetserver>iis, others (more info?)

I have a web server running Windows 2003 with SP1. I need to use a client
certificate to control the access to a path. Under Properties -> Directory
Security -> Security Communications (Edit) of the folder, I checked Require
secure channel and Require client certificates. Then I added a mapping
between a client certificate and a newly created local windows account that
doesn't belong to any User Group. I then tested it from a remote IE
browser. IE correctly detected that the page requires client certificate
and prompted me to select one. I selected the one that's mapped on the
server, it showed me the page. It all seems to work but my question is the
user account on the server the client cert is mapped to does not belong to
any group, so it has no ACL access to the file system folder (that the web
path points at), how come I was able to view the page? I was expecting an
Access Denied error. I disabled Anonymous Access, Integrated Windows
Authentication, Basic Authentication etc, that is, everyting on the
Directory Security -> Authentication and Access Control tab, but the result
is the same. This is really odd as it seems that if you have a valid
client certificate, you can get in regardless of what account it's mapped to
on the server.

Any help with explaining this behavior, or what I did wrong would be much
appreciated.

Bob

 >> Stay informed about: Client certificate mapping question 
Back to top
Login to vote
Ed

External


Since: Jan 19, 2006
Posts: 2



(Msg. 2) Posted: Thu Jan 19, 2006 2:43 pm
Post subject: Re: Client certificate mapping question [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi Bob,

I may have misunderstood your post, but,

> " Then I added a mapping between a client certificate and a newly created
> local windows account that
doesn't belong to any User Group"

All local users belong to the USERS group, each time you create one, it's
automatically part of this group...

--
Cheers,
Ed


"Bob" <bobatkpmg.RemoveThis@yahoo.com> wrote in message
news:%23z5ztR9GGHA.2036@TK2MSFTNGP14.phx.gbl...
>I have a web server running Windows 2003 with SP1. I need to use a client
> certificate to control the access to a path. Under Properties ->
> Directory
> Security -> Security Communications (Edit) of the folder, I checked
> Require
> secure channel and Require client certificates. Then I added a mapping
> between a client certificate and a newly created local windows account
> that
> doesn't belong to any User Group. I then tested it from a remote IE
> browser. IE correctly detected that the page requires client certificate
> and prompted me to select one. I selected the one that's mapped on the
> server, it showed me the page. It all seems to work but my question is
> the
> user account on the server the client cert is mapped to does not belong to
> any group, so it has no ACL access to the file system folder (that the web
> path points at), how come I was able to view the page? I was expecting an
> Access Denied error. I disabled Anonymous Access, Integrated Windows
> Authentication, Basic Authentication etc, that is, everyting on the
> Directory Security -> Authentication and Access Control tab, but the
> result
> is the same. This is really odd as it seems that if you have a valid
> client certificate, you can get in regardless of what account it's mapped
> to
> on the server.
>
> Any help with explaining this behavior, or what I did wrong would be much
> appreciated.
>
> Bob
>
>

 >> Stay informed about: Client certificate mapping question 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
IIS - client certificate mapping - Hi , I wanna use ssl accelerator with IIS . I want that my ssl accelerator will do all the ssl work and not the iis , but I need the iis for client authentication against the server accounts (by using the "enable client certificate mapping&qu...

Client Certificate User Mapping - Does the web server machine has to be part of the domain when mapping client certificates to users? Thanks in advance

Trouble with client certificate mapping on IIS 5 - When attempting to map a client certificate to an local machine account using IIS certificate mapping I get an "The certificate file is not valid." error even though the certificate is in fact valid. Using the same certificate I was able to...

Accept Client Certificate Behavior - Question - I don't have any site to compare to other than my own. Background: Windows Server 2003 IIS 6.0 Java Client XP Web Site SSL I have my site set up to "accept client certificates". When I log into it I get an empty certificate box (just lik...

How to tell which SSL Certificate is installed - Hello. I have a website thats using SSL. What's the best way to check information on the cerificate that's installed? Right now all I see in IIS that is that port 443 is set. Thanks.
   Web Hosting Problem Solving Community! (Home) -> IIS All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]