Advertisement

03.20.2008 at 07:46AM PDT, ID: 23257066
[x]
Attachment Details

SSL server certificate cannot authenticate the client certificate in IIS 6.0

Asked by re-aktiv in Secure Socket Layer (SSL) & HTTPS, Microsoft IIS Web Server, MS Internet Security & Accel

Tags: , , , ,

Hi
I have placed my web application on a web server that runs IIS 6.0 on windows server 2003 Standard Edition. I have assigned an SSL certificate to the site and set it to require secure channel (SSL) and to require client certificates for authentication. The SSL server certificate is correctly installed with every other certificate in the the certificate path correctly placen in its apropriate certificate store trusted root and intermediate. The client certificate is installed and working properly as well. When i remove the option require client certificate and put the ignore or accept client certificate i can acces the web page through HTTPS, but whe the option require client certificate is selected i recieve the message "The page requires a valid SSL client certificate" with the error "HTTP Error 403.13 - Forbidden: Client certificate has been revoked on the Web server.". The client certificate is valid and has not been revoked and the server certificate is valid as well.
In my next step i downloaded the client certificate "Certificate Revocation List (CRL)" and placed it in the personal certificate store on the local computer where the server certificate is placed and at that point i was allowed access to the web page with the option require client certificate selected on the IIS. The problem is that the list i downloaded is static and the list on the CA server is updated every 3 hours so this won't do me much good.
The web server is behind ISA Server 2004 with rule set to Enable All Outbound Traffic for the server where the web application is hosted. When i copry the URL in IExplorer i am allowed to download the CRL.
Can you please help me in finding a solution to this problem
ThanksStart Free Trial
[+][-]03.21.2008 at 12:48PM PDT, ID: 21182597

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.21.2008 at 12:51PM PDT, ID: 21182624

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Secure Socket Layer (SSL) & HTTPS, Microsoft IIS Web Server, MS Internet Security & Accel
Tags: Microsoft, IIS, 6.0, SSL Certificate authentication, SSL Certificate Authentication
Sign Up Now!
Solution Provided By: keith_alabaster
Participating Experts: 1
Solution Grade: A
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628