Solved

Problem with X509 certificate - WSE 2.0

Posted on 2006-11-15
2
696 Views
Last Modified: 2013-11-30
I’m trying to secure the message level communications of my system using WSE 2.0, signing with X.509 certificates.

We have a web server (WEB) hosting a web app and another server (WS) hosting a web service. Both machines have acquired a certificate from the domain controller. Each of these certificates has been exported to the other machine, without a private key. All of the certs are in the local machine store.

I’ve configure WSE to use a policy file at each end. The problem I’m having is with the sending of the original web service request – it isn’t getting any further yet. The tracing on the web server is telling me that it cannot find a security token to sign the message with.

I’ve tried the following:
* Checked and double checked the token issuer, subject name and X509Extension (OID) keys in the policyCache file (I’ve also commented out the extension key to simplify the check)
* Double checked the URL of the endpoint (I’m using the default operation element)
* Used the X509Cert tool to check permissions on the private key of the certificate
* Used winhttpcertcfg.exe to grant access to the certificate to ASPNET and IUSR accounts (this only worked for the cert with a private key)
* Tried altering the policy to specify either of the two available certs.

The only trace message I’m getting is “could not find a security token”. I’m aware that the ASPNET process doesn’t by default look in the localmachine store but I’ve been through the workaround / fix for this (see below) and now I’m a bit stuck. It seems to me that the APSNET (or IUSR) cannot see the certificates, but I’ve no idea why. I’ve had all of this working on my dev machine (with a windows app and with a web app), but only on the one machine and only with test certs, so my local setup doesn’t really compare with our test env.

http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnnetsec/html/secnetht13.asp

Any ideas much appreciated..!!!

Thanks
Alec
0
Comment
Question by:alecpotts
2 Comments
 
LVL 3

Author Comment

by:alecpotts
ID: 17964967
Cracked it.

The problem was mainly that the <tokenIssuer> key within the policy doesn't seem to work. No matter what I put in there - with spaces, without spaces, with commas, backwards (as specified by Microsoft).....everything I tried to make it match up to the Issued By field of the certificate....no joy. As soon as I removed the key completely....everything works fine.

The other thing was that you need to use the WseCertificate2.exe tool to set the access permission on the private key of each client cert - on Server 2000 you need to grant access to ASPNET, but on Server 2003 it's NETWORK SERVICE that needs access...

I've asked for a refund/PAQ....

ALec
0
 

Accepted Solution

by:
CetusMOD earned 0 total points
ID: 17969420
Closed, 500 points refunded.
CetusMOD
Community Support Moderator
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
how to access my server 9 28
Flashing Cisco Meraki MR18 with OpenWRT firmware ? 5 58
Homegroup issues 6 39
server plus 2 47
Read about why website design really matters in today's demanding market.
Although it can be difficult to imagine, someday your child will have a career of his or her own. He or she will likely start a family, buy a home and start having their own children. So, while being a kid is still extremely important, it’s also …
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now