Groups | Blog | Home
all groups > dotnet web services enhancements > december 2005 >

dotnet web services enhancements : What client X509 certificate product should be purchased


Nikolai
12/15/2005 1:57:41 PM
Hi there, i am using WSE2.0 to secure some web services, we have a webserver
SSL certificate that is being used for server signing and encryption, but
what certificate product should we purchase to distribute to clients
connecting to these services?

I can't see anything on Verisgn or any other sites that points to an obvious
solution.

And no I do not want to install the MS certificate server, we only need a
few certificates issued.

GCR
12/16/2005 12:49:02 AM
If you only need a few, than you should consider buying them from a provider
or generate some self-signed (using openSSL for example, if you don't want to
install the MS cert server).

[quoted text, click to view]
Nikolai
12/16/2005 1:13:02 AM
Out of the provider products which is suitable? Digital IDs like these?

http://verisign.com/products-services/security-services/pki/pki-application/email-digital-id/index.html

Sorry if this sounds like a newbie question but I have only used the
makecert tool for development systems so far.

[quoted text, click to view]
GCR
12/16/2005 1:59:02 AM
Something like this:
http://www.entrust.com/ssl-certificates/web_pricing.htm

[quoted text, click to view]
GCR
12/16/2005 2:13:02 AM
You need a certificate having the "Enhanced Key Usage" property set to
OID=(1.3.6.1.5.5.7.3.2).

[quoted text, click to view]
Nikolai
12/18/2005 8:08:02 PM
Great thanks for that. Looking at the price per cert I might have to look at
installing cert server or using OpenSSL.

[quoted text, click to view]
AddThis Social Bookmark Button