Groups | Blog | Home
all groups > dotnet security > february 2007 >

dotnet security : Client certificates do not show up installing the last Root Update


claudio
2/9/2007 3:24:00 AM
After having installed the Jan 31st 2007 Root Update on Windows 2003 Server
I've lost the possibility to use almost all my client certificates when
accessing https pages of web sites on my machine.

Only certs from a given CA are displayed. Not those from my local CA for
instance. The CA certs are in the root store as before.

If I try to connect to servers where the update is not installed I can see
all my certificates.

Any idea?

thanks

Claudio
claudio
2/9/2007 3:46:01 AM
Yes they have.
the strange thing is that they were present in the popup window before and
not now....

[quoted text, click to view]
Dominick Baier
2/9/2007 11:34:46 AM
just a though..

Make sure the "client authentication" purpose is enabled for the CA certs
that issued the client certs...


-----
Dominick Baier (http://www.leastprivilege.com)

Developing More Secure Microsoft ASP.NET 2.0 Applications (http://www.microsoft.com/mspress/books/9989.asp)

[quoted text, click to view]

Dominick Baier
2/9/2007 12:06:35 PM
hhmm..


try this tool
http://www.microsoft.com/downloads/details.aspx?FamilyID=cabea1d0-5a10-41bc-83d4-06c814265282&displaylang=en

this lets you monitor the client certificate handshake in realtime...


-----
Dominick Baier (http://www.leastprivilege.com)

Developing More Secure Microsoft ASP.NET 2.0 Applications (http://www.microsoft.com/mspress/books/9989.asp)

[quoted text, click to view]

CynicalIrony NO[at]SPAM gmail.com
2/12/2007 2:02:44 PM
Check your event log. See if you are getting a truncation on Trusted
Root Certs. If so, remove some of the issuers that you do not need
from your trusted list. We ran in to this problem as well, took us a
couple days to figure it out.

Randy
AddThis Social Bookmark Button