Groups | Blog | Home
all groups > iis security > july 2005 >

iis security : HTTPS design question


NO[at]SPAM
7/27/2005 3:10:06 AM
Hi there,
We have a tomcat servlet container which runs in the context of HTTPS. We
have created a self signed certificate using keytool and this is stored in
the tomcat environment (this certificate has the expiration date as well). We
are having a client which basically is an applet which connects to the server
and gets authenticated. The client certificates are stored in the client
machine. In one scanerio the client and server have an expired certificates.
In that case we need to renew these certificates somehow. Is there any way to
automate the renewal of certificates using someother mechanism than putting
in tomcat. My question is: Is it possible to do these things in IIS
environment? I dont want to get a CA to issue a certificate. I want to have
self signed certificate and authenticate the user to access the servlet
container. Please help me in this regards
Thanks
Miha Pihler [MVP]
7/27/2005 7:23:51 PM
Hi,

Does client use certificate for authentication?

There is a tool called SelfSSL that you can download from Microsoft that
will issue certificate for SSL but not for user authentication.

--
Mike
Microsoft MVP - Windows Security

[quoted text, click to view]

AddThis Social Bookmark Button