【发布时间】:2014-07-20 20:17:28
【问题描述】:
我正在尝试设置 IIS 8 (Windows Server 2012) 以接受安全 WebAPI 端点的客户端证书。在this post之后,我创建了一个自签名证书和一个客户端证书:
makecert.exe -r -n "CN=MyCompany" -pe -sv MyCompany.pvk -a sha1 -len 2048 -cy authority MyCompany.cer
makecert.exe -iv MyCompany.pvk -ic MyCompany.cer -n "CN=MY Client" -pe -sv MyClient.pvk -a sha1 -len 2048 -sky exchange MyClient.cer -eku 1.3.6.1.5.5.7.3.2
pvk2pfx.exe -pvk MyClient.pvk -spc MyClient.cer -pfx MyClient.pfx -po THE_PASSWORD
我在 IIS 服务器上安装了根证书 MyCompany.cer,然后在 IIS 管理器/SSL 设置中我选择了“接受”单选按钮以允许网站接受客户端证书。
在客户端有一个 C# 测试控制台应用程序,它加载客户端证书 MyClient.pfx 文件并调用 WebAPI 端点:
var certHandler = new WebRequestHandler();
certHandler.ClientCertificateOptions = ClientCertificateOption.Manual;
certHandler.UseProxy = false;
var certificate = new X509Certificate2(File.ReadAllBytes(@"C:\MyClient.pfx"), "THE_PASSWORD");
certHandler.ClientCertificates.Add(certificate);
var client = new HttpClient(certHandler);
var result = client.GetAsync("https://MyServer/api/MyEndpoint").Result;
string resultStr = result.Content.ReadAsStringAsync().Result;
Console.WriteLine(resultStr);
我收到一个 403 错误:
403 - Forbidden: Access is denied.
You do not have permission to view this directory or page using the credentials that you supplied.
我在本地 IIS (Windows 7) 上尝试了相同的设置:导入 MyCompany.cer 文件,在 IIS 中设置 SSL。这次一切正常,WebAPI 端点可以毫无问题地看到客户端证书。
有什么想法吗?
-- 更新 1
我在 IIS 上启用了失败的请求跟踪,我得到了这个:
<failedRequest url="https://myserver:443/"
siteId="35"
appPoolId="CertTest"
processId="7248"
verb="GET"
authenticationType="NOT_AVAILABLE" activityId="{00000000-0000-0000-B0AA-0280000000E0}"
failureReason="STATUS_CODE"
statusCode="403.16"
triggerStatusCode="403.16"
timeTaken="0"
xmlns:freb="http://schemas.microsoft.com/win/2006/06/iis/freb"
>
如果我理解正确,错误是 403.16。我了解当服务器上的证书未导入本地计算机下的受信任的根证书颁发机构时会发生这种情况。我仔细检查过,这不是我的情况。
【问题讨论】:
标签: iis ssl-certificate x509certificate