CardSpace - another question

  • Thread starter Thread starter Marcin Daczkowski
  • Start date Start date
M

Marcin Daczkowski

Hello!
I have another question regarding CardSpace. I have two web sites one where
you log in with self-issued-card (this is sts site used for test managed
card issuing) and one where you use managed card received from Identity
Provider.

In my test environment all (IP and RP) sites are placed on same virtual
machine but hosted on different ports. Certuficates (regular, not with
images) are stored in local system store and proper rights are assigned to
network service under which rights web sites are hosted.

When I access STS site and try to login with self issued card everything is
ok, but when I want to do same for RP site CardSpace says that it can't
trust this site and refuses to show cards wallet. When I put certificate in
Trusted People in user store it starts to work.

I would like to know how to avoid that. Regular user need to be skilled to
do that manually - and of course it is not user friendly.

Thanks in advance,
Marcin
 
Self answered again. Client need to trust rp to the whole thing work. It can
be achieved either by having cert in trusted people (chain validation in
that case is "omitted" - peer case), or issued by trusted publisher (chain
validatiom of publisher needs publishers certi in trusted store).

Marcin
 
Back
Top