Mapping certificates and Windows Account

  • Thread starter Thread starter Oriane
  • Start date Start date
O

Oriane

Hi,

I want to use a one-to-one mapping between a certificate and a specific
Windows account on IIS 5.0 on a Windows 2000 Server. I've exported a valid
email cert in a DER X509 *.cer file, and I try to map this cert with my
account with the "account mapping dialog box". However IIS 5.0 tells me that
"the certificate file is not valid". So what's wrong with that ? I guess
that my email cert does not authenticate me as a person but just as an email
address;;;

Besides, if I use a PKI on a Windows 2003 Server, and that many people from
my organization use their own private computer at home (without VPN) do you
think this solution is the best one to control their access to ressources ?

Oriane
 
If you use AD based mapping, the cert must be stored on either the altsecid
attribute of the user account or it must contain a valid subjaltname for a
user that chains to a trusted root CA, etc

some helpful links:


· Guidelines for Enabling Smart Card Logon with Third-Party
Certification Authorities (Q281245):
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q281245
· How to Import a Third-Party Certificate into the NTAuth Store
(Q295663): http://support.microsoft.com/default.aspx?scid=kb;EN-US;Q295663
· Step by Step Guide to Certificate Mapping:
http://www.microsoft.com/windows2000/techinfo/planning/security/mappingcerts.asp
 
Back
Top