Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


March 19, 2002

Secure IIS with Certificates


RSS
View this exclusive article with VIP access -- click here to join |
See More Security Articles Here | Reprints | Or sign up for our VIP Monthly Pass!

IIS supports two types of client-certificate mapping. The legacy mode introduced in Internet Information Server (IIS) 4.0 lets you map certificates to specific user accounts manually. The advantage of this mode is that you can use certificates from multiple CAs and map those certificates to any account you choose. You can also map multiple certificates to a single account. You create the mappings by using the Account Mappings dialog box, which appears when you click Edit in the Secure Communications dialog box's Enable client certificate mapping section. Unfortunately, this mode of operation becomes unwieldy when you work with many certificates and user accounts.

The second type of client-certificate mapping lets you instruct IIS to map the client certificates that an enterprise CA issues to user accounts in AD. To use this mode of operation, open the Internet Information Services snap-in, right-click the Web server (not a Web site), and select Properties. From the Master Properties menu, select WWW Service, click Edit, and select the Directory Security tab. Select Enable the Windows directory service mapper, as Figure 5 shows. The advantages of this mode include scalability and some automated management features: As the enterprise CA issues user certificates, they're stored automatically in AD. You don't need to manually load and manage the certificates, and when users renew their certificates, you don't need to update the mappings. Note that the two types of client-certificate mapping are mutually exclusive in IIS, so you must choose your scheme with care. . . .

Reader Comments
Need to go one step further, 'Renewing client certificates.'

jeaster July 13, 2004 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

New Microsoft/Yahoo! Deal? No

On Sunday, the Times of London reported that Microsoft had renewed talks with failing Internet giant Yahoo! and would manage its search engine for 10 years, while Yahoo! would retain control of its email, messaging, and content services. This report ...

How can I stop and start services from the command line?

...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events How IE7 & The New Extended Validation SSL Certificates Impact Your Site

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing