<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.iis.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:cs="http://blogs.iis.net/"><channel><title>Search results matching tag 'iisClientCertificateMappingAuthentication'</title><link>http://forums.iis.net/search/SearchResults.aspx?o=DateDescending&amp;tag=iisClientCertificateMappingAuthentication&amp;orTags=0</link><description>Search results matching tag 'iisClientCertificateMappingAuthentication'</description><dc:language>en-US</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>iisClientCertificateMappingAuthentication manyToOneMappings </title><link>http://forums.iis.net/p/1162925/1925991.aspx#1925991</link><pubDate>Tue, 24 Nov 2009 13:35:32 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1925991</guid><dc:creator>wkugler</dc:creator><cs:applicationKey>iis7_-_security--1</cs:applicationKey><description>&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;We want to use iisClientCertificateMappingAuthentication to allow access for Clients with certain certificates only. We want to use manyToOneMappings to keep the number of entries small and minimize administrative burden. &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;We experienced that the rules do not work reliable. E.g. on some certificates a match with certificateField Issuer, certificateSubField CN does not work, where certificateField Issuer, certificateSubField C does work. &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Are there any known problems with manyToOneMappings?&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Furthermore we did not find any information concerning &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;following questions:&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;If two or more rules are added, are they combined with OR or with AND?&lt;/font&gt;&lt;/font&gt;&lt;/span&gt; 
&lt;p style="MARGIN:0cm 0cm 0pt;" class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Does the field matchCriteria handle Wildcards? If so, how are wildcards handled?&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;
&lt;p&gt;Thanks for your answers.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;</description></item><item><title>config reference comment</title><link>http://forums.iis.net/p/1157662/1903768.aspx#1903768</link><pubDate>Thu, 14 May 2009 16:36:05 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1903768</guid><dc:creator>barkills</dc:creator><cs:applicationKey>feedback--1</cs:applicationKey><description>&lt;p&gt;(I renamed this post since the long URL was breaking the site design - Pete.)&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Config reference link:&lt;br /&gt;&lt;a href="http://www.iis.net/ConfigReference/system.webServer/security/authentication/iisClientCertificateMappingAuthentication"&gt;http://www.iis.net/ConfigReference/system.webServer/security/authentication/iisClientCertificateMappingAuthentication&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;That reference material really should include a reference to the SSL configuration module, explicitly reminding admins that they need to change the default setting of *Ignore* client certificates to *Accept* or *Require* if they want any of the certificate mapping functionality to actually be usable.&lt;/p&gt;
&lt;p&gt;I would have added this as a comment, but the reference material doesn&amp;#39;t support comments ... &lt;/p&gt;</description></item></channel></rss>