Choose your certificate for every rule (Full Version)

All Forums >> [ISA 2006 Publishing] >> Web Publishing



Message


tijlhaghebaert -> Choose your certificate for every rule (2.Jun.2008 6:24:24 AM)

Hello,

On my ISA I have 5 rules. All this rules are using the same listener.
For authentication I chose Form authentication + Require SSL client certificate.
Also I configured SSO for all the rules. When I put off require SSL client certificate everything works great, but when it's on every time I go to a page from another rule. It keeps me asking which certificate I am want to use.

OK, this isn't such a big problem. I don't have to give my PIN-code and my credential but in my opinion this isn't so properly.

Grtz Tyler 




tshinder -> RE: Choose your certificate for every rule (12.Jun.2008 10:25:57 AM)

Can you combine those five rules into one rule?

Thanks!
Tom




tijlhaghebaert -> RE: Choose your certificate for every rule (13.Jun.2008 5:57:45 AM)

I don't think so.
Every rules is made for another application on another server.

Rule1: Application1 on server1 (IIS): https://app1.domain.com
Rule2: Application2 on server2 (IIS): https://app2.domain.com
Rule3: Application3 on server3 (TomCat (Apache)): https://app3.domain.com
...

The first time I go to one of these websites these are the steps:
  1. Choose my certificate
  2. Enter my PIN-code
  3. Enter username en password in ISA HTML Form
  4. Now I'm logged on.

Then when I go to another application, it only asks me choose my certificate again.
So the Single Sign On works good, but I still have to choose the right certificate again. They don't ask for a Pin-code anymore.

When I go again to that second application, everything works fine. No ask to choose certificate.

Grtz Tijl




tshinder -> RE: Choose your certificate for every rule (16.Jun.2008 10:45:19 AM)

Are all three rules using the same Web Listener?

Thanks!
Tom




frobnitzz -> RE: Choose your certificate for every rule (17.Jun.2008 2:48:03 PM)

quote:

ORIGINAL: tshinder

Are all three rules using the same Web Listener?

Thanks!
Tom


To quote the 1st post "All this rules are using the same listener."

hth
John




tshinder -> RE: Choose your certificate for every rule (18.Jun.2008 12:07:38 PM)

Hi John,

OK, got it. From what I can tell, certificate based authentication without the use of KCD won't support SSO.

HTH,
Tom




Page: [1]