Technorati tag: iis,ca, certificate, SSL, client certificate, Xiamingliang
For the above points, I will design the following experiment.
"One: Is it possible to export your own certificate to others?" 】
1. Find another computer that is not joined to a domain, access https://192.168.111.12
650) this.width=650; "title=" clip_image002[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image002[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/FD/ Wkiom1uojlngoagdaacogsturm4693.jpg "" 557 "height=" 166 "/>
2. Adjusting IIS Settings
650) this.width=650; "title=" clip_image004[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image004[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/F9/wKioL1Uoj6bB_ Zs9aacagbvcyri748.jpg "" 558 "height="/>
3. Re-visit
650) this.width=650; "title=" clip_image006[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image006[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/FD/ Wkiom1uojlrgiimpaabl_ncvnvo942.jpg "" 558 "height=" 107 "/>
4. Re-adjustment
650) this.width=650; "title=" clip_image008[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image008[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/F9/ Wkiol1uoj6fwaqz5aacba3pfbgg455.jpg "" 557 "height=" 155 "/>
650) this.width=650; "title=" clip_image010[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image010[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/FD/ Wkiom1uojlvdcu6iaabhuwwhste518.jpg "" 558 "height=" 119 "/>
5. Re-adjustment
650) this.width=650; "title=" clip_image012[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image012[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/F9/ Wkiol1uoj6ihuj6naacxyoe2f-m791.jpg "" 558 "height="/>
650) this.width=650; "title=" clip_image014[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image014[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/F9/ Wkiol1uoj6myhpr1aacnkmsacxw018.jpg "" 558 "height="/>
6. The same results after importing the root certificate.
650) this.width=650; "title=" clip_image016[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image016[4] "src=" http://s3.51cto.com/wyfs02/M01/5D/F9/ Wkiol1uoj6ny4tohaagqrmolauw499.jpg "" 558 "height=" 311 "/>
650) this.width=650; "title=" clip_image017[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image017[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/FD/ Wkiom1uojl7tnyfsaacnhmz4q4m542.jpg "" 558 "height="/>
7. Export certificates for users who can work properly
650) this.width=650; "title=" clip_image019[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image019[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/F9/ Wkiol1uoj6vdeem1aafkruws0x8238.jpg "" 558 "height=" 314 "/>
650) this.width=650; "title=" clip_image020[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image020[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/F9/ Wkiol1uoj6zygvkkaafkhzjashc735.jpg "" 506 "height=" 424 "/>
650) this.width=650; "title=" clip_image021[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image021[4] "src=" http://s3.51cto.com/wyfs02/M01/5D/F9/ Wkiol1uoj63qx-jlaae1akt8jpw221.jpg "" 508 "height=" 426 "/>
650) this.width=650; "title=" clip_image022[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image022[4] "src=" Http://s3.51cto.com/wyfs02/M01/5D/FD/wKiom1UojmKy_ W6qaagk-o95pfs191.jpg "" 508 "height=" 424 "/>
650) this.width=650; "title=" clip_image023[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image023[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/F9/ Wkiol1uoj6-cgi75aadwgmafjv4492.jpg "" 506 "height=" 422 "/>
650) this.width=650; "title=" clip_image024[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image024[4] "src=" Http://s3.51cto.com/wyfs02/M00/5D/F9/wKioL1Uoj7DyKba_ Aaflayqmpko653.jpg "" 509 "height=" 423 "/>
8. Install on a computer that cannot be accessed
650) this.width=650; "title=" clip_image025[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image025[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/F9/ Wkiol1uoj7ha-upvaah7na7dxsy173.jpg "" 547 "height=" 543 "/>
650) this.width=650; "title=" clip_image026[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image026[4] "src=" http://s3.51cto.com/wyfs02/M01/5D/FD/ Wkiom1uojmxd21qvaag73xfnh_a411.jpg "" 505 "height=" 457 "/>
650) this.width=650; "title=" clip_image027[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image027[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/F9/wKioL1Uoj7PiHd6_ Aafshrnakyo435.jpg "" 507 "height=" 458 "/>
650) this.width=650; "title=" clip_image028[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image028[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/F9/ Wkiol1uoj7sc64elaaf-yqjxlmc828.jpg "" 508 "height=" 459 "/>
650) this.width=650; "title=" clip_image029[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image029[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/F9/ Wkiol1uoj7xbupfpaabezuyg2pi196.jpg "" 231 "height=" 146 "/>
After verification, the above execution, the certificate does not know where to go, every item has been seen, there is no.
Therefore, perform the following operation and reload.
650) this.width=650; "title=" clip_image030[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image030[4] "src=" http://s3.51cto.com/wyfs02/M01/5D/F9/ Wkiol1uoj7bxu2g-aagtodwharc453.jpg "" 508 "height=" 457 "/>
650) this.width=650; "title=" clip_image031[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image031[4] "src=" http://s3.51cto.com/wyfs02/M01/5D/FD/ Wkiom1uojmrdawwoaafro2_1la0414.jpg "" 492 "height=" 459 "/>
650) this.width=650; "title=" clip_image032[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image032[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/F9/ Wkiol1uoj7fqxrw6aabafugrkak219.jpg "" 233 "height=" 155 "/>
650) this.width=650; "title=" clip_image034[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image034[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/F9/ Wkiol1uoj7ijnu6waaeim8os0gy600.jpg "" 558 "height=" 312 "/>
650) this.width=650; "title=" clip_image036[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image036[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/F9/ Wkiol1uoj7nq-1kuaacndhhrlfc532.jpg "" 558 "height=" 148 "/>
10. Export the private key when exporting
650) this.width=650; "title=" clip_image038[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image038[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/F9/ Wkiol1uoj7mxlohoaafey_7cnsk831.jpg "" 558 "height=" 312 "/>
650) this.width=650; "title=" clip_image039[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image039[4] "src=" http://s3.51cto.com/wyfs02/M01/5D/F9/ Wkiol1uoj7ryirztaafj1dant3e052.jpg "" 509 "height=" 423 "/>
11. Yes, export the private key.
650) this.width=650; "title=" clip_image040[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image040[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/F9/ Wkiol1uoj7uqrd4kaafhldei6lg390.jpg "" 507 "height=" 426 "/>
650) this.width=650; "title=" clip_image041[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image041[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/FD/ Wkiom1uojndywvftaahb-jldjfw821.jpg "" 509 "height=" 425 "/>
650) this.width=650; "title=" clip_image042[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image042[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/FD/ Wkiom1uojngrxilaaadx7se84no670.jpg "" 507 "height=" 426 "/>
650) this.width=650; "title=" clip_image043[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image043[4] "src=" http://s3.51cto.com/wyfs02/M01/5D/FD/wKiom1UojnKBMrH_ Aadzj4hoany611.jpg "" 508 "height=" 424 "/>
650) this.width=650; "title=" clip_image044[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image044[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/F9/wKioL1Uoj7_ Ccedgaafefbciqbm657.jpg "" 508 "height=" 425 "/>
650) this.width=650; "title=" clip_image045[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image045[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/FD/ Wkiom1uojnpzvacraaa674wogh8428.jpg "" "height=" 127 "/>
11. Install the certificate again (on computers that have failed to access previously)
650) this.width=650; "title=" clip_image047[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image047[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/F9/ Wkiol1uoj8cgukxvaad6p6u5dpw005.jpg "" 557 "height=" 319 "/>
650) this.width=650; "title=" clip_image048[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image048[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/FD/ Wkiom1uojnxqabceaad6qqbzq9c179.jpg "" 557 "height=" 319 "/>
650) this.width=650; "title=" clip_image050[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image050[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/FD/ Wkiom1uojnxtszg9aaeraztk8_w388.jpg "" 557 "height=" 432 "/>
650) this.width=650; "title=" clip_image051[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image051[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/F9/ Wkiol1uoj8kaxwjwaagyjqnr-h4796.jpg "" 510 "height=" 459 "/>
650) this.width=650; "title=" clip_image052[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image052[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/F9/ Wkiol1uoj8pjbxotaaghp9vnahw077.jpg "" 506 "height=" 458 "/>
650) this.width=650; "title=" clip_image053[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image053[4] "src=" http://s3.51cto.com/wyfs02/M01/5D/FD/ Wkiom1uojniinpjbaagcd8f3lgo511.jpg "" "height=" 465 "/>
650) this.width=650; "title=" clip_image054[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image054[4] "src=" http://s3.51cto.com/wyfs02/M01/5D/F9/ Wkiol1uoj8wdc5jqaagpflbvtni672.jpg "" 510 "height=" 460 "/>
650) this.width=650; "title=" clip_image055[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image055[4] "src=" http://s3.51cto.com/wyfs02/M02/5D/F9/ Wkiol1uoj8ajhh7yaabgrr8dfwe480.jpg "" 235 "height=" 154 "/>
650) this.width=650; "title=" clip_image057[4] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image057[4] "src=" http://s3.51cto.com/wyfs02/M00/5D/F9/ Wkiol1uoj8eadfjxaaebsqcruaq102.jpg "" 558 "height=" 314 "/>
Note: When you select Automatic selection on import, there is no second certificate in.
650) this.width=650; "title=" clip_image059[6] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; margin:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image059[6] "src=" http://s3.51cto.com/wyfs02/M00/5D/FE/ Wkiom1uojnuygkddaad8r96bzxy393.jpg "" 558 "height=" 261 "/>
650) this.width=650; "title=" clip_image061[6] "style=" border-top:0px; border-right:0px; Background-image:none; border-bottom:0px; padding-top:0px; padding-left:0px; border-left:0px; padding-right:0px "border=" 0 "alt=" clip_image061[6] "src=" http://s3.51cto.com/wyfs02/M02/5D/FE/wKiom1UojnyArHE_ Aabgbmned8i696.jpg "" 558 "height="/>
Proof: Certificates can be exported to others for use.
Not finished, to be continued ...
Next: IIS SSL client certificate (ignore/accept/must) three--thinking verification (1)
IIS SSL Client certificate (ignore/accept/must) three--thinking verification (1)