BizTalk and X509 V1 Certificates

I have a trading partner that has given us a public key certificate for encryption/signing for AS2 communication. I have imported the certificate into "Local Computer\Other People" but BizTalk still does not recognize the certificate when I attempt to assign it to a send port in BTS 2013. The only difference I can see with their certificate with others that work properly in my system is that the "Version" attribute in the Details tab says "V1". I assume this means X509 V1. Is BizTalk unable to recognize a certificate of this type.

Thanks for any assistance,

Bob Mc.

May 28th, 2015 2:17pm

Try importing in into the "Other People" folder for the DOMAIN ACCOUNT which is hosting the instance of your AS2 Send/Receive Ports.

Regards.

Free Windows Admin Tool Kit Click here and download it now
May 29th, 2015 1:03am

Thanks for your suggestion.

There doesn't seem to be an "Other People" folder in the certificate manager for any domain accounts. It's only available in the "Local Computer" certificate store. Is that what you had in mind? This is on Windows Server 2012 so I don't know if that makes a difference.

Bob Mc.

May 29th, 2015 8:37am

It appears from information in this thread that BizTalk does not support any X509 version except for version 3.

https://msdn.microsoft.com/en-us/library/aa547244.aspx

Now for a more difficult question. What are my options? It may be difficult for the trading partner to reissue the certificate since other partners that they have are already using that cert. Can I use the cert in an orchestration or is that subject to the same restriction (BizTalk newbie here)?

Bob Mc.

Free Windows Admin Tool Kit Click here and download it now
May 29th, 2015 8:51am

Hi Bob,

Did you got solution to the problem. We are also trying to consume X509 V1 certificate enabled POX service. We are using Http adapter to call POX service and unfortunately neither we aer able to connect and  even all message are going in active state. We are facing weired condition and as there is no exception not able to figure out.

May 31st, 2015 1:48am

gennii,

Unfortunately, I can't speak specifically about consuming X509 V1 certificates via a POX service. I'm working with BizTalk 2013 and using it for simple EDI with receiver and send ports. I'm trying to rig a send port with our trading partner's V1 certificate but BizTalk does not support it, as I noted in my previous post.

See here for more information: https://msdn.microsoft.com/en-us/library/aa547244.aspx

There don't appear to be any workarounds. A V3 certificate is necessary in my case.

Sorry I can't offer more assistance.

Bob Mc.

Free Windows Admin Tool Kit Click here and download it now
May 31st, 2015 4:28pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics