Client Cerificate with TMG 2010

We have a website that we want to publish using TMG 2010 SP2 RU1

We would like to use FBA, protected by a certificate. Goal is that only have users access the FBA when they have a correct ClientCertificate. After that, LDAP authentication is used. To be clear: It is not the intention to use the client certificate to authenticate the user to AD.

To accomplish this I have done the following:

- Working installation of TMG, not domain joined

- installed a Enterprise Sub CA which deployes UserCertificates to users.

- Deployed a user certificate to the user with which I am trying access the webpage

- Installed the ROOT and SubCa certificates on the TMG server, so it will trust the client certificates

- Created a HTTP location for CRL which is accessible for the TMG servers

- The TMG listener is configured with: Require SSL client certificate

When I access the site, I get an error:

"Error Code: 403 Forbidden. The page requires a client certificate as part of the authentication process. If you are using a smart card, you will need to insert your smart card to select an appropriate certificate. Otherwise, contact your server administrator. (12213) .

The following error is logged in TMG: "12313 The page requires a client certificate as part of the authentication
process. If you are using a smart card, you will need to insert your smart card
to select an appropriate certificate. Otherwise, contact your server
administrator"

As far as I understand IE should come up with a popup to select the usercertificate to authenticate with. But it does not.

To fix the problem I used this URL:

http://blogs.technet.com/b/isablog/archive/2013/03/06/clients-are-not-prompted-to-choose-a-certificate-when-authenticating-to-isa-tmg.aspx : I added the regkey, but no effect.

I also following the next post, but without luck. I have the same scenario as in this thread:

http://social.technet.microsoft.com/Forums/forefront/en-US/1dfe9c23-778f-40a4-92c3-cc1d5446681b/problem-using-client-ssl-certificate

An help would be much appreciated.

July 4th, 2013 10:19am

Hi,

for client certificate authentication, the TMG Server must be a member of the Active Directory domain

Free Windows Admin Tool Kit Click here and download it now
July 4th, 2013 11:48pm

Hi,

for client certificate authentication, the TMG Server must be a member of the Active Directory

July 5th, 2013 3:30am

Hey

Try to follow all the steps from the link below:

http://social.technet.microsoft.com/Forums/forefront/en-US/fe01f9da-d124-4ca5-ac2e-8b8dd29877d5/publishing-webserver-with-ssl-certificate-spn#973f6a5d-a4f4-4e0b-8b04-54f67feacaf9

July 5th, 2013 10:20am

Found the issue. The TMG server was generating Event 36885 Schannel. The list of Certificates trusted by the server was too long. After removing a lot of unused root certificates it worked. Now IE is popping up asking for the client certificate. After the certificate is send to TMG and is valid, the FBA is displayed for credentials. Also CRL checking for the certificate is working.

Free Windows Admin Tool Kit Click here and download it now
July 5th, 2013 10:28am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics