ASP.NET MVC Client Certificate validation

Viewed 570

I'm actually trying to expose some methods of an ASP.NET MVC specific controller, in order to secure sensitive calls.

The entire website doesn't have to be protected by a specific SSL certificate, but some requests are.

Here is my code (as simple as it is) to get "Data", as you can see, I first check the SSL certificate, then the process continues if the SSL Certificate is correct :

public string GetData()
{
    try
    {
        var certificate = Request.ClientCertificate;

        if (certificate == null || string.IsNullOrEmpty(certificate.Subject))
        {
            // certificate may not be here
            throw new Exception("ERR_00_NO_SSL_CERTIFICATE");
        }

        if (!certificate.IsValid || !IsMyCertificateOK(certificate))
        {
            // certificate is not valid
            throw new Exception("ERR_01_WRONG_SSL_CERTIFICATE");
        }

        // Actions here ...
    }
    catch (Exception)
    {
        Response.StatusCode = 400;
        Response.StatusDescription = "Bad Request";
    }

}

Here is my IIS configuration :

SSL Configuration in IIS

SSL Certificate is set to "Accept", thus, I hope I could get the client certificate in the Request.ClientCertificate property, but it's never the case, I never get the certificate set in my client.

Here is my client code (copied from generated Postman C# code) :

string PFX_PATH = @"C:\Test\test.pfx"; // set here path of the PFX file
string PFX_PASSWORD = "password"; // set here password of the PFX file

var client = new RestClient("https://mywebsite.com/GetData?input=test");
client.Timeout = -1;

client.ClientCertificates = new System.Security.Cryptography.X509Certificates.X509CertificateCollection()
{
    new System.Security.Cryptography.X509Certificates.X509Certificate(PFX_PATH,
    PFX_PASSWORD,
    System.Security.Cryptography.X509Certificates.X509KeyStorageFlags.Exportable)
};

var request = new RestRequest(Method.GET);
IRestResponse response = client.Execute(request);
Console.WriteLine(response.Content);

The PFX file has a private key, and is accessible from client side.

Am I missing something regarding the IIS configuration, or should I update my web.config somehow ?

0 Answers
Related