Force Send Root CA with Request

Viewed 111

We have third party API provider that provided an SOAP API. They have provided 3 certificates,

  1. Client Cert
  2. Intermediate Cert
  3. Root Cert

All certs are installed locally. They have provided a pfx cert with password. We have uploaded this pfx in SOAP UI tool and run a request it worked. Then we tried the same with .NET request,

var binding = new BasicHttpBinding(BasicHttpSecurityMode.Transport);
var client = new ServiceReference1.myClient(binding, new EndpointAddress(serviceUrl));
binding.Security.Transport.ClientCredentialType = HttpClientCredentialType.Certificate;
var certificate = new X509Certificate2(certificateBinary, certificatePassword);
client.ClientCredentials.ClientCertificate.Certificate = certificate;

It failed with handshake failure error.

Then we monitored both SOAP UI traffic and .NET code traffic using WireShark.

enter image description here

Clearly the .NET is not sending Root CA. The problem is that request is rejected by the third party API if Root CA is not present in the request. How can force send ROOT CA.

0 Answers
Related