To use client certificate authentication for publishing over HTTPS
-
In the Forefront TMG Management console, in the tree, click the Firewall Policy node.
-
In the details pane, click the applicable Web publishing rule.
-
On the Tasks tab, click Edit Selected Rule.
-
On the Listener tab, click Properties.
-
On the Connections tab, verify that Enable SSL (HTTPS) connections on port is selected.
-
If you do not want to allow HTTP connections without client certificate authentication, verify that Enable HTTP connections on port is not selected.
-
On the Authentication tab, do one of the following:
- If Method clients use to authenticate to Forefront TMG
is set to HTTP Authentication or No Authentication,
select SSL Client Certificate Authentication in the
drop-down list, and click Advanced.
- If Method clients use to authenticate to Forefront TMG
is set to HTML Form Authentication, click Advanced.
You should select Require SSL client certificate only if you
want to require that an SSL client certificate be sent in the HTTPS
request before the HTML form is presented to the user.
- If Method clients use to authenticate to Forefront TMG
is set to HTTP Authentication or No Authentication,
select SSL Client Certificate Authentication in the
drop-down list, and click Advanced.
-
On the Client Certificate Trust List tab, select one of the following:
- Accept any client certificate trusted by
the Forefront TMG computer. Select this option if you want the
list of acceptable certification authorities to include all
certification authorities whose root certificate is installed in
the Trusted Root Certification Authorities store on the Forefront
TMG computer.
- Only accept client certificates issued by
the certification authorities selected below. Select this
option if you want to limit the list of certification authorities
whose certificates will be trusted.
- Accept any client certificate trusted by
the Forefront TMG computer. Select this option if you want the
list of acceptable certification authorities to include all
certification authorities whose root certificate is installed in
the Trusted Root Certification Authorities store on the Forefront
TMG computer.
-
On the Client Certificate Restrictions tab, define the restrictions that the SSL client certificates must match.
-
Click OK to close the Advanced Authentication Options page.
-
On the Certificates tab, verify that an SSL server certificate is selected, and then click OK.
-
For forms-based authentication, on the Traffic tab, select Require SSL Client Certificate.
-
Click OK.
-
In the details pane, click Apply, and then click OK.
Note: |
---|
|
Related Topics
Copyright © 2009 by Microsoft Corporation. All rights reserved.