WSE 3.0, Verisign and Data Encipherment
I have a verisign certificate, and the Key Usage shows as Digital
Signature, Key Encipherment (a0). When I try to use the WSE 3.0
configuration tool, I cannot add the certificate because the
certificate does not support Data Encipherment.
However, when I manually add the certificate programatically, and
check the SupportsDataEncryption and SupportsDigitalSignature
properties, it shows the certificate does support them.
I have seen a blog entry where the WSE needs the Data Encipherment
policy to work. Verisign advised us they don't sell a certificate for
that, although admittedly the tech we spoke with was not certain.
I have been trying for some time to connect to a 3rd party vendor over
HTTPS using the MutualCertificate10Assertion policy, with no luck. The
errors we have seen are all cryptic, and the vendor cannot determine
the cause from their end. Some of the erros have ben WSE910, WS
Seceurity Error 181000 and WS Security Error 111000.
Anyone else come across issues using Verisign certificates without
Data Encipherment? Will switching to a cetificate (cannot use a self
generated certificate) help?
Thanks!
Date:Sun, 19 Aug 2007 17:28:23 -0700
Author:
|