Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 558549
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 13, 20262026-05-13T12:08:38+00:00 2026-05-13T12:08:38+00:00

My MOSS 2007 instance (IIS 6) uses Windows Authentication and IIS’ Directory Service Mapping

  • 0

My MOSS 2007 instance (IIS 6) uses Windows Authentication and IIS’ Directory Service Mapping (against Active Directory), allowing the user to authenticate using only her smartcard client certificate, without any username/password, and regardless of what (if any) domain the client workstation is joined to. The IIS instance is set to require client certificates.

My understanding is that, for IIS to find (in Active Directory) an account associated with the client certificate, it must be able to read from it a “User Principle Name” (sometimes called “User Logon Name”).

My user’s smartcard has two client certificates issued by the same Root CA. One specifies a UPN. The other does not. She’s able to choose from either certificate when accessing the site. If she chooses the certificate without the UPN, authentication is certain to fail.

What can I do to make the browser’s certificate selection dialog show only certificates which IIS at least has a chance of matching to an account (again: DSM & AD)?

Put more technically: how do I limit the MOSS user’s client certificate selection options to those that have a UPN in the “Subject Alternate Name” field?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-13T12:08:38+00:00Added an answer on May 13, 2026 at 12:08 pm

    I don’t think you can change this. I believe the certificate selection screen is part of Internet Explorer.

    If the user chooses a certificate that doesn’t have a UPN associated, you could prompt the user to select another certificate and try again.

    Edit: Since tapping into the MOSS security framework could be difficult, you can implement this as an HTTPHandler and add it to the MOSS root web.config.

    When the user request comes in, the handler gets first dibs and can redirect to the “try again” page if the UPN is missing from the cert.

    The “try again” page will have to retry the request by opening another window to get another certificate prompt.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

As you may know, MOSS 2007 offers functionality to synchronize Active Directory properties to
I'm building a MOSS 2007 site on Windows 2008 R2, 64 bit. Not wanting
we are using SharePoint Server (MOSS 2007) with Windows Integrated Security. A few computers
I have written the following code to edit the User Profiles for MOSS 2007.
I am facing a strange error in MOSS 2007 running under Windows 2008. I
[SharePoint/MOSS 2007] I want to access several web services (on external sites, with WSDL
In SharePoint (MOSS 2007) search, I need to match an exact number such as
We are currently implementing MOSS 2007 to replace an older portal system (Plumtree) and
I have modified my MOSS 2007 configuration to query a given target AD successfully.
EDIT: Server is MOSS 2007 Enterprise, running SP1 and all patches up to, but

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.