IIS - Accessing secure web service - Asked By Christopher Baker on 15-Nov-11 09:09 AM

I'm trying to modify an existing (Classic ASP of all things) site to hit a secure web service at Chase Bank. Chase has installed our certificate on their server. I am having trouble, however, understanding how I have to configure my server to properly pass our certificate to Chase.

I wrote a little test page to test connectivity:

Dim objXMLHTTP : set objXMLHTTP = Server.CreateObject("MSXML2.ServerXMLHTTP")
Dim strRequest, strResult, strFunction, strURL, strNamespace

'URL to SOAP namespace and connection URL
strURL = "https://ws.payconnexion.com:1401/pconWS/9_3/"

strRequest="<?xml version=""1.0"" encoding=""utf-8""?>" _
& "<soap:Envelope xmlns:soap=""http://www.w3.org/2003/05/soap-envelope"" xmlns:_3=""http://ws.payconnexion.com/pconWS/9_3"">" _
& "<soap:Header /><soap:Body>" _
& "<_3:initiatePublicSessionTransferRequest><_3:billerGroupId>X50</_3:billerGroupId><_3:productCode>SinglePayment</_3:productCode>" _
& "<_3:billerPayorId xsi:nil=""true"" xmlns:xsi=""http://www.w3.org/2001/XMLSchema-instance""/>" _
& "<_3:amountDue>1.50</_3:amountDue><_3:amountDueTbd>false</_3:amountDueTbd><_3:dueDate>2011-08-15</_3:dueDate><_3:dueDateTbd>false</_3:dueDateTbd>" _
& "<_3:level2SalesTaxAmount xsi:nil=""true"" xmlns:xsi=""http://www.w3.org/2001/XMLSchema-instance""/>" _
& "<_3:level2CustomerReferenceNumber xsi:nil=""true"" xmlns:xsi=""http://www.w3.org/2001/XMLSchema-instance""/>" _
& "<_3:userId>11112222</_3:userId>" _
& "<_3:locale xsi:nil=""true"" xmlns:xsi=""http://www.w3.org/2001/XMLSchema-instance""/>" _
& "<_3:parameters><_3:parameter><_3:name>StatementNo</_3:name><_3:value>123456</_3:value></_3:parameter></_3:parameters><_3:disallowLogin>false</_3:disallowLogin>" _
& "<_3:returnSessionId xsi:nil=""true"" xmlns:xsi=""http://www.w3.org/2001/XMLSchema-instance""/>" _
& "<_3:returnUrl xsi:nil=""true"" xmlns:xsi=""http://www.w3.org/2001/XMLSchema-instance""/>" _
& "</_3:initiatePublicSessionTransferRequest></soap:Body></soap:Envelope>"

objXMLHTTP.open "POST", "" & strURL & "", False
objXMLHTTP.setRequestHeader "Content-Type", "text/xml; charset=utf-8"
objXMLHTTP.setRequestHeader "Content-Length", Len(strRequest)

objXMLHTTP.setRequestHeader "SOAPAction", "https://ws.payconnexion.com:1401/pconWS/9_3/initiatePublicSessionTransferRequest"

'send the request and capture the result
objXMLHTTP.send strRequest
strResult = "strResult: " & objXMLHTTP.responseText

'display the XML
response.write strResult


The line I've highlighted in bold red throws this error:

Error Type:
msxml3.dll (0x80072F0C)
A certificate is required to complete client authentication

I believe that I need to configure IIS to send the correct certificate but would really appreciate any direction.

Thanks




Riley K replied to Christopher Baker on 15-Nov-11 09:09 PM


The server requires a client certificate. This certificate must be added to your machine or to the browser. The administrator of the server will have all the details for you.

Refer this link

http://support.microsoft.com/kb/302080/en-us

Regards
Reena Jain replied to Christopher Baker on 16-Nov-11 02:21 AM
Hi,

To make any SSL requests from the Web server, ServerXMLHTTP expects a client digital certificate to be installed, even if the target Web server does not require a client certificate. As a quick fix you can set the application protection to low in IIS
but you may want to look at
http://support.microsoft.com/?id=301429

May be helpful: http://support.microsoft.com/kb/302080

"To make any SSL requests from the Web server, ServerXMLHTTP expects a client digital certificate to be installed, even if the target Web server does not require a client certificate
Christopher Baker replied to Reena Jain on 16-Nov-11 08:22 AM
Thank you to both of you for your responses.

I have seen those KB articles, and am confident that you're on the right track. Chase Bank certainly requires my certificate, so setting the site security to low or ignoring SSL errors is not an option. Furthermore, I agree that all I have to do is pass Chase the right certificate. I've installed the certificates on my server. How do I ensure that IIS passes the right certificate to Chase?

Thanks for your help.