I'm currently implementing a small HTTP server using Microsoft HTTP Server API Version 2.0 (http://msdn.microsoft.com/en-us/library/windows/desktop/aa364510(v=vs.85).aspx).

I need to enable HTTPS on server side and also demand client certificate when client requests are coming in ( I need the client to be able to authenticate the server and the server to authenticate the client and they should communicate over SSL).

So far I've been able to enable server-side SSL, so I can connect securely to {https://127.0.0.1:9999/hello} site, make requests to server and receive responses, but I haven't been able to turn on the feature that requests client certificate as well (and verifys it).

I said in my application code that I'm listening "{https://127.0.0.1:9999/hello}" URL (this was the URL I added to URL group) and then I used netsh.exe tool to bind the 9999 port to SSL:

C:\>netsh http add sslcert ipport=0.0.0.0:9999 certhash=e515b6512e92f4663252eac72c28a784f2d78c6 appid={2C565242-B238-11D3-442D-0008C779D776} clientcertnegotiation=enable

I'm not sure what this "clientcertnegotiation=enable" should exactly do, the docs said it should "turn on negotiation of certificate". So now I added one additional function call to my HTTP Server code:

  DWORD answer = 0;
  HTTP_SSL_CLIENT_CERT_INFO sslClientCertInfo;
  ULONG bytesReceived;
  answer = HttpReceiveClientCertificate(hReqQueue, pRequest->ConnectionId, 0,
      &sslClientCertInfo, sizeof( HTTP_SSL_CLIENT_CERT_INFO ), &bytesReceived, NULL );

I understood that now the client should be prompted for certificate, but it does not work (I'm probably doing something wrong, so that is the reason why

Edit
Report