From : David Gabrichidze <David.Gabrichidze@ugt.ge>
To : Batiashvili Zurab <zbatiashvili@moh.gov.ge>
Subject : How to Grant IIS 7.5 access to a certificate in certificate store?
Received On : 04.03.2015 14:43

1.    Create / Purchase certificate. Make sure it has a private key.

2.    Import the certificate into the "Local Computer" account. Best to use Certificates MMC. Make sure to check "Allow private key to be exported"

3.    Based upon which, IIS 7.5 Application Pool's identity use one of the following.

·         IIS 7.5 Website is running under ApplicationPoolIdentity. Using Certificates MMC, added "IIS AppPool\AppPoolName" to Full Trust on certificate in "Local Computer\Personal". Replace "AppPoolName" with the name of your application pool.

·         IIS 7.5 Website is running under NETWORK SERVICE. Using Certificates MMC, added "NETWORK SERVICE" to Full Trust on certificate in "Local Computer\Personal".

·         IIS 7.5 Website is running under "MyIISUser" local computer user account. Using Certificates MMC, added "MyIISUser" (a new local computer user account) to Full Trust on certificate in "Local Computer\Personal".

EDIT: To add a user to Full Trust of a certificate. Right click the certificate -> All Tasks -> Manage Private Keys

 

 

http://serverfault.com/questions/131046/how-to-grant-iis-7-5-access-to-a-certificate-in-certificate-store

 

 

 

დათო

 



This email and attachments may contain confidential information and/or copyright material. This email is intended for the use of the addressee only. Any unauthorised use may be unlawful. If you receive this email by mistake, please advise the sender immediately by using the reply facility in your email software, immediately delete the original e-mail and it’s attachments from your system and do not disclose or otherwise take any action against its content. While this email has been scanned for all known viruses, internet communications may not be secure or virus-free; UGT does not accept responsibility for any damage arising from unauthorized access to this e-mail, or interference with, by any third-party.