mTLS authentication on IIS 10.0 with Belgian eID card

Cyril COLIN 0 Points de réputation
2025-04-17T10:19:01.95+00:00

Hello,

I've been tasked to make a POC API that would authenticate external users with their Belgian ID Card and a custom registration request/validation process.

As the eID uses PKCS#11 and the card reader is not accessible in web environment (which is expected), I decided that my best shot would be through Mutual TLS authentication. As it would allow the app to automatically validate the certificate and access/store it for review and validation.

I'm developping the app in a .NET 8.0 WebAPI and deploying it on an IIS 10.0 on a Windows server 2022 VM.

The app itself work correctly locally, and the certificate is accessible through the HttpContext.Connection.ClientCertificate property.

I believe I've done things correctly but I'm still stuck on a "HTTP Error 403.13 - Forbidden

Your client certificate was revoked, or the revocation status could not be determined." error.

This error only happens when app is deployed and ran on the IIS.

Here are a few screenshots to show the configuration of the IIS

Bindings:Image de l’utilisateur

(I disabled TLS 1.3 over TCP because it would cause a "CONNECTION_RESET" error in chrome)

SSL Settings:

Image de l’utilisateur

(I used "Accept" as this is only a test server)

The Event Viewer Logs:

Image de l’utilisateur The Trusted Root Certification Authorities:rootca

I imported all Belgium Root CA's in the Trusted Root CAs of the server.

Il also imported the current Intermediate Citizen CA in the Intermediate CAs of the server:

Image de l’utilisateur

The actual 403 error:

Image de l’utilisateur

I do not know why I still have this error as the CRL and OCSP are accessible from the server (using edge also works):

Image de l’utilisateur

Image de l’utilisateur

And I found a command to run on the server that also seems to state that the certificate is valid and that revocation checks passed.

Command: certutil -urlfetch -verify "Cyril Colin (Authentication).DER"

Output (I removed some of my data as I do not know if it is sensitive or not):

Issuer:

CN=Citizen CA

SERIALNUMBER=202310

OU=QTSP: FPS Policy and Support - BOSA (NTRBE-0671516647)

OU=CA/RA: FPS Home Affairs - BIK-GCI (NTRBE-0362475538)

O=Kingdom of Belgium - Federal Government

L=Brussels

C=BE

Name Hash(sha1): a0a5f787b45fa08ba939cb71ca784f8e1becc2b3

Name Hash(md5): 1a5720f2cc797de8bdfcc34b3ae818a6

Subject:

CN=Cyril Colin (Authentication)

SERIALNUMBER= ###REMOVED###

G=Cyril ###REMOVED###

SN=Colin

C=BE

Name Hash(sha1): ###REMOVED###

Name Hash(md5): ###REMOVED###

Cert Serial Number: ###REMOVED###

dwFlags = CA_VERIFY_FLAGS_CONSOLE_TRACE (0x20000000)

dwFlags = CA_VERIFY_FLAGS_DUMP_CHAIN (0x40000000)

ChainFlags = CERT_CHAIN_REVOCATION_CHECK_CHAIN_EXCLUDE_ROOT (0x40000000)

HCCE_LOCAL_MACHINE

CERT_CHAIN_POLICY_BASE

-------- CERT_CHAIN_CONTEXT --------

ChainContext.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)

ChainContext.dwRevocationFreshnessTime: 148 Days, 21 Hours, 23 Minutes, 11 Seconds

SimpleChain.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)

SimpleChain.dwRevocationFreshnessTime: 148 Days, 21 Hours, 23 Minutes, 11 Seconds

CertContext[0][0]: dwInfoStatus=102 dwErrorStatus=0

Issuer: CN=Citizen CA, SERIALNUMBER=202310, OU=QTSP: FPS Policy and Support - BOSA (NTRBE-0671516647), OU=CA/RA: FPS Home Affairs - BIK-GCI (NTRBE-0362475538), O=Kingdom of Belgium - Federal Government, L=Brussels, C=BE

NotBefore: 07-07-23 23:35

NotAfter: 07-07-33 23:59

Subject: CN=Cyril Colin (Authentication), SERIALNUMBER=###REMOVED###, G=Cyril ###REMOVED###, SN=Colin, C=BE

Serial: ###REMOVED###

Cert: ###REMOVED###

Element.dwInfoStatus = CERT_TRUST_HAS_KEY_MATCH_ISSUER (0x2)

Element.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)

---------------- Certificate AIA ----------------

Verified "Certificate (0)" Time: 0 b01702adb796e044ca320485bd243543632c5ab4

[0.0] http://crt.eidpki.belgium.be/eid/eidc202310.crt

---------------- Certificate CDP ----------------

Verified "Base CRL (67ee)" Time: 0 6c8a93a6ee6540bc3f9961053f571435d63971cd

[0.0] http://crl.eidpki.belgium.be/eid/eidc202310.crl

---------------- Base CRL CDP ----------------

No URLs "None" Time: 0 (null)

---------------- Certificate OCSP ----------------

Verified "OCSP" Time: 0 a220f7411e0ff8ffa42d7b47decd661f886d7803

[0.0] http://ocsp.eidpki.belgium.be/eid/0

--------------------------------

CRL 67ee:

Issuer: CN=Citizen CA, SERIALNUMBER=202310, OU=QTSP: FPS Policy and Support - BOSA (NTRBE-0671516647), OU=CA/RA: FPS Home Affairs - BIK-GCI (NTRBE-0362475538), O=Kingdom of Belgium - Federal Government, L=Brussels, C=BE

ThisUpdate: 13-04-25 00:56

NextUpdate: 20-04-25 00:56

CRL: 6c8a93a6ee6540bc3f9961053f571435d63971cd

Delta CRL 6874:

Issuer: CN=Citizen CA, SERIALNUMBER=202310, OU=QTSP: FPS Policy and Support - BOSA (NTRBE-0671516647), OU=CA/RA: FPS Home Affairs - BIK-GCI (NTRBE-0362475538), O=Kingdom of Belgium - Federal Government, L=Brussels, C=BE

ThisUpdate: 17-04-25 11:28

NextUpdate: 17-04-25 12:28

CRL: 95a2b233cd6beb17ee9d3512ff3c6d4ad91d6455

Issuance[0] = 2.16.56.13.6.1.1.1000

Issuance[1] = 0.4.0.2042.1.2

Application[0] = 1.3.6.1.5.5.7.3.2 Client Authentication

CertContext[0][1]: dwInfoStatus=102 dwErrorStatus=0

Issuer: CN=Belgium Root CA6, OU=FPS Policy and Support - BOSA (NTRBE-0671516647), OU=FPS Home Affairs - BIK-GCI (NTRBE-0362475538), O=Kingdom of Belgium - Federal Government, L=Brussels, C=BE

NotBefore: 07-12-22 15:04

NotAfter: 07-12-34 15:04

Subject: CN=Citizen CA, SERIALNUMBER=202310, OU=QTSP: FPS Policy and Support - BOSA (NTRBE-0671516647), OU=CA/RA: FPS Home Affairs - BIK-GCI (NTRBE-0362475538), O=Kingdom of Belgium - Federal Government, L=Brussels, C=BE

Serial: 74c60915c475ea0e41ec28b96b5cfe977264c7c2

Cert: b01702adb796e044ca320485bd243543632c5ab4

Element.dwInfoStatus = CERT_TRUST_HAS_KEY_MATCH_ISSUER (0x2)

Element.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)

---------------- Certificate AIA ----------------

Verified "Certificate (0)" Time: 0 98989feec16ad774615415e93a963ea3eef5fe4f

[0.0] http://crt.eidpki.belgium.be/eid/brca6.crt

---------------- Certificate CDP ----------------

Verified "Base CRL (08)" Time: 0 5de7925cdc05926ea32c390d41fde431a6210d7b

[0.0] http://crl.eidpki.belgium.be/eid/brca6.crl

---------------- Base CRL CDP ----------------

No URLs "None" Time: 0 (null)

---------------- Certificate OCSP ----------------

Verified "OCSP" Time: 0 d92dfc60e401072cb365fea87cbe8362dbfcae8e

[0.0] http://ocsp.eidpki.belgium.be/eid/brca6

--------------------------------

CRL 08:

Issuer: CN=Belgium Root CA6, OU=FPS Policy and Support - BOSA (NTRBE-0671516647), OU=FPS Home Affairs - BIK-GCI (NTRBE-0362475538), O=Kingdom of Belgium - Federal Government, L=Brussels, C=BE

ThisUpdate: 19-11-24 14:39

NextUpdate: 19-11-25 14:39

CRL: 5de7925cdc05926ea32c390d41fde431a6210d7b

Application[0] = 1.3.6.1.5.5.7.3.2 Client Authentication

Application[1] = 1.3.6.1.5.5.7.3.4 Secure Email

CertContext[0][2]: dwInfoStatus=10a dwErrorStatus=0

Issuer: CN=Belgium Root CA6, OU=FPS Policy and Support - BOSA (NTRBE-0671516647), OU=FPS Home Affairs - BIK-GCI (NTRBE-0362475538), O=Kingdom of Belgium - Federal Government, L=Brussels, C=BE

NotBefore: 03-06-20 12:01

NotAfter: 03-06-40 12:01

Subject: CN=Belgium Root CA6, OU=FPS Policy and Support - BOSA (NTRBE-0671516647), OU=FPS Home Affairs - BIK-GCI (NTRBE-0362475538), O=Kingdom of Belgium - Federal Government, L=Brussels, C=BE

Serial: 718b57ff6b693e5a1c235ed887a3ef51f4010f26

Cert: 98989feec16ad774615415e93a963ea3eef5fe4f

Element.dwInfoStatus = CERT_TRUST_HAS_KEY_MATCH_ISSUER (0x2)

Element.dwInfoStatus = CERT_TRUST_IS_SELF_SIGNED (0x8)

Element.dwInfoStatus = CERT_TRUST_HAS_PREFERRED_ISSUER (0x100)

---------------- Certificate AIA ----------------

No URLs "None" Time: 0 (null)

---------------- Certificate CDP ----------------

No URLs "None" Time: 0 (null)

---------------- Certificate OCSP ----------------

No URLs "None" Time: 0 (null)

--------------------------------

Exclude leaf cert:

Chain: d57c0c16f8dacd8ad4a49d828cda3e2c52d80b78

Full chain:

Chain: 43d59c3b0c2fa8026f9f13a26b8511d9001b1ce9

------------------------------------

Verified Issuance Policies:

2.16.56.13.6.1.1.1000

0.4.0.2042.1.2

Verified Application Policies:

1.3.6.1.5.5.7.3.2 Client Authentication (Client TLS)

Leaf certificate revocation check passed

CertUtil: -verify command completed successfully.

Has anyone met a similar problem and could give me pointers ?

I've been searching for solutions for a while but I can't get it working. Any help would be greatly appreciated.

Thanks in advance,

Cyril.

Windows pour les entreprises | Windows Server | Services d’annuaire | Certificats et infrastructure à clé publique (PKI)
0 commentaires Aucun commentaire

Votre réponse

Les réponses peuvent être marquées comme « Acceptées » par l’auteur de la question et « Recommandées » par les modérateurs, ce qui aide les utilisateurs à savoir que la réponse a résolu le problème de l’auteur.