How to map certificates with windows accounts
Jason Taylor, Prashant Bansode, Carlos Farre, Madhu Sundararajan, Steve Gregersen
Client certificates are not mapped to Windows accounts by default. Set the mapClientCertificateToWindowsAccount property to true to map certificates to Windows accounts.
Use the following steps to map certificates to Windows accounts:
- Select the IIS vs Active Directory Mapping.
- IIS Mapping is useful if you need only a limited number of mappings or a different mapping on each WCF Service.
- Use Active Directory mapping when the account mappings are identical on all IIS servers. Active Directory mapping is easier to maintain than IIS mapping because you only have to create the mapping in one location.
- Configure the IIS / Active directory for mapping the certificates.
- Once you have enabled the client certificate mapping feature, set the mapClientCertificateToWindowsAccount property to true.
* <authentication mapClientCertificateToWindowsAccount="true" />*