IIS客户端证书认证:Accept与Require模式下证书验证规则咨询
Answers to Your IIS Client Certificate Questions
1. Does IIS validate client certificate validity when choosing Accept or Require?
Absolutely—both Accept and Require trigger full certificate validity checks in IIS. Here’s the breakdown:
- When set to
Require: Clients must present a valid certificate to access the resource. If the certificate is expired, revoked, untrusted, or fails any other validity check, IIS will immediately block the request. - When set to
Accept: Clients can choose to send a certificate or not. But if they do submit one, IIS will fully validate it—any invalid certificate will result in the request being rejected. The only difference fromRequireis that a missing certificate won’t block access.
2. Is your interpretation of the statement correct?
No, that understanding is incorrect. Let’s clarify the original context:
"If you configured IIS to demand..."
This refers to the Require setting (since "demand" implies a mandatory requirement). Your take that "IIS won't validate certificates unless Accept is selected" is backwards—both settings validate certificates when one is provided. The key distinction isn’t whether validation happens, but whether a certificate is required to proceed:
Require: Certificate is mandatory, and must be valid to gain access.Accept: Certificate is optional, but if provided, it must pass all validity checks.
IIS never skips validation for either option when a client submits a certificate.
内容的提问来源于stack exchange,提问作者Errol Neal
相关产品推荐
相关产品推荐

