WCF and NetTcp security with Certificate










0















From the issuer Server, I created the server certificate and client one ( using XCA). then imported into my machine.



Service configuration looks like



<?xml version="1.0" encoding="utf-8"?>
<configuration>
<startup>
<supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.5.2"/>
</startup>
<system.serviceModel>

<services>
<service name="xxx.yyy.Providers.zzz" behaviorConfiguration="MetaDataBehvior" >
<host>
<baseAddresses>
<add baseAddress="net.tcp://localhost:9002/yyyService"/>
</baseAddresses>
</host>
<endpoint address="" binding="netTcpBinding" contract="xxx.yyy.Interfaces.Izzz" />
<endpoint address="mex" binding="mexTcpBinding" contract="IMetadataExchange" />
</service>
</services>

<behaviors>
<serviceBehaviors>
<behavior name="MetaDataBehvior">
<serviceMetadata />
</behavior>
<behavior>
<serviceCredentials>
<clientCertificate>
<authentication
certificateValidationMode="ChainTrust"
revocationMode="NoCheck" />
</clientCertificate>
<serviceCertificate
findValue="xxx.yyy.Server"
x509FindType="FindBySubjectName"
storeLocation="LocalMachine"
storeName="My" />
</serviceCredentials>
</behavior>
</serviceBehaviors>
</behaviors>

<bindings>
<netTcpBinding>
<binding name="NetTcpBinding" closeTimeout="00:01:00" openTimeout="00:01:00" receiveTimeout="00:10:00" sendTimeout="00:01:00" transactionFlow="false" hostNameComparisonMode="StrongWildcard" maxBufferPoolSize="524288" maxReceivedMessageSize="2147483647">
<readerQuotas maxDepth="32" maxStringContentLength="2147483647" maxArrayLength="2147483647" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" />
<reliableSession ordered="true" inactivityTimeout="00:10:00" enabled="false" />
<security mode="Message">
<message clientCredentialType="Certificate" />
</security>
</binding>
</netTcpBinding>
</bindings>

</system.serviceModel>
</configuration>


and client side looks like



<?xml version="1.0" encoding="utf-8"?>
<configuration>


<system.serviceModel>
<bindings>
<netTcpBinding>
<binding name="yyynetTcpBinding" closeTimeout="00:01:00" openTimeout="00:01:00" receiveTimeout="00:10:00" sendTimeout="00:01:00" transactionFlow="false" hostNameComparisonMode="StrongWildcard" maxBufferPoolSize="524288" maxReceivedMessageSize="2147483647">
<readerQuotas maxDepth="32" maxStringContentLength="2147483647" maxArrayLength="2147483647" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" />
<reliableSession ordered="true" inactivityTimeout="00:10:00" enabled="false" />
<security mode="Message">
<message clientCredentialType="Certificate" />
</security>
</binding>
</netTcpBinding>
</bindings>

<client>

<endpoint name="PrimaryService_TcpEndPoint" address ="net.tcp://localhost:9002/yyyService" behaviorConfiguration="yyyEndPointBEhavior"
binding="netTcpBinding" contract="xxx.yyy.Interfaces.Izzz">
<identity>
<dns value="10.0.5.187" />
</identity>
</endpoint>

</client>
<behaviors>
<endpointBehaviors>
<behavior name="yyyEndPointBEhavior">
<clientCredentials>
<clientCertificate
findValue="xxx.yyy.Client"
x509FindType="FindBySubjectName"
storeLocation="LocalMachine"
storeName="My" />
<serviceCertificate>
<authentication
certificateValidationMode="ChainTrust"
revocationMode="NoCheck" />
</serviceCertificate>
</clientCredentials>
</behavior>
</endpointBehaviors>
</behaviors>
</system.serviceModel>
<startup>
<supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.5.2"/>
</startup>

</configuration>


when start establishing the connection I got the following error



It is likely that certificate 'OU=xxx.yyy.Client, C=cc' may not have a private key that is capable of key exchange or the process may not have access rights for the private key. Please see inner exception for detail.



Invalid provider type specified.



Any idea how to solve that?










share|improve this question


























    0















    From the issuer Server, I created the server certificate and client one ( using XCA). then imported into my machine.



    Service configuration looks like



    <?xml version="1.0" encoding="utf-8"?>
    <configuration>
    <startup>
    <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.5.2"/>
    </startup>
    <system.serviceModel>

    <services>
    <service name="xxx.yyy.Providers.zzz" behaviorConfiguration="MetaDataBehvior" >
    <host>
    <baseAddresses>
    <add baseAddress="net.tcp://localhost:9002/yyyService"/>
    </baseAddresses>
    </host>
    <endpoint address="" binding="netTcpBinding" contract="xxx.yyy.Interfaces.Izzz" />
    <endpoint address="mex" binding="mexTcpBinding" contract="IMetadataExchange" />
    </service>
    </services>

    <behaviors>
    <serviceBehaviors>
    <behavior name="MetaDataBehvior">
    <serviceMetadata />
    </behavior>
    <behavior>
    <serviceCredentials>
    <clientCertificate>
    <authentication
    certificateValidationMode="ChainTrust"
    revocationMode="NoCheck" />
    </clientCertificate>
    <serviceCertificate
    findValue="xxx.yyy.Server"
    x509FindType="FindBySubjectName"
    storeLocation="LocalMachine"
    storeName="My" />
    </serviceCredentials>
    </behavior>
    </serviceBehaviors>
    </behaviors>

    <bindings>
    <netTcpBinding>
    <binding name="NetTcpBinding" closeTimeout="00:01:00" openTimeout="00:01:00" receiveTimeout="00:10:00" sendTimeout="00:01:00" transactionFlow="false" hostNameComparisonMode="StrongWildcard" maxBufferPoolSize="524288" maxReceivedMessageSize="2147483647">
    <readerQuotas maxDepth="32" maxStringContentLength="2147483647" maxArrayLength="2147483647" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" />
    <reliableSession ordered="true" inactivityTimeout="00:10:00" enabled="false" />
    <security mode="Message">
    <message clientCredentialType="Certificate" />
    </security>
    </binding>
    </netTcpBinding>
    </bindings>

    </system.serviceModel>
    </configuration>


    and client side looks like



    <?xml version="1.0" encoding="utf-8"?>
    <configuration>


    <system.serviceModel>
    <bindings>
    <netTcpBinding>
    <binding name="yyynetTcpBinding" closeTimeout="00:01:00" openTimeout="00:01:00" receiveTimeout="00:10:00" sendTimeout="00:01:00" transactionFlow="false" hostNameComparisonMode="StrongWildcard" maxBufferPoolSize="524288" maxReceivedMessageSize="2147483647">
    <readerQuotas maxDepth="32" maxStringContentLength="2147483647" maxArrayLength="2147483647" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" />
    <reliableSession ordered="true" inactivityTimeout="00:10:00" enabled="false" />
    <security mode="Message">
    <message clientCredentialType="Certificate" />
    </security>
    </binding>
    </netTcpBinding>
    </bindings>

    <client>

    <endpoint name="PrimaryService_TcpEndPoint" address ="net.tcp://localhost:9002/yyyService" behaviorConfiguration="yyyEndPointBEhavior"
    binding="netTcpBinding" contract="xxx.yyy.Interfaces.Izzz">
    <identity>
    <dns value="10.0.5.187" />
    </identity>
    </endpoint>

    </client>
    <behaviors>
    <endpointBehaviors>
    <behavior name="yyyEndPointBEhavior">
    <clientCredentials>
    <clientCertificate
    findValue="xxx.yyy.Client"
    x509FindType="FindBySubjectName"
    storeLocation="LocalMachine"
    storeName="My" />
    <serviceCertificate>
    <authentication
    certificateValidationMode="ChainTrust"
    revocationMode="NoCheck" />
    </serviceCertificate>
    </clientCredentials>
    </behavior>
    </endpointBehaviors>
    </behaviors>
    </system.serviceModel>
    <startup>
    <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.5.2"/>
    </startup>

    </configuration>


    when start establishing the connection I got the following error



    It is likely that certificate 'OU=xxx.yyy.Client, C=cc' may not have a private key that is capable of key exchange or the process may not have access rights for the private key. Please see inner exception for detail.



    Invalid provider type specified.



    Any idea how to solve that?










    share|improve this question
























      0












      0








      0








      From the issuer Server, I created the server certificate and client one ( using XCA). then imported into my machine.



      Service configuration looks like



      <?xml version="1.0" encoding="utf-8"?>
      <configuration>
      <startup>
      <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.5.2"/>
      </startup>
      <system.serviceModel>

      <services>
      <service name="xxx.yyy.Providers.zzz" behaviorConfiguration="MetaDataBehvior" >
      <host>
      <baseAddresses>
      <add baseAddress="net.tcp://localhost:9002/yyyService"/>
      </baseAddresses>
      </host>
      <endpoint address="" binding="netTcpBinding" contract="xxx.yyy.Interfaces.Izzz" />
      <endpoint address="mex" binding="mexTcpBinding" contract="IMetadataExchange" />
      </service>
      </services>

      <behaviors>
      <serviceBehaviors>
      <behavior name="MetaDataBehvior">
      <serviceMetadata />
      </behavior>
      <behavior>
      <serviceCredentials>
      <clientCertificate>
      <authentication
      certificateValidationMode="ChainTrust"
      revocationMode="NoCheck" />
      </clientCertificate>
      <serviceCertificate
      findValue="xxx.yyy.Server"
      x509FindType="FindBySubjectName"
      storeLocation="LocalMachine"
      storeName="My" />
      </serviceCredentials>
      </behavior>
      </serviceBehaviors>
      </behaviors>

      <bindings>
      <netTcpBinding>
      <binding name="NetTcpBinding" closeTimeout="00:01:00" openTimeout="00:01:00" receiveTimeout="00:10:00" sendTimeout="00:01:00" transactionFlow="false" hostNameComparisonMode="StrongWildcard" maxBufferPoolSize="524288" maxReceivedMessageSize="2147483647">
      <readerQuotas maxDepth="32" maxStringContentLength="2147483647" maxArrayLength="2147483647" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" />
      <reliableSession ordered="true" inactivityTimeout="00:10:00" enabled="false" />
      <security mode="Message">
      <message clientCredentialType="Certificate" />
      </security>
      </binding>
      </netTcpBinding>
      </bindings>

      </system.serviceModel>
      </configuration>


      and client side looks like



      <?xml version="1.0" encoding="utf-8"?>
      <configuration>


      <system.serviceModel>
      <bindings>
      <netTcpBinding>
      <binding name="yyynetTcpBinding" closeTimeout="00:01:00" openTimeout="00:01:00" receiveTimeout="00:10:00" sendTimeout="00:01:00" transactionFlow="false" hostNameComparisonMode="StrongWildcard" maxBufferPoolSize="524288" maxReceivedMessageSize="2147483647">
      <readerQuotas maxDepth="32" maxStringContentLength="2147483647" maxArrayLength="2147483647" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" />
      <reliableSession ordered="true" inactivityTimeout="00:10:00" enabled="false" />
      <security mode="Message">
      <message clientCredentialType="Certificate" />
      </security>
      </binding>
      </netTcpBinding>
      </bindings>

      <client>

      <endpoint name="PrimaryService_TcpEndPoint" address ="net.tcp://localhost:9002/yyyService" behaviorConfiguration="yyyEndPointBEhavior"
      binding="netTcpBinding" contract="xxx.yyy.Interfaces.Izzz">
      <identity>
      <dns value="10.0.5.187" />
      </identity>
      </endpoint>

      </client>
      <behaviors>
      <endpointBehaviors>
      <behavior name="yyyEndPointBEhavior">
      <clientCredentials>
      <clientCertificate
      findValue="xxx.yyy.Client"
      x509FindType="FindBySubjectName"
      storeLocation="LocalMachine"
      storeName="My" />
      <serviceCertificate>
      <authentication
      certificateValidationMode="ChainTrust"
      revocationMode="NoCheck" />
      </serviceCertificate>
      </clientCredentials>
      </behavior>
      </endpointBehaviors>
      </behaviors>
      </system.serviceModel>
      <startup>
      <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.5.2"/>
      </startup>

      </configuration>


      when start establishing the connection I got the following error



      It is likely that certificate 'OU=xxx.yyy.Client, C=cc' may not have a private key that is capable of key exchange or the process may not have access rights for the private key. Please see inner exception for detail.



      Invalid provider type specified.



      Any idea how to solve that?










      share|improve this question














      From the issuer Server, I created the server certificate and client one ( using XCA). then imported into my machine.



      Service configuration looks like



      <?xml version="1.0" encoding="utf-8"?>
      <configuration>
      <startup>
      <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.5.2"/>
      </startup>
      <system.serviceModel>

      <services>
      <service name="xxx.yyy.Providers.zzz" behaviorConfiguration="MetaDataBehvior" >
      <host>
      <baseAddresses>
      <add baseAddress="net.tcp://localhost:9002/yyyService"/>
      </baseAddresses>
      </host>
      <endpoint address="" binding="netTcpBinding" contract="xxx.yyy.Interfaces.Izzz" />
      <endpoint address="mex" binding="mexTcpBinding" contract="IMetadataExchange" />
      </service>
      </services>

      <behaviors>
      <serviceBehaviors>
      <behavior name="MetaDataBehvior">
      <serviceMetadata />
      </behavior>
      <behavior>
      <serviceCredentials>
      <clientCertificate>
      <authentication
      certificateValidationMode="ChainTrust"
      revocationMode="NoCheck" />
      </clientCertificate>
      <serviceCertificate
      findValue="xxx.yyy.Server"
      x509FindType="FindBySubjectName"
      storeLocation="LocalMachine"
      storeName="My" />
      </serviceCredentials>
      </behavior>
      </serviceBehaviors>
      </behaviors>

      <bindings>
      <netTcpBinding>
      <binding name="NetTcpBinding" closeTimeout="00:01:00" openTimeout="00:01:00" receiveTimeout="00:10:00" sendTimeout="00:01:00" transactionFlow="false" hostNameComparisonMode="StrongWildcard" maxBufferPoolSize="524288" maxReceivedMessageSize="2147483647">
      <readerQuotas maxDepth="32" maxStringContentLength="2147483647" maxArrayLength="2147483647" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" />
      <reliableSession ordered="true" inactivityTimeout="00:10:00" enabled="false" />
      <security mode="Message">
      <message clientCredentialType="Certificate" />
      </security>
      </binding>
      </netTcpBinding>
      </bindings>

      </system.serviceModel>
      </configuration>


      and client side looks like



      <?xml version="1.0" encoding="utf-8"?>
      <configuration>


      <system.serviceModel>
      <bindings>
      <netTcpBinding>
      <binding name="yyynetTcpBinding" closeTimeout="00:01:00" openTimeout="00:01:00" receiveTimeout="00:10:00" sendTimeout="00:01:00" transactionFlow="false" hostNameComparisonMode="StrongWildcard" maxBufferPoolSize="524288" maxReceivedMessageSize="2147483647">
      <readerQuotas maxDepth="32" maxStringContentLength="2147483647" maxArrayLength="2147483647" maxBytesPerRead="2147483647" maxNameTableCharCount="2147483647" />
      <reliableSession ordered="true" inactivityTimeout="00:10:00" enabled="false" />
      <security mode="Message">
      <message clientCredentialType="Certificate" />
      </security>
      </binding>
      </netTcpBinding>
      </bindings>

      <client>

      <endpoint name="PrimaryService_TcpEndPoint" address ="net.tcp://localhost:9002/yyyService" behaviorConfiguration="yyyEndPointBEhavior"
      binding="netTcpBinding" contract="xxx.yyy.Interfaces.Izzz">
      <identity>
      <dns value="10.0.5.187" />
      </identity>
      </endpoint>

      </client>
      <behaviors>
      <endpointBehaviors>
      <behavior name="yyyEndPointBEhavior">
      <clientCredentials>
      <clientCertificate
      findValue="xxx.yyy.Client"
      x509FindType="FindBySubjectName"
      storeLocation="LocalMachine"
      storeName="My" />
      <serviceCertificate>
      <authentication
      certificateValidationMode="ChainTrust"
      revocationMode="NoCheck" />
      </serviceCertificate>
      </clientCredentials>
      </behavior>
      </endpointBehaviors>
      </behaviors>
      </system.serviceModel>
      <startup>
      <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.5.2"/>
      </startup>

      </configuration>


      when start establishing the connection I got the following error



      It is likely that certificate 'OU=xxx.yyy.Client, C=cc' may not have a private key that is capable of key exchange or the process may not have access rights for the private key. Please see inner exception for detail.



      Invalid provider type specified.



      Any idea how to solve that?







      wcf certificate nettcpbinding






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 16 '18 at 0:44









      AliAli

      92852346




      92852346






















          0






          active

          oldest

          votes











          Your Answer






          StackExchange.ifUsing("editor", function ()
          StackExchange.using("externalEditor", function ()
          StackExchange.using("snippets", function ()
          StackExchange.snippets.init();
          );
          );
          , "code-snippets");

          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "1"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );













          draft saved

          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53329853%2fwcf-and-nettcp-security-with-certificate%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown

























          0






          active

          oldest

          votes








          0






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes















          draft saved

          draft discarded
















































          Thanks for contributing an answer to Stack Overflow!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid


          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.

          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53329853%2fwcf-and-nettcp-security-with-certificate%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          Top Tejano songwriter Luis Silva dead of heart attack at 64

          ReactJS Fetched API data displays live - need Data displayed static

          Evgeni Malkin