AnsweredAssumed Answered

Mutual certificate exchange with REST web service calls

Question asked by baltner on Nov 7, 2018

Greetings:

 

I am trying to connect to a REST API via Nintex workflow (Web Request action).  I got it working in Google Postman but to do so I had to load two certificates in the Postman certificate store (.pem file and .key file).  This is because the API leverages a mutual certificate exchange over SSL model, where certificates are exchanged in both directions so that the client is sure that the server is who it says it is and the server is sure that the client is who he/she says he/she is.

 

How do you do this in the SharePoint environment?  Without doing this properly I get an SSL error in my workflow that is identical to the error I get in Postman if I remove the certificates I loaded there.

 

See https://www.nevatech.com/blog/post/What-you-need-to-know-about-securing-APIs-with-mutual-certificates for a discussion of mutual certificate exchange for REST Web services.

 

Thanks,

Bruce

Outcomes