Certificate authentication with PKI

View on GitHub

Access secured portals using a certificate.

Image of certificate authentication with PKI

Use case

PKI (Public Key Infrastructure) is a certificate authentication method to secure resources without requiring users to remember passwords. Government agencies commonly issue smart cards using PKI to access computer systems.

How to use the sample

NOTE: You must provide your own ArcGIS Portal with PKI authentication configured.

Provide a URL to a PKI-enabled server, then use the certificate selection UI to select an appropriate certificate for that server.

How it works - Windows WPF

  1. Create the X.509 certificate store, referring to the user's certificates.
  2. Open the certificate store in read-only mode.
  3. Find all certificates that are currently valid.
  4. Display the Windows certificate selection UI to choose from the returned certificates.
  5. Create the ArcGIS Runtime credential with the chosen certificate.
  6. Create the Portal, explicitly passing in the credential that was created.

Relevant API

  • CertificateCredential

Additional information

ArcGIS Enterprise requires special configuration to enable support for PKI. See Using Windows Active Directory and PKI to secure access to your portal and Use LDAP and PKI to secure access to your portal in Portal for ArcGIS.


authentication, certificate, login, passwordless, PKI, smartcard, store, X509

Sample Code

        <DataTemplate x:DataType="x509certificates:X509Certificate2" x:Key="CertificateTemplate">
                    <ColumnDefinition Width="Auto" />
                    <ColumnDefinition Width="*" />
                    <RowDefinition Height="Auto" />
                    <RowDefinition Height="Auto" />
                    <RowDefinition Height="Auto" />
                <TextBlock Text="User:"
                           Grid.Row="0" Grid.Column="0"/>
                <TextBlock Text="Issuer:"
                           Grid.Row="1" Grid.Column="0"/>
                <TextBlock Text="Valid until:"
                           Grid.Row="2" Grid.Column="0"/>
                <TextBlock Text="{Binding Subject}"
                           Grid.Row="0" Grid.Column="1"/>
                <TextBlock Text="{Binding Issuer}"
                           Grid.Row="1" Grid.Column="1"/>
                <TextBlock Text="{Binding NotAfter}"
                           Grid.Row="2" Grid.Column="1"/>
        <Grid HorizontalAlignment="Center" VerticalAlignment="Center">
                <RowDefinition Height="Auto" />
                <RowDefinition Height="Auto" />
                <RowDefinition Height="Auto" />
                <RowDefinition Height="Auto" />
                <ColumnDefinition Width="Auto" />
                <ColumnDefinition Width="150" />
            <TextBlock Text="Enter the URL to a portal that you have a certificate for:"
                       Grid.Row="0" Grid.Column="0" Grid.ColumnSpan="2"/>
            <TextBox x:Name="PortalUrlTextbox"
                     Grid.Row="1" Grid.Column="0" Grid.ColumnSpan="2" Margin="0,10" MinWidth="300" />
            <Button Content="Choose a certificate"
                    Grid.Row="2" Grid.Column="0" Grid.ColumnSpan="2"
                    Click="Button_Click" />
            <TextBlock Text="User: "
                       Grid.Row="3" Grid.Column="0"/>
            <TextBlock x:Name="LoggedInUsername"
                       Grid.Row="3" Grid.Column="1"
                       Text="Not logged in" />