Hello @Bruce Zhang-MSFT ,
Thans for your answer
In applicationhost.config i have this:
<site name="FTPS" id="2">
<application path="/">
<virtualDirectory path="/" physicalPath="C:\inetpub\ftproot\myftp" />
</application>
<bindings>
<binding protocol="ftp" bindingInformation="192.168.1.10:21:" />
</bindings>
<ftpServer>
<security>
<ssl serverCertHash="C657EE78425790D20E4B5E1548C636A374A0CE00" serverCertStoreName="My" ssl128="false" controlChannelPolicy="SslRequire" dataChannelPolicy="SslRequire" />
<authentication>
<basicAuthentication enabled="true" />
<anonymousAuthentication enabled="false" />
</authentication>
<sslClientCertificates clientCertificatePolicy="CertRequire" useActiveDirectoryMapping="false" />
</security>
</ftpServer>
</site>
<location path="FTPS">
<system.ftpServer>
<security>
<authorization>
<add accessType="Allow" roles="ftpgroup" permissions="Read, Write" />
</authorization>
</security>
</system.ftpServer>
<system.webServer>
<security>
<authentication>
<iisClientCertificateMappingAuthentication enabled="true" manyToOneCertificateMappingsEnabled="true">
<oneToOneMappings>
<add userName="ftp01" password="[enc:IISCngProvider:gDmQuTLUM/AqQ3lk1DwBSzN3zwTTHdTSJ32fNAFtxEMZiedXFWCuA+aH/TOsyaT/+FXt+Jv/s5unKE4qbFlKiHILh+ulAc29/uZ/jQfG+TQ=:enc]" certificate="cert here in PEM format without --BEGIN-- ---END---" />
</oneToOneMappings>
</iisClientCertificateMappingAuthentication>
</authentication>
</security>
</system.webServer>
</location>
I check the logs when user get connected and there is no line concerning onetone certificate mapping
Software: Microsoft Internet Information Services 10.0
Version: 1.0
Date: 2022-01-18 09:42:40
Fields: date time c-ip cs-username s-ip s-port cs-method cs-uri-stem sc-status sc-win32-status sc-substatus x-session x-fullpath
2022-01-18 09:42:40 192.168.25.129 - 192.168.25.10 21 ControlChannelOpened - - 0 0 69b04f17-6407-4dfb-afdc-6e3a73e093c0 -
2022-01-18 09:42:40 192.168.25.129 - 192.168.25.10 21 AUTH TLS 234 0 0 69b04f17-6407-4dfb-afdc-6e3a73e093c0 -
2022-01-18 09:43:01 192.168.25.129 - 192.168.25.10 21 ControlChannelClosed - - 0 0 69b04f17-6407-4dfb-afdc-6e3a73e093c0 -
2022-01-18 09:43:13 192.168.25.129 - 192.168.25.10 21 ControlChannelOpened - - 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:13 192.168.25.129 - 192.168.25.10 21 AUTH TLS 234 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 - 192.168.25.10 21 USER ftp01 331 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 PASS *** 230 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 /
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 SYST - 215 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 FEAT - 211 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 OPTS UTF8+ON 200 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 PBSZ 0 200 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 PROT P 200 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 PWD - 257 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 CWD /bin 250 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 /bin
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 PWD - 257 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 TYPE A 200 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 PASV - 227 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 49807 DataChannelOpened - - 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 49807 DataChannelClosed - - 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 LIST -a 226 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 /bin
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 PWD - 257 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 CWD /bin/FileZilla_3.57.0_win64_sponsored-setup.exe 550 123 3 c52c44d2-a956-4a4f-b26c-051ab3c7c092 /bin/FileZilla_3.57.0_win64_sponsored-setup.exe
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 TYPE I 200 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 -
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 SIZE /bin/FileZilla_3.57.0_win64_sponsored-setup.exe 213 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 /bin/FileZilla_3.57.0_win64_sponsored-setup.exe
2022-01-18 09:43:14 192.168.25.129 DESKTOP-I6K65KR\ftp01 192.168.25.10 21 MDTM /bin/FileZilla_3.57.0_win64_sponsored-setup.exe 213 0 0 c52c44d2-a956-4a4f-b26c-051ab3c7c092 /bin/FileZilla_3.57.0_win64_sponsored-setup.exe
Sincerilly
Osvaldo