要注意的一点是,application pool的identity是ApplicationPoolIdentity,如果是customize的账号或network service则重复以上过程添加它们到permission中即可。
http://stackoverflow.com/questions/2609859/how-to-give-asp-net-access-to-a-private-key-in-a-certificate-in-the-certificate
http://serverfault.com/questions/131046/how-to-grant-iis-7-5-access-to-a-certificate-in-certificate-store