PC Review


Reply
Thread Tools Rate Thread

Certificate Services for VPN Access

 
 
Richard
Guest
Posts: n/a
 
      14th Jul 2003
I have setup a RRAS VPN server and it works for PPTP
connections. I setup Certificate Services for L2TP
connections. I have issued certificate for the server
and the remote user. I get errors that state the client
does not have a valid certificate and also that the
server certificate is invalid as well. I used the MS
white papers to alter the connection to use a shared
secret for L2TP and that works. For some reason the
certificates will not. My CA is an Enterprise Root and I
have checked to make sure that it is in the Cert
Publishers security group and that it is listed in
Directory Services as a CA.

Any ideas?

-Richard
 
Reply With Quote
 
 
 
 
Vadxov
Guest
Posts: n/a
 
      15th Jul 2003

It sounds like you're trying to accomplish client
authentication... yes? Remember, there a 4 methods of
authenticating the client - anonymous, basic, NT challange-
response, and SSL.
Anonymous - all clients are simply considered
authenticated.
Basic - users attempting to gain access to the resources
enter their username/pwd in the dialog box rendered by the
browser.
NT challange-response - authentication without requiring
actual passwords being transmitted across the network -
the browser uses cryptography to "prove its knowledge" of
the current users login/pwd.
SSL - based on public-key cryptography in which the users
client certificate is used to verify identity. BINGO!

Authentication takes place when the users private key
information is presented for authentication against the
public key information stored on the server... Do you
have the users key information installed on the server and
does the session know where to find them?

Also the advantage of this method is that you do not need
to setup individual accounts for each user attempting
access - multiple certificates can be mapped to one
account. Check account association also.

Hope this helps...


>-----Original Message-----
>I have setup a RRAS VPN server and it works for PPTP
>connections. I setup Certificate Services for L2TP
>connections. I have issued certificate for the server
>and the remote user. I get errors that state the client
>does not have a valid certificate and also that the
>server certificate is invalid as well. I used the MS
>white papers to alter the connection to use a shared
>secret for L2TP and that works. For some reason the
>certificates will not. My CA is an Enterprise Root and I
>have checked to make sure that it is in the Cert
>Publishers security group and that it is listed in
>Directory Services as a CA.
>
>Any ideas?
>
>-Richard
>.
>

 
Reply With Quote
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Certificate Services Web Enrollment requires admin access Steve March Microsoft Windows 2000 1 1st Jul 2004 02:37 AM
Certificate Services Web Enrollment requires admin access Steve March Microsoft Windows 2000 Security 1 1st Jul 2004 02:37 AM
Web Certificate Services - Error 0x80090016 on certificate install for IPsec [WORKAROUND INSIDE!] Todd Day Windows XP Networking 1 11th May 2004 01:34 PM
MS Certificate services - CA root certificate has expired Microsoft Windows 2000 0 28th Jan 2004 07:55 PM
Certificate for signing VBA projects using Windows 2000 Certificate Services Tim Dreyling Microsoft Access Security 0 14th Jan 2004 08:37 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 10:22 PM.