Re: VPN vs SSL client side certificates

From: Volker Birk (bumens_at_dingens.org)
Date: 09/08/05

  • Next message: Volker Birk: "Re: VPN vs SSL client side certificates"
    Date: 8 Sep 2005 08:56:52 +0200
    
    

    In comp.security.misc Michael Sharman <msharman@internode.on.net> wrote:
    > To lower the risk of password compromise I'm planning to use client side
    > certificates to authenticate as well as the passwords, so that a
    > stolen/cracked password isn't enough.

    If you're authenticating the clients with certificates, authenticating the
    server with a certificate, and have an SSL connection, then I cannot see,
    why using passwords at all.

    > Is a VPN useful given that I'm using SSL in this circumstance?

    Maybe.

    > What security does IPSEC provide that SSL doesn't?

    Used in this way, tunnelling with IPSEC hides which service who is using.

    > Would the IPSEC implementation in a firewall appliance be more trust
    > worthy than Apache-SSL?

    It depends.

    F'up2here, because this is not ssh, what we're talking about.

    Yours,
    VB.

    -- 
    "Es kann nicht sein, dass die Frustrierten in Rom bestimmen, was in
    deutschen Schlafzimmern passiert".
                                        Harald Schmidt zum "Weltjugendtag"
    

  • Next message: Volker Birk: "Re: VPN vs SSL client side certificates"

    Relevant Pages

    • Re: VPN vs SSL client side certificates
      ... >> If you're authenticating the clients with certificates, ... Roles can be authenticated with certificates also. ... compromizing the client machine is enough ...
      (comp.security.misc)
    • Re: VPN vs SSL client side certificates
      ... > To lower the risk of password compromise I'm planning to use client side ... If you're authenticating the clients with certificates, ...
      (comp.security.ssh)
    • Re: VPN vs SSL client side certificates
      ... > If you're authenticating the clients with certificates, ... > why using passwords at all. ... The authorised client machine is likely to be in a office environment ...
      (comp.security.misc)
    • Re: WSE 3.0 CertSrv Request
      ... ASP.NET Development Server caching info like IIS would if it were running ... Client OutputTrace looks clean. ... X509 security use our in house Cert Authority with teh CertSrv wizard. ... I have not found any good documentation on what type of certificates ...
      (microsoft.public.dotnet.framework.webservices.enhancements)
    • On Open Source
      ... server certificate against root certificates when used for client side ... likely to be secure than non-standard or closed source software. ... Client side authentication of the remote host identity is THE ... security service you would normally use SSL/TLS for. ...
      (sci.crypt)

  • Quantcast