Re: CALG_SSL3_SHAMD5 support for ClientAuthentication

From: John Banes (jabanes_at_comcast.remove.net)
Date: 10/27/05


Date: Thu, 27 Oct 2005 14:24:14 -0700

There should be no connection.

If all you want is to use your CSP for client authentication, then the CSP
type should be PROV_RSA_FULL. It should NOT be set as the default CSP, and
so it will be used for nothing other than the client auth signature
operation. The SSL implementation knows to use your CSP because it's the one
that's associated with the client certificate.

Regards,
John

<viveque.kumar@gmail.com> wrote in message
news:1130327077.206313.172730@g47g2000cwa.googlegroups.com...
> No DER header and type1 padding worked,.. Thanks a ton for your
> suggestion.
>
> Is there some link between this algorithm and 128-bit encryption? If I
> specify
> "Requires 128-bit encryption" in IIS settings, it fails but no error
> reported from CSP.
> If I un-check the 128-bit requirement, everything works fine.
>



Relevant Pages

  • help! how to use my csp to access ssl site!
    ... I write my own csp wrap the basic functions provided by MS_ENHANCED_PROV. ... It can't access ssl sit from a client machine. ...
    (microsoft.public.platformsdk.security)
  • clarification in PIN caching & usb token
    ... I read from "The Smart Card Cryptographic Service Provider Cookbook" ... by Microsoft that the PIN is stored within the CSP. ... Is this the method used by most usb tokens ... server and a client. ...
    (comp.security.misc)
  • Re: About schannel and CSP
    ... schannel will use whatever CSP that's used to store the ... server private key for all SSL-related crypto. ... the client auth signature operation ...
    (microsoft.public.platformsdk.security)
  • Re: Smart Card Logon Kerberos error
    ... > We have probe a csp based in smart card logon with a third party ... > CA,the client show a message about the "System couldnīt verify the ...
    (microsoft.public.platformsdk.security)
  • WPA EAP-TLS
    ... General questions on WPA and IAS authentication of a WPA EAP-TLS client with ... non-Microsoft WPA client where the client has embedded within it an X.509 ... The embedded certificate would NOT have user identifying ... I believe the first thing I would need is a CSP that is an RSA Schannel CSP. ...
    (microsoft.public.internet.radius)