Re: des instead of 3des

From: D. Cross [MS] (
Date: 06/03/02

From: "D. Cross [MS]" <>
Date: Mon, 3 Jun 2002 06:32:28 -0700

the certificates have nothing to do with DES/3DES. Symmetric algorithm
information is not contained within the x.509 certificate issued by the MSFT

I think you are referring to the VPN software itself - in that case 3DES is
only supported by Windows XP clients (has nothing to do with the CA you are
using). You can use 3DES with IPSEC in Windows XP, by turning it on through
group policy.

David B. Cross [MS]
This posting is provided "AS IS" with no warranties, and confers no rights.
"Luschinsky Vyacheslav" <> wrote in message
> I don't need strong protection. I just need other then password protected
> entrance to local network. VPN with certificate auth will just do.
> "David Dickinson [MVP]" <> wrote in message
> news:eV6x2ztCCHA.824@tkmsftngp05...
> > Luschinsky Vyacheslav wrote:
> > > I have w2k server sp2 and certificate services installed.
> > > certificates that are issued by it allow only 3des encription that is
> > > not supported by other side. Can I make server issue certs for des
> > > encription?
> >
> > Can you update the other side?  DES is not secure. It takes less than a
> day
> > to break it.
> >
> > --
> > David Dickinson, MVP (Security)
> > EveningStar Information Services
> > Las Cruces, NM USA
> >
> > Summary of Microsoft Security Bulletins
> >
> >
> >
> >

Relevant Pages

  • RE: updates after format
    ... if the Microsoft Server is down. ... software you are installing has not passed Windows Logo testing verify its ... When you try to download an ActiveX control, install an update to Windows ... and you do not have the appropriate certificate in your Trusted Publishers ...
  • Re: Need help configuring Wireless Connection profile
    ... and I can only use the intel OR windows utility, not both at the same time. ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
  • Re: Windows Update repeats
    ... You cannot install some updates or programs ... to a Windows component, install a service pack for Windows or for a Windows ... The Microsoft digital signature affirms that software has been tested with ... Publishers certificate store. ...
  • Re: sfc /scannow wont run
    ... or upgrade installs but I definitely know retail versions do. ... If you have Windows XP Pro installed then do not purchase a Windows XP Home ... This behavior can occur if the certificate for VeriSign time stamping ...
  • RE: Double authentication (User & Machine) with VPN SSL
    ... If you've got Windows and IIS, ... server machine using the typical IPSec policy and normal IPSec certs. ... Double authentication with VPN SSL ... - our users will soon have a certificate in a USB token; ...