Re: Computer Certificate Private Key



Interested.
I have set up 802.1x. I will test it tomorrow. SO i can excepted that
computer will be authenticated with 802.1x. So computer get in to private
network, but it does not authenticate to domain. But that is security birch.
Problem is that I use v1 computer template, and I don’t now, how to make
automotive request, with option, do not export private can, or make it
exportable….


"Alun Jones" wrote:

"Mr.B" <MrB@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C70A8D7E-E75E-45ED-834B-D8ADB05521CE@xxxxxxxxxxxxxxxx
By default, if i set up auto enrollment for computer certificate, i can
from
computer export private key.
What would happened, if i import these key to different computer.
If I use different computer and i tried to authenticate, to IAS, would it
exempted as valid ?

Cryptography assumes that if you have the private key, you are the
individual or computer identified as associated with that key.

However, the recipient of a signed key exchange (in this case, IAS) might
note that your computer is trying to authenticate as a computer name other
than that with which it passed NTLM authentication. In such a case, it would
almost certainly fail the authentication.

Alun.
~~~~



.



Relevant Pages

  • Re: etc/passwd file
    ... > The point is that any scheme such as this where the encrypted password is ... into a private dmz (say ssl via web, then an ssh through a secure java ... the host itself cannot be the means for authenticating itself... ... and then authenticate the user with some time of otp scheme (which gets ...
    (comp.security.unix)
  • Re: 802.1x authentication for wireless issues w/ ISA 2004
    ... The do support WPA-EAP and the radius ... authenticate the computer and this is trying to authenticate the user and not ... If you can post perhaps 10 lines from the IAS log, ... represent my IAS server or the client laptops. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN 3005 to IAS authentication failure...
    ... Call it something like "VPN Users" or similar. ... install IAS using the Add/Remove Programs icon in Control Panel. ... we can now configure the PIX firewall as a RADIUS client. ... Any user that should be allowed to authenticate on a VPN connection will ...
    (comp.dcom.sys.cisco)
  • Re: IAS server and access points
    ... I use PEAP and passwords to authenticate wireless clients. ... I get an occassional message on my IAS server that says "A RADIUS ...
    (microsoft.public.internet.radius)
  • Re: PEAP (MSCHAPV2) - Confusion over User vs. Computer Authentication
    ... > authenticate WLAN clients via Cisco 1200 APs. ... > somewhere that you could configure IAS to ENFORCE the rule ... If you deploy EAP-TLS without smart cards you can prevent non-domain member ... that the user cert that your CA issues goes only to machines that are ...
    (microsoft.public.internet.radius)