RE: Force Protocol Encryption - Please help!

From: Kevin McDonnell [MSFT] (kevmc_at_online.microsoft.com)
Date: 09/28/04


Date: Tue, 28 Sep 2004 19:10:44 GMT

Prev Post:
After installing the cert, I was once again able to start my SQL
server and it appears that all is well, however I am concerned about
whether or not the connections are actually being encrypted. Do my
clients need to trust the Certificate Authority that the cert was
generated on for the encryption to work? I read some Microsoft
support articles about this issue and they don't seem that clear on
this issue.

Is there anything special that needs to be done on the clients & does
anyone know of a way to verify that the connection is encrypted?

Reply:
The only way to verify that the connection is encrypted is to make a
network trace and review it.
If you enable encryption on the serverside, the clients are not required to
trust the same root authority .

Thanks,

Kevin McDonnell
Microsoft Corporation

This posting is provided AS IS with no warranties, and confers no rights.



Relevant Pages

  • RE: questions on setting up a mail server
    ... questions on setting up a mail server ... The first group does encryption of the password only. ... Sure it is simple - when ALL clients are running the same version ... of Windows, IE, and Outlook. ...
    (freebsd-questions)
  • Re: PEAP Authentication Issues
    ... > I have setup a wireless security environment using PEAP, ... > (RADIUS/IAS and MS Cert Service) with WPA on Cisco 1200 APs. ... The main issue is that you deployed a server certificate for the IAS server ... When you are plugging the clients into the Ethernet network, ...
    (microsoft.public.internet.radius)
  • Re: How to encrypt/decrypt a file
    ... I think the OP simply wants to encrypt the xml file to prevent the clients ... server. ... doing the encryption with the public key and the server decrypts with the ...
    (microsoft.public.dotnet.security)
  • Re: !@#$% Cert Server
    ... I've been able to get most clients to ... > I've installed MS Cert Server about 10 times now. ... I've added the Cert Server FQDN to my list of trusted ... > client side cert requests from the browser into which I will install the ...
    (microsoft.public.win2000.security)
  • Re: Explaination required for using RRAS / L2TP/IPSEC and certficates for VPN connection
    ... >> certificates but whenever I go into RRAS, edit profile for my policy, ... When your RRAS server has a cert that meets the minimum ... > If clients are domain members, ...
    (microsoft.public.win2000.ras_routing)