ipsec w/certificates

From: dan (anonymous_at_discussions.microsoft.com)
Date: 06/08/04


Date: Tue, 8 Jun 2004 09:16:03 -0700

What I'm trying to do: Create an IPSEC trust in transport mode, using certificates as the mode of authentication. I'm attempting to do this on a LAN between two hosts. NAT is not an issue.

What I've done:
- Successfully created the trust using a preshared secret (password) just to make sure that IPSEC was working. (note: this was just a test step, I am going to disable the preshared pw because I want to use certs)
- Used openssl to generate a CA (I used the canned CA.sh script)
- Generated certificates for the two hosts.
- Imported the CA certificate to each host.
- Imported the respective cert to each host.
- Changed the authentication mode to certificates.
- Assigned the ipsec policies.

when I ping, it shows that the nodes are negotiating but never connect (this was working in pw mode). Nor can I use any of the services between the host (http, ftp, etc. -- also working in pw moded).

What could I be forgetting/missing? Also, I can't seem to locate any obvious errors in the event logs --- is there another place I can look for info?

Thanks,
Dan



Relevant Pages

  • Re: IPSEC wireless router ?
    ... > The main advantage of IPSec is the Sec part, ... digital certificates issued by these organizations called certification ... SSL implementation at the time was one-way authentication between the ... supporting digital signature authentication ... ...
    (alt.internet.wireless)
  • Re: VPN client for linux without compiling kernel
    ... A 2.6 kernel have IPsec in by default. ... We use machine-based certificates for authentication. ...
    (comp.os.linux.networking)
  • Re: PEAP-TLS vs EAP-TLS
    ... MSCHAPV2 will not be used and then maybe that would be PEAP-TLS. ... select authentication method there are two choices - secured password ... certificates for both server authentication and client authentication; ... I think this means that there's a PEAP-TLS that's separate from EAP-TLS ...
    (microsoft.public.windows.server.security)
  • Re: public key vs passwd authentication?
    ... note that in the generic description of 3-factor authentication, ... certification authorities, and/or certificates ... considered a totally orthogonal business issue. ... possible to deploy a digital signature based two-factor authentication ...
    (comp.security.ssh)
  • RE: IAS server blues (Cant get 802.1x to work)
    ... clients. ... and it appears that the certificates are deploying correctly. ... Proxy-Policy-Name = Use Windows authentication for all users ... IAS Log Sample ...
    (microsoft.public.windows.server.general)