Re: Using Certificates with IPSEC

From: Scotty (Scotty_at_discussions.microsoft.com)
Date: 01/28/05


Date: Fri, 28 Jan 2005 13:51:02 -0800

What is the process of trusting other computers for IPSEC using Certificates?

"Brian Komar" wrote:

> In article <FAD1D514-2475-41A9-8081-D1C35E4B9146@microsoft.com>,
> Scotty@discussions.microsoft.com says...
> > How do you implement IPSEC using Certificates? Right now I have it set up
> > with Kerberos. Does the Client/Server have to have each others Certificate,
> > etc?
> >
> Both endpoints (computers) must have a certificate that chains to the
> same root CA, or to CAs that are trusted by the opposite endpoint.
>
> Brian
>



Relevant Pages

  • Re: IPSEC with non-domain Server
    ... Certificates are not the "most secure", rather, they are one of the 2 "more ... > authenticate computers and protect traffic integrity and confidentiality ... > Attacks on IPSec and Other Security Concerns ...
    (microsoft.public.security)
  • Re: The art of negotiation and trust in IPSEC
    ... They would need to be ipsec certificates or possibly machine certificates as ... IPSEC to confirm the validity of the Cert on the remote endpoint? ... > (or preshared key)) to authenticate/validate the enpoints of the IPSEC ...
    (microsoft.public.win2000.security)
  • Re: IPSEC wireless router ?
    ... > The main advantage of IPSec is the Sec part, ... digital certificates issued by these organizations called certification ... SSL implementation at the time was one-way authentication between the ... supporting digital signature authentication ... ...
    (alt.internet.wireless)
  • Re: Shared Certificate Store in Active Directory
    ... There is no need to store IPSEC certs in the AD for IPSEC, ... > Active Directory so you can make Certificates and their ... > Certificates rather than Kerberos? ...
    (microsoft.public.win2000.security)
  • Re: Adding the Certificate Templates to the Certification Authority
    ... > The link below for Windows 2003 WIFI has a bunch of articles. ... > to use PEAP which does not require certificates on the clients. ... > required to gain access to the WAP which can keep unauthorized computers ... >> the certificate templates to the CA, ...
    (microsoft.public.security)