revoking ipsec certificate doesn't work

From: Franz Schenk (franz.schenkNOSPAM_at_fititNO-_SPAM.ch)
Date: 09/15/05


Date: Thu, 15 Sep 2005 16:01:41 +0200

imagine the following scenario:

- have a Windows 2003 SP1 VPN Server with standalone or enterprise
certification authority, allowing only L2TP/IPSec connections with
certificate based authentication.
- have an external company that has a computer with an installed computer
IPSec certificate from our CA for VPN access.
- The external company has knowledge of several user accounts/password that
have VPN dial in permissions to our VPN server.

- Need to disable VPN access for this external company as fast as possible.
But it's not possible to change all these user accounts/passwords.

Thought that this one is easy: Go to the certification authority, revoke the
certificate that was issued to the computer of the external company, then
manually publish the CRL and delta CRL.

Have tested this scenario, doesn't work at all. The computer from the
external company still has the IPSec certificate after several hours and
several reboots, and is able to connect to the VPN server.

Any advice, aolutions, suggestions?
Thank you all in advance for your help!
Franz



Relevant Pages

  • Re: VPN L2TP [Error 786: The L2TP connection failed bec...]
    ... First off L2TP will not work over regular NAT. ... The other concern is that both the VPN server and the client need computer ... certificates in there certificate store personal folder for computers. ...
    (microsoft.public.windows.server.networking)
  • Re: Prevent logon without certificate
    ... You can not on a normal network. ... Ipsec with a require policy can prevent such access to non ... certificate authentication is used for the ipsec. ... access through that VPN server to any computer without a computer ...
    (microsoft.public.windows.server.security)
  • error 786: L2tp/ipsec VPN server
    ... windows 2000 active directory domain. ... In that domain is the server called VPN with windows 2003 standard edition ... Certificate server, VPN server, institutions on ...
    (microsoft.public.isa.vpn)
  • L2TP/IPSec using OpenSSL generated machine certificate
    ... I am running a multihomed Windows2000 server as a VPN server. ... issued a certificate from our Windows2000-based certificate server ... I implemented an openssl CA on Linux (called linuxCA). ... certificate to be 'server authentication and 'client authentication'. ...
    (microsoft.public.win2000.networking)
  • vpn access
    ... messages on my vpn server: ... 9C86C0F2D4DD} with the Router Manager for the IP protocol. ... A certificate could not be found. ... L2TP protocol over IPSec require the installation of a ...
    (microsoft.public.win2000.networking)

Loading