Re: two CA certificates for IPSec or something...

From: Ondrej Sevecek (ondra)
Date: 09/18/05

  • Next message: Miha Pihler [MVP]: "Re: Certificate Service"
    Date: Sun, 18 Sep 2005 10:57:15 +0200
    
    

    I cannot imagine one. I would like the isolation to occure on another bases
    than IP, so I think, the authentication is the only solution.
    Installation of subordinate CA would require strict security on the machine,
    so we probably will install standalone subordinate on a separate server that
    will be used to only this purpose.

    O.

    "Brian Komar [MVP]" <bkomar@nospam.identit.ca> wrote in message
    news:MPG.1d964a45fbd29c0d989698@msnews.microsoft.com...
    > In article <e5oRO35uFHA.1560@TK2MSFTNGP09.phx.gbl>, "Ondrej Sevecek"
    > <ondra at my_surname dot com> says...
    >> > You could use two certificate templates to accomplish this, but if you
    >> > are applying different IPSec filters, the authentication can only
    >> > indicate *which* root CA the chain is rooted.
    >>
    >> .... and when I would use two templates, how to distinguish them in the
    >> filter rules?
    >>
    >>
    >> O.
    >>
    >>
    >>
    >>
    > This is the issue, the certificate templates would still chain to CAs
    > that chain to the same root.
    > Is there any other criteria that you could use, other than the
    > authentication to isolate?
    > Brian


  • Next message: Miha Pihler [MVP]: "Re: Certificate Service"

    Relevant Pages

    • Re: CUPS printer error for Canon BJC-250
      ... The configuration through gnome-cups-manager is finished, ... from the terminal window) I get erros like 'authentication ... failure' althought the root password is properly entered and the ... One of the nice things about GNU/Linux is that you do not need to reboot the PC after an installation or configuration change. ...
      (Debian-User)
    • Re: Crystal Enterprise 8 standard config questions
      ... On the server where IIS is installed, go to 'Program Files', ... 'Administrative Tools', 'Internet Services Manager'. ... the box at the bottom for 'integrated windows authentication'. ... >> installation because I didn't have "NT Challenge/Response" turned off in ...
      (microsoft.public.vb.crystal)
    • Microsoft UAM not kicking in with Mac OS 10.2.8
      ... The installation ... the native OS X SMB authentication dialog (i.e., the Microsoft UAM is NOT ...
      (microsoft.public.macintosh.general)
    • Microsoft UAM not kicking in with Mac OS 10.2.8
      ... The installation ... the native OS X SMB authentication dialog (i.e., the Microsoft UAM is NOT ...
      (microsoft.public.win2000.macintosh)
    • Re: IIS permissions
      ... the antivirus installation program itself. ... When authentication is required, the ... > I am looking for an advice for Security betwen DC W2K3 and IIS installed ...
      (microsoft.public.windows.server.security)