I can't underestand IKE Authentication!



Hi
I have a problem when trying to understand Certificate-Authententication in
IKE.
The problem is that when we take an IPSec-certificates from CA and install
them in the Principal's-Store, it doesn't matter to what name we use for
Subject-Field.
So how it protects against Man-in-the-Middle Attack? as it is possible for
attacker to take a certificate with an optional name from the same CA and
performs a successful authentication?
In other word, what attribute (except that Subject) in the certificate
exactly determines the identification of other principal?
It is clear for me when using the Authentication Process in Kerberos or
Pre-Shared-Key but not about Certificate when no field in the certificate is
related to other principal!

Please help !
Thanks



.



Relevant Pages

  • How to install the Radius Server Cert. to PDA ?
    ... Our company are using Windows 2003 Enterprise Edition and Running Radius ... Server, and 2 notebook computers can successful authentication, via ... have try to install the certificate on it, ...
    (microsoft.public.internet.radius)
  • Re: I cant underestand IKE Authentication!
    ... I have a problem when trying to understand Certificate-Authententication in IKE. ... So how it protects against Man-in-the-Middle Attack? ... as it is possible for attacker to take a certificate with an optional name from the same CA and performs a successful authentication? ... what attribute in the certificate exactly determines the identification of other principal? ...
    (microsoft.public.windows.server.security)
  • I cant underestand IKE Authentication!
    ... The problem is that when we take an IPSec-certificates from CA and install ... So how it protects against Man-in-the-Middle Attack? ... performs a successful authentication? ... what attribute in the certificate ...
    (microsoft.public.windows.server.security)
  • Re: Windows Update repeats
    ... You cannot install some updates or programs ... to a Windows component, install a service pack for Windows or for a Windows ... The Microsoft digital signature affirms that software has been tested with ... Publishers certificate store. ...
    (microsoft.public.windowsupdate)
  • RE: updates after format
    ... if the Microsoft Server is down. ... software you are installing has not passed Windows Logo testing verify its ... When you try to download an ActiveX control, install an update to Windows ... and you do not have the appropriate certificate in your Trusted Publishers ...
    (microsoft.public.windows.mediacenter)