Re: I can't underestand IKE Authentication!



ArshinK,
Information at http://technet2.microsoft.com/windowsserver/en/library/47b6a8a2-c239-4264-ae23-9b220391293c1033.mspx?mfr=true might help you.

---
Gaurav Kumar
Security Consultant
http://blogs.technet.com/gauravphoenix/








"ArshinK" <ArshinK@xxxxxxxxx> wrote in message news:eFWlAAYGIHA.4880@xxxxxxxxxxxxxxxxxxxxxxx
Hi
I have a problem when trying to understand Certificate-Authententication in IKE.
The problem is that when we take an IPSec-certificates from CA and install them in the Principal's-Store, it doesn't matter to what name we use for Subject-Field.
So how it protects against Man-in-the-Middle Attack? as it is possible for attacker to take a certificate with an optional name from the same CA and performs a successful authentication?
In other word, what attribute (except that Subject) in the certificate exactly determines the identification of other principal?
It is clear for me when using the Authentication Process in Kerberos or Pre-Shared-Key but not about Certificate when no field in the certificate is related to other principal!

Please help !
Thanks



.



Relevant Pages

  • I cant underestand IKE Authentication!
    ... The problem is that when we take an IPSec-certificates from CA and install ... So how it protects against Man-in-the-Middle Attack? ... performs a successful authentication? ... what attribute in the certificate ...
    (microsoft.public.windows.server.security)
  • I cant underestand IKE Authentication!
    ... The problem is that when we take an IPSec-certificates from CA and install ... So how it protects against Man-in-the-Middle Attack? ... performs a successful authentication? ... what attribute in the certificate ...
    (microsoft.public.windows.server.security)
  • VPN using L2TP
    ... IKE security association established. ... Peer Identity: ... Certificate based Identity. ... Destination Port 0 ...
    (microsoft.public.windows.server.sbs)
  • Re: Problem with certificates/L2TP VPN
    ... I would never recommend changing to L2TP unless there was an established certificate service. ... Does the EKU extension on the client contain the 'Client Authentication Purpose' or IPSec purpose? ... On the VPN server does the EKU extension contain the Server & Client Authentication purpose? ... IKE security association negotiation failed. ...
    (microsoft.public.windows.server.networking)
  • Re: L2TP/IPSEC Connection problem to Windows 2000 Server
    ... IKE security association negotiation failed. ... Peer Identity: ... Peer Issuing Certificate Authority ... >Issuing Certificate Authority Root Certificate Authority My ...
    (microsoft.public.win2000.ras_routing)