Re: IPSec & Kerberos

From: Steven L Umbach (n9rou_at_N0sPaM-comcast.net)
Date: 09/27/04


Date: Mon, 27 Sep 2004 03:07:18 GMT

There are three authentication methods for ipsec - kerberos [default ],
certificate, or preshared key. They are all forms of authentication. A
certificate is not required for authentication. Key use is not exclusive to
a key exchange. It is however the most secure method of authentication of
authentication outside of a domain for ipsec. In the initial authentication
a computers public key is used to encrypt the keys in the challenge sent to
the other computer when a certificate is used. If preshared keys are used
then the challenge is encrypted with a hash created from the pre shared
ey. --- Steve

"myrt webb" <anonymous@discussions.microsoft.com> wrote in message
news:274601c4a437$d7d3e040$a301280a@phx.gbl...
> I do not understand the relationship between Kerberos and
> IPSec when encypting communications in a domain.
>
> If you turn on Secure Server on a server all commo is
> IPSec encrypted in the domain from that server without
> the use of a Certificate Authority. According to what I
> have read Kerberos takes care of the key exchange so the
> SA can be established. Does Kerberos construct a
> certificate or is some other method used.



Relevant Pages

  • Re: ACL login security access
    ... I am already using IPSec with Kerberos authentification on my Domain network ... Kerberos even from a Workgroup machine, just by opening a Windows Explorer ... > traffic that involves authentication and Active Directory with domain ...
    (microsoft.public.windows.server.security)
  • Re: secure server policy
    ... Authentication data to DC is already protected using Kerberos protocol (by ... >> Be very careful with ipsec policies. ...
    (microsoft.public.win2000.security)
  • Is it possible to require both a certificate and a Kerberos password for authentication?
    ... My problem is that I don't trust my users to validate the server certificate - I know that ignorant muppets will accept a man in the middle attack without any worries as long as it gives them access to our network. ... But I don't want to rely entirely upon the certificate, because I don't trust the users to look after it and don't want the users to have to remember both a certificate passphrase and their kerberos password. ... What I want is to require two different methods of authentication. ...
    (comp.security.ssh)
  • Re: Is it possible to require both a certificate and a Kerberos password for authentication?
    ... Authentication is username & password via kerberos. ... My problem is that I don't trust my users to validate the server ... So I'd like to refuse access to clients that do not provide a certificate.. ... What I want is to require two different methods of authentication. ...
    (comp.security.ssh)
  • Re: IPSec and CAs
    ... 547 and end up making an un-secured connection. ... "IKE failed to find valid machine certificate". ... > Ipsec would use mutual machine authentication to set up a security ... > setting up with preshared key for ipsec authentication to test everything ...
    (microsoft.public.win2000.security)