Re: IPSec policies with Kerberos only??

From: Herb Martin (news_at_LearnQuick.com)
Date: 07/01/04


Date: Thu, 1 Jul 2004 07:51:11 -0500


"Spin" <Spin@spin.com> wrote in message news:2kh9o3F2c78qU1@uni-berlin.de...
> That's what I thought. Thanks for confirming.
>
> "Simon Geary" <simon_geary@hotmail.com> wrote in message
> news:%23iYIhdvXEHA.1652@TK2MSFTNGP09.phx.gbl...
> > Yes, by just using Kerberos you can run IPSec without getting your hands
> > dirty with keys or certificates. It makes it a breeze to set up and is
> > recommended if you have a small network.

Same domain (or trust relationship actually).

Kerberos won't work for "foreign" domain machines otherwise.

Certificates are largely for machines that aren't in the same domain/forest
or which cannot join due to being "routers" or some such.

-- 
Herb Martin
> >
> > "Spin" <Spin@spin.com> wrote in message
> news:2kgtdbF2896sU1@uni-berlin.de...
> > > Gurus,
> > >
> > > I have been studying Windows Server 2003.  Regarding IPSec policies,
if
> > one
> > > does not want to use a pre-shared key (least secure), and does not
have
> > > Certificate Server, can one still implement IPSec policies with just
> > > straight-up Kerberos as the default authentication method?
> > >
> > >
> >
> >
> >
>
>


Relevant Pages

  • RE: Between Forest IPSec Implementation?
    ... Using Windows 2000, your design should work fine with Certificates and CA's, ... As far as using a CA, you can setup your IPSec policies in each forest to ... Kerberos cross-forest auth will not work in 2000. ... Subject: Between Forest IPSec Implementation? ...
    (Focus-Microsoft)
  • Re: Should I install Certificate Authority to solve these problems ?
    ... there are multiple considerations for IPsec. ... "trust" is defined as the ability to authenticate with IKE; ... constrain the use of certificates for IPsec authN to ... > base it on Kerberos you pretty much limit hard binding ...
    (microsoft.public.win2000.security)
  • Re: IPSec policies with Kerberos only??
    ... by just using Kerberos you can run IPSec without getting your hands ... Kerberos won't work for "foreign" domain machines otherwise. ... Certificates are largely for machines that aren't in the same domain/forest ...
    (microsoft.public.windows.server.active_directory)
  • Re: IPSec policies with Kerberos only??
    ... by just using Kerberos you can run IPSec without getting your hands ... dirty with keys or certificates. ...
    (microsoft.public.windows.server.general)
  • Re: IPSec policies with Kerberos only??
    ... by just using Kerberos you can run IPSec without getting your hands ... dirty with keys or certificates. ...
    (microsoft.public.windows.server.active_directory)