Access to network shares

Access to network shares

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Access to network shares Marianna 01-25-2007
Posted by Marianna on January 25, 2007, 5:13 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,
is it possible to use the certificate, created from my CA (generated on
Windows 2003 Server Enterprise - CA Standalone or CA integrated with AD), to
access to network shares so that I am sure that the pc connected is really
that pc ?
And I can disable the possibility that anyone, knowing the user credential,
with a pc not authorized, can to be connect to network shares ?
I cannot use the smart card for now and, configuring the network to use
IPsec and certificate, is very very slow the access to the network shares.

That one I ask, is it possible?
If yes, there is any documentation?

Thanks
Marianna



Posted by Roger Abell [MVP] on January 25, 2007, 6:31 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Have you tried IPsec based on Kerberos instead of certs,
and are you sure whether the slowing you mention is due
to having defined encryption of the entire packet to happen
instead of only enforcing a secure IPsec asssociation for
the traffic? At this time, using IPsec is the industry defined
way to ascertain the endpoints in a network exchange.

> Hi,
> is it possible to use the certificate, created from my CA (generated on
> Windows 2003 Server Enterprise - CA Standalone or CA integrated with AD),
> to access to network shares so that I am sure that the pc connected is
> really that pc ?
> And I can disable the possibility that anyone, knowing the user
> credential, with a pc not authorized, can to be connect to network shares
> ?
> I cannot use the smart card for now and, configuring the network to use
> IPsec and certificate, is very very slow the access to the network shares.
>
> That one I ask, is it possible?
> If yes, there is any documentation?
>
> Thanks
> Marianna
>



Posted by Marianna on January 25, 2007, 6:59 am
If you were  Registered and logged in, you could reply and use other advanced thread options
It's slow also ipsec with kerberos.
The server and the client is on test environment on Vmware GSX Server
connected on wireless network.
Probably my conf is wrong...
The parameter of security option doesn't help me?
Can I set the parameters of network access that helps me? What?
Thanks
Marianna

> Have you tried IPsec based on Kerberos instead of certs,
> and are you sure whether the slowing you mention is due
> to having defined encryption of the entire packet to happen
> instead of only enforcing a secure IPsec asssociation for
> the traffic? At this time, using IPsec is the industry defined
> way to ascertain the endpoints in a network exchange.
>
>> Hi,
>> is it possible to use the certificate, created from my CA (generated on
>> Windows 2003 Server Enterprise - CA Standalone or CA integrated with AD),
>> to access to network shares so that I am sure that the pc connected is
>> really that pc ?
>> And I can disable the possibility that anyone, knowing the user
>> credential, with a pc not authorized, can to be connect to network shares
>> ?
>> I cannot use the smart card for now and, configuring the network to use
>> IPsec and certificate, is very very slow the access to the network
>> shares.
>>
>> That one I ask, is it possible?
>> If yes, there is any documentation?
>>
>> Thanks
>> Marianna
>>
>
>



Posted by Roger Abell [MVP] on January 25, 2007, 10:35 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Present generation access control on shares within Windows
is based on the account that is accessing, not the machine from
which the access originates.
You mentioned cert vs kerberos, but not whether you are
sure you are not forcing encryption of entire packet content,
which could be part of a slowing.

> It's slow also ipsec with kerberos.
> The server and the client is on test environment on Vmware GSX Server
> connected on wireless network.
> Probably my conf is wrong...
> The parameter of security option doesn't help me?
> Can I set the parameters of network access that helps me? What?
> Thanks
> Marianna
>
>> Have you tried IPsec based on Kerberos instead of certs,
>> and are you sure whether the slowing you mention is due
>> to having defined encryption of the entire packet to happen
>> instead of only enforcing a secure IPsec asssociation for
>> the traffic? At this time, using IPsec is the industry defined
>> way to ascertain the endpoints in a network exchange.
>>
>>> Hi,
>>> is it possible to use the certificate, created from my CA (generated on
>>> Windows 2003 Server Enterprise - CA Standalone or CA integrated with
>>> AD), to access to network shares so that I am sure that the pc connected
>>> is really that pc ?
>>> And I can disable the possibility that anyone, knowing the user
>>> credential, with a pc not authorized, can to be connect to network
>>> shares ?
>>> I cannot use the smart card for now and, configuring the network to use
>>> IPsec and certificate, is very very slow the access to the network
>>> shares.
>>>
>>> That one I ask, is it possible?
>>> If yes, there is any documentation?
>>>
>>> Thanks
>>> Marianna
>>>
>>
>>
>
>



Similar ThreadsPosted
Read Only Access to ALL Shares On a Network December 12, 2005, 3:34 pm
Question on - Network Access: Do not allow anonymous enumeration of SAM accounts and shares April 3, 2008, 9:48 am
Tightening down shares on a network?? October 13, 2005, 2:02 pm
Blank password allowed for network shares? October 3, 2008, 11:02 am
Open Access to Shares June 7, 2008, 6:22 pm
Access to Shares by Right Click on the Start menu June 18, 2008, 10:29 am
Workgroup clients can access domain shares July 10, 2008, 12:14 pm
Why can domain users access to admin shares on my servers? June 25, 2008, 8:46 am
Shares, Named Pipes, and Registry for Anonymous Remote Access February 23, 2007, 2:24 am
Internal Network Access Thru VPN October 18, 2005, 11:57 am

The site map in XML format XML site map

Contact Us | Privacy Policy