SSPI to verify machine identity

SSPI to verify machine identity

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
SSPI to verify machine identity Prasanna Padmanabhan 01-12-2006
Posted by Prasanna Padmanabhan on January 12, 2006, 8:59 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

Is it possible to use SSPI for the server to validate the identity of a
client machine (not the user on the client machine, but rather the client
machine itself)? In oter words if a client machine claims to be
workstation@MyNtDomain.com, can the server verify, during the process of
user authentication, whether the client machine is also what it claims to be
(eg: does the client really belong to the MyNtDomain.com?)

Thanks,
Prasanna





Posted by Ondrej Sevecek on January 12, 2006, 9:46 am
If you were  Registered and logged in, you could reply and use other advanced thread options
for built-in SSPIs probably not, as what I suppose. The client machine
identity does not travel within the authentication exchange.
You would need to have your own client-server application. The server would
then require a service ticket back for the clients machine.

Normally, with kerberos in place, only the user knows what the server
identity is.
The only thing you can consult is the fact, that without windows 2003 dc you
have no choice to obtain user ticket without having valid machine ticket
that in fact authenticates the machine. But I do not think you can get this
with w2k3.



O.


> Hi,
>
> Is it possible to use SSPI for the server to validate the identity of a
> client machine (not the user on the client machine, but rather the client
> machine itself)? In oter words if a client machine claims to be
> workstation@MyNtDomain.com, can the server verify, during the process of
> user authentication, whether the client machine is also what it claims to
> be
> (eg: does the client really belong to the MyNtDomain.com?)
>
> Thanks,
> Prasanna
>
>
>
>



Similar ThreadsPosted
Firefox dialog: unable to verify the identity of ... as a trusted site October 14, 2007, 11:37 am
Bug in Kerberos SSP within SSPI?? July 28, 2005, 4:46 am
SSPI: VerifySignature(Digest) October 17, 2005, 4:52 pm
Using SPNEGO/SSPI in SMB (Extended Security) August 18, 2005, 5:56 pm
SSPI client to ldap Server - Error at last stage of n-way authentication check December 24, 2005, 1:14 am
SSPI client to ldap Server - Error at last stage of n-way authentication check December 24, 2005, 1:15 am
Identity Theft August 20, 2005, 5:51 pm
Re: Identity Theft November 15, 2005, 11:01 pm
Your Identity is Exposed October 9, 2008, 12:13 pm
Securing data to a process identity March 3, 2008, 11:01 am

The site map in XML format XML site map

Contact Us | Privacy Policy