VPN Client and Machine Certificates for Unattanded VPN access

VPN Client and Machine Certificates for Unattanded VPN access

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
VPN Client and Machine Certificates for Unattanded VPN access Mike Lanham-Hat 09-11-2007
Posted by =?Utf-8?B?TWlrZSBMYW5oYW0tSGF0 on September 11, 2007, 11:28 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi There,

I am looking for information on if it is possbile to get the MS VPN Client
to use digital authentication certificates issued into the machine
certificate store for establishing an IPsec VPN? I have a number of XP
workstations acting as information kiosks that will require secure access to
a network with no user intervention. I want to know if it is also posible to
get XP to establish this VPN at boot time rather than have a user start this
manually??

Any help would be great.

Mike

Posted by Brian Komar on September 11, 2007, 4:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
You need to understand how the MS VPN client works. If you are planning on
using IPSec, the client uses L2TP over IPSec, not pure IPSec.
This means that the machine store is read for the IPSec authentication
certificate. For the actual user authenticatoin of the VPN, the certificate
must be in the user's store. Thus, you could not have the VPN launched
automatically using a machine assigned certificate. The user would have to
log on to do this or provide credential/certificate to do this

Brian

> Hi There,
>
> I am looking for information on if it is possbile to get the MS VPN Client
> to use digital authentication certificates issued into the machine
> certificate store for establishing an IPsec VPN? I have a number of XP
> workstations acting as information kiosks that will require secure access
> to
> a network with no user intervention. I want to know if it is also posible
> to
> get XP to establish this VPN at boot time rather than have a user start
> this
> manually??
>
> Any help would be great.
>
> Mike


Similar ThreadsPosted
Acceptability Of Self-Sign SSL And Client Certificates June 27, 2007, 9:18 pm
Access to local machine store June 2, 2008, 4:08 am
getting IPSec Certificates for VPN access for non domain members January 4, 2007, 11:02 am
How to protect web files from direct access by client in windows 2 September 5, 2005, 5:28 am
Client Wireless Set To PEAP But Need Access To Public AP's Also February 21, 2007, 10:48 am
WHY SOME MACHINE HAVE SP2 AND HAVE POLICY WSUS November 29, 2005, 4:05 pm
Security within Virtual Machine December 5, 2005, 6:16 am
Machine and User credentials October 9, 2006, 5:10 pm
Java Virtual Machine October 17, 2006, 4:19 pm
XP can't install secuirty updates on my machine June 22, 2005, 1:04 pm

The site map in XML format XML site map

Contact Us | Privacy Policy