Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

November 07, 2003 12:00 AM

Certificate Authentication

Windows IT Pro
InstantDoc ID #40598
Rating: (0)

A Microsoft Internet Security and Acceleration (ISA) Server 2000 VPN operating over the Internet requires X.509 server certificates for authentication. You need a certificate for each ISA Server and client. To establish a VPN, participants must trust the root Certificate Authority (CA) or CAs that issue the certificates.

If all endpoints are members of the same domain, consider installing Microsoft Certificate Services and using autoenrollment to ease certificate distribution. Installing Certificate Services and generating usable enterprise certificates can be challenging; read the Microsoft article "Step-by-Step Guide to Setting up a Certification Authority" for details. If participants are in different domains, you'll need to acquire third-party certificates from a trusted root authority, such as VeriSign. You won't need to set up Certificate Services or generate certificates, which makes life easier on the front end, but you'll face more labor during certificate distribution, when each machine requests and installs a certificate.

Certificates need to be bound to machines rather than users because you're authenticating the computers in the VPN. You use the Microsoft Management Console (MMC) Certificates snap-in to manage certificates. For more information about certificates, see the Microsoft articles "HOW TO: How to Install/Uninstall a Public Key Certificate Authority for Windows 2000" and "HOW TO: Install a Certificate for Use with IP Security" or read Tom Shinder’s "Configuring Gateway to Gateway L2TP/IPSec VPNs" series, which you can access at http://www.isaserver.org/thomas_shinder.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.