Windows 2000 Certificates

yous <[email protected]>
Newsgroups gmane.comp.security.vpn
Message-ID <[email protected]>
Hi all,

I have a problem configuring my vpn ends so I can't access the lan using certificate authentication. Maybe some of you can help. 

Note: As this was a test we do not work through the net yet but it works as if we were so please do not consider it when establishing possible problem

WORKING CINFIGURATION (NO CERTIFICATES)

Domain Controller XXL - NIC001: 192.168.1.1 (lan XXL)

Active directory contains the user john.doe and his password.

VPN Server - NIC001: 192.168.1.10 (lan XXL)

NIC002: 192.168.100.100 (vpn connection)

with ms-chap v2 for windows authentication (no RADIUS).

VPN Client - NIC001: 192.168.100.200 (vpn connection)

john.doe connects via a VPN connection pointing to the vpn server and using ms-

chap v2 for authentication. The connection port is automatic.

The way I understand it is: when I want to establish the connection, the VPN client is not on the network XXL so cannot contact the domain controller but it retains the domain information from previous cached login. Hence, when the connection is started the username/password is somehow checked against the active directory and the connection is established following:

client ----------------request connection---------------------> server 

server -----requests authentication information--------> client

client ----------------send infomation-------------------------> server 

server --------request check on information -------------> domain controller (DC)

DC ----------- authentify the user/pass combination---> server

server ------------accept connection -------------------------> client

 

NOT WORKING CONFIGURATION (CERTIFICATES - all other things stay the same)

Now I have one more machine on the domain XXL which I defined as the certificate authority.

Domain Controller XXL - NIC001: 192.168.1.1 (lan XXL)

Active directory contains the user john.doe and his password

The XXL CA is entered as Trusted Authority.

VPN Server - NIC001: 192.168.1.10 (lan XXL)

NIC002: 192.168.100.100 (vpn connection)

with ms-chap v2 for windows authentication (no RADIUS)

This machine has a machine certificate from the XXL CA following a mmc 

request. IPSec is enabled for the NIC002. The RAS authentication method is 

EAP only using certificates.

Certificate Authority - NIC001: 192.168.1.50 (lan XXL)

This CA is entered as trusted root authority in the active directory.



VPN Client - NIC001: 192.168.100.200 (vpn connection)

john.doe has a user certificate on the machine following an enrollment request 

using the XXL CA web interface. The machine itself also has a certificate and 

IPSec is enabled at basic level for the network card.

The vpn connection uses EAP authentication with certificate - the certificate 

server is XXL CA 

When I click the connection I do not have to enter any username/password as I just get a reference to the certificate I want to use (john.doe, issued by XXL CA and expiration date next year). When the connection reaches the verifying usernmae and pasword I receive the error:

691 - Access was denied because the username and/or password was invalid on the domain.

I believe it means that the DC is not contacted hence cannot chek the username/password. I do not understand why it worked in the previous configuration but not now.

Any idea?

Ps: I checked a lot and several times trivial elements as that the certificate for john.does was valid or that john.doe existed in the group allowed to remotely access the vpn server.



---------------------------------
Do you Yahoo!?
Protect your identity with Yahoo! Mail AddressGuard

_______________________________________________
VPN mailing list
[email protected]
http://lists.shmoo.com/mailman/listinfo/vpn
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.