Thanks Robert.
We are really trying to build a corporate VPN, we don't need to
authenticate people inside our environment. We looked into using IPSEC with
pre-shared keys rather than certificates, but according to IRE we would need
to pre-define all our IP addresses for this to work. Since our current ISP
uses DHCP and we have several people telecommuting with cable and DSL
connections with DCHCP the certificates seemed the right way to go.
-----Original Message-----
From: [EMAIL PROTECTED]
[SMTP:[EMAIL PROTECTED]] On Behalf Of Robert E. Spivack
Sent: Friday, July 30, 1999 4:33 PM
To: [EMAIL PROTECTED]
Subject: RE: [IMail Forum] Off Topic - Certificate Server
To build on comments, be clear whether you are trying to simply build a VPN,
or truly need trusted/secured end-to-end presentation layer information.
VPN -using the public Internet to create the equivalent of a private
corporate network
Trusted End-to-End: you need to verify that people are who they say they
are, even within a corporate environment
A good VPN client (such as IRE) plus IPSEC enabled routers (Cisco, of
course) provides full VPN solution. A PKI infrastructure with certs et. al.
is only needed if you really don't even trust the people within your
corporate environment.
Most of the folks I have worked with on VPN are primarily concerned about
keeping the VPN safe so outsiders don't sniff their traffic traversing the
public Internet, but are much less concerned about internally encumbering
everyone with layers and layers of added security.
By the way, since Cisco annouced they will be reselling the IRE client,
using Cisco routers can facilitate a complete single-vendor solution which
is a non-trivial advantage in bleeding-edge stuff like VPNs.
also, I have unofficially heard that the Cisco/IRE client might even be
bundled into future Microsoft OS's directly as part of their colloborative
work on Active Directory stuff, but that's just a rumour....
-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Vaughn Thurman
Sent: Friday, July 30, 1999 6:55 AM
To: [EMAIL PROTECTED]
Subject: Re: [IMail Forum] Off Topic - Certificate Server
Are you putting in Safe-Net boxes in your facility, or just doing client
software and using an IPSEC compliant router or something? IRE has great
hardware and software, but the thing that sort of bothers me about their
program is that they really want to push their "trusted services"
certificate management program. I toured their facility in White Marsh
Maryland a few months ago and they have some impressive clients on their
program, but the "trusted services" certificate management thing is pretty
new. I can not say for sure that they are wrong about the IIS Certificate
Server, but I do know what they want to charge for one of their Certificate
Servers (Wheeoooo!) and why you would want to find something cheaper. There
is not a lot of documentation on the MS Cert Server with IIS4, but I have to
say it has done everything I have needed for internal (Intranet) security
for a client we have with 3,000 users. Client side validation, software
code-signing, server certification, SSL 2.0 and 3.0 and more are all running
from one MS cert box there. We use Java code to read the X.509 certificates
as part of our authentication scheme and have had no trouble with the MS
Certificates meeting all known standards we have run in to. I think IRE is
extremely reputable, but you still might want to do some homework on that
"won't work with IIS thing" post SP5 Cert server I think does support those
standards, but I will have to dig through the notes to see. one more place
to look at is http://www.thawte.com/enterprise/managed.html Thawte
Consulting's Enterprise PKI. They are more affordable than Verisign for PKI
systems and pre-recognized by all v.4 and above browsers.
Hope this helps...
-V
----- Original Message -----
From: Brian Politis <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Friday, July 30, 1999 9:20 AM
Subject: RE: [IMail Forum] Off Topic - Certificate Server
> I am new to certificates, and am not sure yet what the standards listed
> below really are, but the vendor of the software I am trying to use
> specifically said their software would not work with the IIS Certificate
> Server and I needed the PKCS #7 and 10 compliancy. From that I inferred
> that IIS did not support these.
>
> The end goal is to use IRE's IPSEC VPN client to connect to our corporate
> network via the internet.
>
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [SMTP:[EMAIL PROTECTED]] On Behalf Of Vaughn Thurman
> Sent: Thursday, July 29, 1999 10:34 PM
> To: [EMAIL PROTECTED]
> Subject: Re: [IMail Forum] Off Topic - Certificate Server
>
> Doesn't the Certificate Server Component of IIS4 comply with that if you
do
> an advanced install on a machine that already had the domestic security
> installed? I know it is not the most user friendly thing in the world but
> it works sorta :->
> -V
> ----- Original Message -----
> From: Brian Politis <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Thursday, July 29, 1999 4:23 PM
> Subject: [IMail Forum] Off Topic - Certificate Server
>
>
> > I am looking for an in-expensive certificate server to co-exist with
> Imail,
> > and IIS 4.0 on the same box. I downloaded Netscape's Certificate server
> > 1.01 and after hours of fiddling discovered that it would not run on SP4
> or
> > SP5.
> >
> > In particular I need PKCS#7 and PKCS#10 compliancy.
> >
> > Does anyone out there have a product they can reccomend?
> >
> > Please visit http://www.ipswitch.com/support/mailing-lists.html
> > to be removed from this list.
> >
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.