Re: Digital Certificate Implementation TN3270



Hal Merritt wrote:
That was then. This is now. The target continues to move. Plan on client
certificates if you are subject to privacy regulations.

The reason I was given is that server only authentication is vulnerable
to a 'man in the middle' attack vector.

HTH and good luck.

Client certificates allow the server to authenticate the client. The use of client certificates has no bearing whatsoever on the prevention of man-in-the-middle attacks.

To prevent this kind of attack with a mainframe emulation, you need to make sure that your client (such as IBM PCOMM):

1. only recognizes trusted Certification Authorities (like Verisign or your own company CA) for server certificates.

2. has the option selected to verify the hostname. In this case, the cn= attribute in the subject's name in the server certificate must be identical to the hostname. Alternatively, the altName= attribute can be used in the certificate to specify the hostname.

IBM PCOMM does not accept self-signed server certificates. This is helpful in preventing MITM attacks.
--
Ulrich Boche
SVA GmbH, Germany
IBM Premier Business Partner

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to listserv@xxxxxxxxxxx with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

.



Relevant Pages

  • Re: copy files from internet using authenticate certificates
    ... Just use ASP.NET on the server, configure your IIS server to use SSL and ... require client certificates. ... you'll need some kind of software that runs when the laptop ... > How I need to use these certificates is the confusing part. ...
    (microsoft.public.dotnet.general)
  • Re: Secure VPN access
    ... with it's security option for the client. ... After getting the VPN connection I check the Ip settings and found the ... point to the head ISP's DNS server. ... > Computer certificates for L2TP/IPSec VPN connections ...
    (microsoft.public.windows.server.sbs)
  • RE: L2TP/IPSEC site-to-site question
    ... seems more difficult on Windows and Isa 2000 mix, ... If I want to use certificates what type I have to use? ... > site-to-site VPN connection. ... > Site-to-Site VPN in ISA Server 2004 ...
    (microsoft.public.isa)
  • Re: Vista wireless using IAS and WPA-Enterprise
    ... certificates, which may be more than the limit that the IAS server can send ... on a Web site or if you use IAS in Windows Server 2003 ... Vista wireless using IAS and WPA-Enterprise ...
    (microsoft.public.windows.server.networking)
  • RE: L2TP/IPSEC site-to-site question
    ... Microsoft Internet Security and Acceleration (ISA) Server 2004 ... >site-to-site vpn connection. ... >My concerns are about the certificates part. ...
    (microsoft.public.isa)