|
Posted by ArshinK on October 28, 2007, 12:33 pm
Please log in for more thread options
Hi
I have a problem when trying to understand Certificate-Authententication in
IKE.
The problem is that when we take an IPSec-certificates from CA and install
them in the Principal's-Store, it doesn't matter to what name we use for
Subject-Field.
So how it protects against Man-in-the-Middle Attack? as it is possible for
attacker to take a certificate with an optional name from the same CA and
performs a successful authentication?
In other word, what attribute (except that Subject) in the certificate
exactly determines the identification of other principal?
It is clear for me when using the Authentication Process in Kerberos or
Pre-Shared-Key but not about Certificate when no field in the certificate is
related to other principal!
Please help !
Thanks
|