66
Chapter 3 Using certificates
311644-J Rev 00
Digital certificates are currently supported by the Contivity ISAKMP key
management protocol. Both the Contivity VPN Client and the Contivity VPN
Secure IP Services Gateway can be configured to mutually authenticate using
digital certificates during the IKE negotiation.
MS-CAPI feature dependencies and backward compatibility
The Contivity VPN Client has dependencies on the Microsoft Crypto-API. Due to
the varying availability of these required features on the different Windows
platforms, there may be some restrictions. When using a Microsoft Enterprise CA,
the Contivity VPN Client Version 4.10 installed on Windows XP, Windows 2000
or later, and using certificates in MS-CAPI store, it is backwards compatible with
the Contivity gateway Version 3.65 or later due to the required certificate
extension processing feature on the gateway.
MSCAPI server CRL checking
MSCAPI server Certificate Revocation List (CRL) checking is disabled by
default. MSCAPI server CRL checking is governed by the
HKLM\Software\Nortel Networks\Extranet Access
Client\MSCAPIServerCRLCheck registry key. If the parameter
MSCAPIServerCRLCheck is set to 1, server CRL checking is performed. If it is
set to 0 or missing, server CRL checking is not performed.
For a custom client installation, you can use the setup.ini file to create and
initialize the MSCAPIServerCRLCheck registry key. To do this, set
MSCAPIServerCRLCheck to 0 or 1 in the setup.ini options section:
[Options]
MSCAPIServerCRLCheck=1
The Entrust functionality remains unchanged.
Note:
You can use any tools provided by a Certification Authority (CA)
that support and have been integrated with MS CAPI to create certificate
requests.
Содержание Contivity VPN Client
Страница 8: ...8 Contents 311644 J Rev 00 ...
Страница 10: ...10 Figures 311644 J Rev 00 ...
Страница 12: ...12 Tables 311644 J Rev 00 ...
Страница 84: ...84 Chapter 3 Using certificates 311644 J Rev 00 ...
Страница 88: ...88 Appendix A Client logging 311644 J Rev 00 ...