一個關于SSL,CDP和 x509的問題 - 資安

Daph Bay avatar
By Daph Bay
at 2009-01-12T22:03

Table of Contents

※ [本文轉錄自 Prob_Solve 看板]

作者: outdance (美國要掛了,我會失業嗎) 站內: Prob_Solve
標題: [問題] 一個關于SSL,CDP和 x509的問題
時間: Mon Jan 12 21:50:36 2009

我的頭解決不了這問題,到處在尋求答案

要是誰有點思路,小弟定當感激不盡,下面是他的問題

The current task we are doing is two factors authentication, which is used
to authenticate users against both their client certificates and their accounts
.

Now we configured a web server successfully, which requires clients certificates
when users access it. And then try to make it working with SiteMinder( the
SSO application).
We need use SiteMinder to validate both of the users certificates and user
accounts. But after we installed SiteMinder agent for the web server, the
SiteMinder can not get the clients certificates from web server side.
The information we got is that there are something in IIS preventing SiteMinder
from getting the clients certificates. SiteMinder support said we need disable
a option in IIS, named CDP checking.
CDP means CRL Distribution Point, and CRL means Certificate Revocation List
.
Actually, we disabled the CRL checking of IIS by setting CertCheckMode to
1 in IIS. But it doesn't resolve this problem.

All members in SSO team are not familiar with x509 certificate and advanced
SSL configuration for IIS.
So we want ask for helps from who are experienced in x509 certificate, SSL
configuration for IIS, especially CRL and CDP. If anybody are familiar with
SiteMinder x509 configuration, it will be perfect.

--
Tags: 資安

All Comments

遠端桌面遙控的安全問題

Wallis avatar
By Wallis
at 2009-01-09T20:51
由於工作上的需要,有時會回家後以遠端桌面的方式, 連結工廠內的電腦,監控發酵槽溫度的變化, 因為工廠地處偏遠無法申請固定IP,所以我都將電腦保持在上網的狀態, 回家前再記下工廠電腦的IP,以便回家後可監控它。 問題來了! 今天清晨因天氣驟降,工廠內的溫控系統發出警報, 而我卻無法在家裡即時連結上工 ...

一直有外部UDP封包流進來??

Zora avatar
By Zora
at 2009-01-09T12:15
小弟是網咖網管 近日來一直被十二之天貳這個遊戲困擾 目前會發生的現像是 場內單機的ip進到遊戲後 and#34;有時and#34;會出現一個從遊戲公司server 傳過來的UDP封包 而這個UDP封包會一直想送進來 就算把那一台場內的電腦關機 遊戲公司會一直傳大概20K Byte 左右的流量 不會間斷 ...

無線網路出現"Free Public WiFi"

Regina avatar
By Regina
at 2009-01-08T20:53
家中用無線網路分享器,一直以來都平安無事, 但在剛剛有電腦開始無法連上網路, 但我自己的電腦卻可以順暢的使用, 就算是把筆電換個位置也沒有問題,但爸媽在用的卻是一直都連不上 然後我搜尋了可用的網路,出現了以前從沒有看過的 and#34;Free Public WiFiand#34;,而且強度很強。 ...

980107垃圾郵件IP

Edith avatar
By Edith
at 2009-01-07T17:15
Source IP 國家 反解名稱 =========================================================================================== 200.67.120.2 ...

憑奇摩的ID或暱稱有可能Pin得到IP出處嗎?

Una avatar
By Una
at 2009-01-05T15:48
這照理說應該是網路警察該做的事, 但很擔心案子太小,被吃案,所以到版上來問問. 雅虎奇摩不知道是吃錯什麼藥, 居然他們很多平台都可以讓user暱稱換來換去, 看不到原始註冊的ID,導致一些有心人, 常冒用本人公司的相關名義當暱稱, 讓這些冒用的暱稱到別人的部落格發黑函,或污衊, 因為都是暱稱,完全看不到原始 ...