cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1168
Views
0
Helpful
2
Replies

Client 4.0.5 Mutual Group Authentication

raymng
Level 1
Level 1

Anyone tried the new Mutual group authentication with the VPN client 4.0.5? Besides the release notes, I am unable to find any documents discussed this in details. Anyone have more info about how this works and how to set it up?

Thanks.

2 Replies 2

umedryk
Level 5
Level 5

Mutual group authentication is asymmetrical in that each side uses a different method to authenticate the other while establishing a secure tunnel to form the basis for group authentication. In this method, authentication happens in two stages. During the first stage, the VPN central-site device authenticates itself using public-key techniques (digital signature) and the two sides negotiate to establish a secure channel for communication. During the second stage, the actual authentication of the VPN Client user by the central-site VPN device takes place. Since this approach does not use pre-shared keys for peer authentication, it provides greater security than group authentication alone, as it is not vulnerable to a man-in-the-middle attack.

My question is how to get a certificate for the Cisco VPN Concentrator. We don't have in-house CA. Does this (mutual group auth) require just basic SSL certificate from Versign, or it would require more than that? I don't know much about PKI, and so I would want to find out what I need to buy from Versign or Entrust for this type of certificate.

Thanks.