cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
674
Views
0
Helpful
1
Replies

IPSEC using RSA-SIGNATURE

rehan alam
Level 1
Level 1

If I'm using RSA-SIG as authentication mechanism;
1. do i need to configure PSK as well on my router.
2. is ther any use of shared secret key that is generated by DH Group in case of RSA-SIG based authentication.

 

1 Reply 1

RSA-SIG is used for the authentication of the VPN-peers. With that, PSKs are not needed any more. But authenticating the VPN is only one step in setting it up. Both peers still need key-material for the encryption and integrity-protection. All this key-material is typically generated with Diffie-Hellmann and still needed regardless of the way you authenticate your peer.