Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Problem with Contivit y and Certificates from Verisign |
|---|---|
| Date: | Sat, 10 Sep 2005 06:46:10 -0600 |
No, I tend to remember that in the certificate properties (System>Certificates>[SERVER CERTIFICATE]), you could establish a mapping between the client certificates' DN and the groups in the Contivity... it should be in the manual or in a tech tips from Nortel. If you cannot find this, feel free to mail me off-line for more info. Regards, Rodrigo. On 9/8/05, Cesar Farro Flores <cesar.farro@t-empresas.com.pe> wrote:
1- Are other similar certificates working, or all of them are failing to authenticate? Now, I am testing only with Verisign certificates for server and users. At the beginning, I was testing with Microsoft certificate for the server and Verisign certificate for users. The result was the same. 2.- Have you established obligatory CRL check in the Contivity server certificate, and if so, is the CRL accessible from the Contivity? No. CRL check is disabled. 3.- Has the certificate been revoked in the CA? No. The certificate is valid. 4.- Is the server certificate in the Contivity enabled? Yes, It is. 5.- Have you configured the <certificate DN - Contivity group> mapping? I think you ask me about "Profiles/Groups/IPSec"...It's configured as follows: Database Authentication LDAP - User and password: enabled - RSA Digital Signature: enabled * Default Server Certificate: CN=VPN1700, OU=Sis.... CF. Rodrigo Blanco <rodrigo.blanco.r@gmail.com> escribió el 06/09/2005 01:46:35 a.m.:Hello Cesar, I would check these items, just as a beginning: - Are other similar certificates working, or all of them are failing to authenticate? - Have you established obligatory CRL check in the Contivity server certificate, and if so, is the CRL accessible from the Contivity? - Has the certificate been revoked in the CA? - Is the server certificate in the Contivity enabled? - Have you configured the <certificate DN - Contivity group> mapping? Regards, Rodrigo. On 9/5/05, Cesar Farro Flores <cesar.farro@t-empresas.com.pe> wrote:Hi List, We have contivity vpn switch 1700 sw V05_00.136 and certificates fromCAVerisign, we have a problem in the process of authenticatication. Wecansee in the log that before this error message, the contivity deliversanIP Address to my user. Then the authentication failure. Does anybodyknowwhy this error messages appears in the log : "rejected or aborted connection attempt". We will appreaciate your help. #################################################################### 08/31/2005 11:43:40 0 ISAKMP [02] ISAKMP SA established with mail=jesus@x.com.pe, cn=jesus , ou=organizacion - x, ou=terms of use at www.ace.es/rpa (c)01, ou=csc - class 2, o=xxx.s.a.a. (200.x.x.83) 08/31/2005 11:43:40 0 ISAKMP [13] Error notification (Authentication failure) received from mail=jesus@x.com.pe, cn=jesus, ou=organizacion - x, ou=terms of use at www.ace.es/rpa (c)01, ou=csc - class 2, o=xxx.s.a.a. (200.x.x.83) 08/31/2005 11:43:40 0 ISAKMP [13] mail=jesus@x.com.pe, cn=jesus, ou=organizacion - x, ou=terms of use at www.ace.es/rpa (c)01, ou=csc - class 2, o=xxx.s.a.a. (200.x.x.83) rejected or aborted connection attempt ##################################################################ForwardSourceID:NT0000AD06
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Aply Kernel Extensions, Ronald van der Westen |
|---|---|
| Next by Date: | pix snmp logging, Ade |
| Previous by Thread: | Re: Problem with Contivit y and Certificates from Verisign, Cesar Farro Flores |
| Next by Thread: | Cisco PIX VPN Client issue, Hodgson, Tim |
| Indexes: | [Date] [Thread] [Top] [All Lists] |