DirectAccess with Computer Certificates and SHA512 algorithms
hi,
i not sure if right forum.
i have finished test lab deployment of direct access, , have noticed 1 interesting issue trying confirm.
in lab deployed pki part of infrastructure quite while ago, typical deployment, offline root , online issuing authority. configured use sha512 signature , signature hash algorithms. selection might seem paranoid, has never been issue clients have been windows 7 or higher , have full support.
i deployed direct access, , using default settings, appears working correctly, clients connect.
i switched requiring computer certificates, issued certificate da server , test clients based upon "computer" template.
clients no longer connect. looking @ diagnostic logs direct access appeared tunnels not being established correctly. looking @ get-daconnectivitystatus, there issue present, sub status error referring errors remote network authentication. nothing appeared out of ordinary in client diagnostic logs or event viewer.
i went looking on server, nothing appeared @ first point problem, on inspection of system event log, there errors in regards tls:
'an tls 1.2 connection request recieved remote client application, none of cipher suites supported client application supported server. ssl connection request has failed'
so looked around , didn't find out there, couldn't see obvious, occurred me using sha512 in our certificates. fired new ca in test environment, time accepting defaults. reissued certificates computer certificates da server , test clients, , connecting.
does know of incompatibility? documented anywhere? known anyone? has seen well?
any more info great.
kieran jacobsen
hi,
base on experience, information happened when use server supported cipher suite (the client support more cipher suite version, server relatively pool).
the detail of server 2008 support cipher suite version please refer following kb:
schannel cipher suites in windows vista
http://msdn.microsoft.com/en-us/library/windows/desktop/ff468651(v=vs.85).aspx
more information:
test lab guide: troubleshoot directaccess
http://www.microsoft.com/en-us/download/details.aspx?id=22210
hope helps.
alex lv
Windows Server > Network Infrastructure Servers
Comments
Post a Comment