Solved

SSL and SSL Client authentication

Posted on 2014-03-21
1
357 Views
Last Modified: 2014-03-24
Can SSL authentication be used just before the session invokes a SSL data transfer protocol (with its own hadnshaking?)

In other words, can you use the two protocols together seemlessly without need for user input.

Thanks
0
Comment
Question by:Anthony Lucia
1 Comment
 
LVL 35

Accepted Solution

by:
Mahesh earned 500 total points
ID: 39946555
user input is required in case of SSL
When you 1st access ssl enabled sites, their certificate public key sent to you through browser
Now you enter your username and password and encrypt that with server public key and sent to server
Server has associated private key which can decrypt that credentials and again send  confirmation to client by encrypting it with its private key
Again client is able to decrypt that with provided public key

Also if certificate mapping is enabled, then user has to provide its client certificate as well

Mahesh
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It’s a strangely common occurrence that when you send someone their login details for a system, they can’t get in. This article will help you understand why it happens, and what you can do about it.
Since pre-biblical times, humans have sought ways to keep secrets, and share the secrets selectively.  This article explores the ways PHP can be used to hide and encrypt information.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

930 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now