Solved

SSL and SSL Client authentication

Posted on 2014-03-21
1
367 Views
Last Modified: 2014-03-24
Can SSL authentication be used just before the session invokes a SSL data transfer protocol (with its own hadnshaking?)

In other words, can you use the two protocols together seemlessly without need for user input.

Thanks
0
Comment
Question by:Anthony Lucia
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 37

Accepted Solution

by:
Mahesh earned 500 total points
ID: 39946555
user input is required in case of SSL
When you 1st access ssl enabled sites, their certificate public key sent to you through browser
Now you enter your username and password and encrypt that with server public key and sent to server
Server has associated private key which can decrypt that credentials and again send  confirmation to client by encrypting it with its private key
Again client is able to decrypt that with provided public key

Also if certificate mapping is enabled, then user has to provide its client certificate as well

Mahesh
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It’s the first day of March, the weather is starting to warm up and the excitement of the upcoming St. Patrick’s Day holiday can be felt throughout the world.
Ransomware continues to grow in reach and sophistication, putting data everywhere at risk. Learn how to avoid being caught in its sinister clutches with these 11 key tips.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question