?
Solved

SSL and SSL Client authentication

Posted on 2014-03-21
1
Medium Priority
?
382 Views
Last Modified: 2014-03-24
Can SSL authentication be used just before the session invokes a SSL data transfer protocol (with its own hadnshaking?)

In other words, can you use the two protocols together seemlessly without need for user input.

Thanks
0
Comment
Question by:Anthony Lucia
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 37

Accepted Solution

by:
Mahesh earned 2000 total points
ID: 39946555
user input is required in case of SSL
When you 1st access ssl enabled sites, their certificate public key sent to you through browser
Now you enter your username and password and encrypt that with server public key and sent to server
Server has associated private key which can decrypt that credentials and again send  confirmation to client by encrypting it with its private key
Again client is able to decrypt that with provided public key

Also if certificate mapping is enabled, then user has to provide its client certificate as well

Mahesh
0

Featured Post

Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this blog we highlight approaches to managed security as a service.  We also look into ConnectWise’s value in aiding MSPs’ security management and indicate why critical alerting is a necessary integration.
Hey fellow admins! This time, I have a little fairy tale for you. As many tales do, it starts boring and then gets pretty gory. I hope you like it. TL;DR: It is about an important security matter, you should read it if you run or administer Windows …
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
Suggested Courses
Course of the Month10 days, 6 hours left to enroll

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question