Project

General

Profile

Requirements for certificates used with Windows 7 » History » Version 2

« Previous - Version 2/13 (diff) - Next » - Current version
Martin Willi, 07.05.2009 14:01


Requirements for certificates used with Windows 7

The Windows 7 Beta release was liberal in accepting certificates, but the Release Candidate adds new requirements to the used certificates.

Required fields

Your Gateway certificate must have:

  • An Extended Key Usage Flag, expilicitly allowing the certificate to be used for authentication purposes. It is currently unclear which OIDs are accepted by Windows, but it seems that the ServerAuth OID (1.3.6.1.5.5.7.3.1, often called TLS Web server authentication) gets accepted.
  • The Gateway Hostname entered in the clients connection properties MUST be contained in the Distinguished Name of the certificate or in a subjectAltName.

Disabling extended certificate checks

Alternatively, you may disable these extended certificate checks on the client.

This is potentially dangerous, as any certificate holder assured by your CA may act as the VPN gateway.

To disable the extended checks, add a DWORD called DisableIKENameEkuCheck to

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RasMan\Parameters\

in the clients Registry.

Futher information

For more details about the requirements and other ways to disable the certificate checks, have a look to this knowledge base article.