ErrorDB » Latest News » News » Linux Cannot Connect to Vista SP1 over Cryptographic Security Services

News Get the latest Technology News

Post New Thread Reply
  Linux Cannot Connect to Vista SP1 over Cryptographic Security Services
LinkBack Thread Tools
  #1 (permalink)  
Old 06-05-2008, 08:10 AM
Root Admin
 
Join Date: May 2008
Posts: 16
Default Linux Cannot Connect to Vista SP1 over Cryptographic Security Services

Computers running open source Linux operating systems have problems connecting to Windows Vista Service Pack 1 machines when cryptographic security services are involved.




Essentially, the problem affects all distributions of Linux and both Vista RTM and SP1 and is related to failures to establish IPsec connections between the platforms, in scenarios where the connection is initiated from the machine powered by the open source operating system. Internet Protocol security (Ipsec) is, of course, related to the cryptographic security services which are used to protect network communications.

"Consider the following scenario. You use Windows Vista Local Security Policy on a Windows Vista-based computer. Or, you use the new Windows Firewall with Advanced Security on a Windows Vista-based computer. You try to initiate an Internet Protocol Security (IPsec) connection from a Linux-based computer to the Windows Vista-based computer. In this scenario, you cannot establish the connection," Microsoft revealed.

Previous versions of the Windows operating systems, including Windows XP and Windows Server 2008 have no issues communicating with Linux. The same is valid for IPsec communications between Vista SP1 and Linux, when the connection is initiated by the Vista computer. This is not an interoperability problem, but rather a glitch in Vista SP1. Microsoft offers a hotfix for the customers impacted by this specific issue.

"In IPsec negotiation for transform proposal of the combination where Authentication Header (AH) and Encapsulating Security Payload (ESP) are used for securing the same packet (AH+ESP), Windows Vista switches the order and replaces the packet with ESP+AH. This behavior breaks the negotiation. In this case, when you initiate the IPsec connection from a Linux-based computer, the Linux operating system proposes that the IPsec security format is AH+ESP. Therefore, the connection cannot be established," Microsoft explained.

source: news.softpedia.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!jeqqit! Wong this Post!
Reply With Quote
Post New Thread Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 11:47 PM.

Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41