K
Kati
If a fully AD-controlled computer inside the network gets
a certificate, it can connect using IPSEC/L2TP just fine,
but there seems to be no way to give a certificate to an
uncontrolled computer (e.g., one owned by an otherwise
authenticated user at his home) that would allow a
connection.
So far I have found no way to produce a certificate for
such a user that would be honored by the RAS server.
a certificate, it can connect using IPSEC/L2TP just fine,
but there seems to be no way to give a certificate to an
uncontrolled computer (e.g., one owned by an otherwise
authenticated user at his home) that would allow a
connection.
So far I have found no way to produce a certificate for
such a user that would be honored by the RAS server.