<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx</link><description>GINAs Replaced with New Credential Providers In previous releases, the customization of interactive user logon was done by creating a custom GINA. Despite the name, GINAs were responsible for more than simply gathering authentication information and rendering</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx#422518</link><pubDate>Mon, 20 Mar 2006 14:31:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422518</guid><dc:creator>olt</dc:creator><description>Interesting. &amp;nbsp;From an IT management / user point of view - does allow further development of the RunAs (secondary logon) theme to allow task based authorisation within windows generally?&lt;br&gt;&lt;br&gt;The push towards least privileged user accounts is great but it's not easily supported in the OS for day to day users. &amp;nbsp;For example, if they need to install a new application (and it's not been deployed via GP) it would be great if the OS would prompt them to elevate their privileges temporarily; or, if they needed to change their IP address - rather than simply saying &amp;quot;please contact your system administrator&amp;quot;.&lt;br&gt;&lt;br&gt;Dare I say this: the users' experience of &amp;quot;least privilege&amp;quot; in OSX is good - they get prompted to confirm or enter credentials when they try to perform an &amp;quot;elevated&amp;quot; task in the OS which means that they can actually get on with life without &amp;quot;contacting your system administrator&amp;quot;. &amp;nbsp;I believe this should at least be an option in a Windows environment as it would encourage organisations who currently don't implement a decent security policy for their desktop PCs (running as local admins for example is very common) to make some steps in the right direction.&lt;br&gt;</description></item><item><title>re: New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx#422576</link><pubDate>Tue, 21 Mar 2006 01:35:39 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422576</guid><dc:creator>Authentication</dc:creator><description>Indeed we are working in Vista to improve the Least privilege user experience. Please take a look at the UAC blog for more details&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/uac"&gt;http://blogs.msdn.com/uac&lt;/a&gt;</description></item><item><title>re: New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx#681657</link><pubDate>Thu, 08 Mar 2007 11:13:14 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:681657</guid><dc:creator>BkCloud</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;I would like to create new cipher suite and then plug it into Schannel. But I Couldn't find the way how to do it.&lt;/p&gt;
&lt;p&gt;Could you tell me where I can get it or how to do it?&lt;/p&gt;
&lt;p&gt;thanks,&lt;/p&gt;
&lt;p&gt;Hyun&lt;/p&gt;
</description></item><item><title>re: New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx#681660</link><pubDate>Thu, 08 Mar 2007 11:16:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:681660</guid><dc:creator>BkCloud</dc:creator><description>&lt;p&gt;Furthermore, I'd like to use new cipher suite at windows xp. If you know the way to plug the new cipher suite into XP, please let me know.&lt;/p&gt;
</description></item><item><title>re: New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx#744817</link><pubDate>Tue, 10 Apr 2007 18:14:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:744817</guid><dc:creator>GordT.</dc:creator><description>&lt;p&gt;&amp;quot;Windows Vista includes new authentication feature changes to support the branch office DC feature in Longhorn.&amp;quot; &lt;/p&gt;
&lt;p&gt;Are there more details on this? I thought it would be possible to use the Branch Office DC features with WinXP as well - is this not to be?&lt;/p&gt;
</description></item><item><title>re: New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx#852104</link><pubDate>Mon, 30 Apr 2007 20:14:20 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:852104</guid><dc:creator>Authentication</dc:creator><description>&lt;p&gt;GordT,&lt;/p&gt;
&lt;p&gt;Sorry for the confusion. This was authored a while back before we knew Vista was just client. We have updated the text to avoid future confusion.&lt;/p&gt;
&lt;p&gt;- The Windows Authentication Team&lt;/p&gt;
</description></item><item><title>re: New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx#1307539</link><pubDate>Wed, 20 Jun 2007 23:22:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1307539</guid><dc:creator>cxu123</dc:creator><description>&lt;p&gt;Unfortunately the new AES encryption for SSL/TLS is not compatible with OpenSSL library! Many people experience this problem. &lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.mail-archive.com/openssl-users@openssl.org/msg48968.html"&gt;http://www.mail-archive.com/openssl-users@openssl.org/msg48968.html&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx#1308794</link><pubDate>Thu, 21 Jun 2007 01:54:23 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1308794</guid><dc:creator>Authentication</dc:creator><description>&lt;p&gt;Interestingly enough - this is an interop issue that we have seen previously. The problem is occurs only in the following scenario:&lt;/p&gt;
&lt;p&gt;TLS Enabled Client --&amp;gt; SSL3.0 only server&lt;/p&gt;
&lt;p&gt;The SSL3.0 server responds to a TLS client hello with a SSL3.0 server hello trying to negotiate an AES cipher. Unfortunately AES ciphers were not even defined for SSL3.0 and obviously the client closes the connection.&lt;/p&gt;
&lt;p&gt;The server in this case is misconfigured to negotiate AES over SSL3.0&lt;/p&gt;
&lt;p&gt;This will be a bigger problem if not fixed when TLS 1.2 is implemented and SSL3.0 servers try to negotiate new TLS1.2 ciphersuites like TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256.&lt;/p&gt;
</description></item><item><title>re: New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx#1396349</link><pubDate>Fri, 29 Jun 2007 17:53:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1396349</guid><dc:creator>cxu123</dc:creator><description>&lt;p&gt;This seems to be happened in TLS also.&lt;/p&gt;
&lt;p&gt;I had tried to use SDK sample web server from:&lt;/p&gt;
&lt;p&gt;C:\Program Files\Microsoft Platform SDK\Samples\Security\SSPI\SSL\WebServer&lt;/p&gt;
&lt;p&gt;If I connected it with AES128-SHA from client using Microsoft CryptoAPI, it works without any problem.&lt;/p&gt;
&lt;p&gt;But if I connected it with cipher AES128-SHA from client using openssl, TLS negotiation can success. The WebServer using Microsoft CryptoAPI can not decrypt message from openssl client. However, openssl client can decrypt message from CryptoAPI WebServer.&lt;/p&gt;
&lt;p&gt;Is the SDK example outdated with Windows Vista?&lt;/p&gt;
</description></item><item><title>re: New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx#1426219</link><pubDate>Tue, 03 Jul 2007 03:59:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1426219</guid><dc:creator>Authentication</dc:creator><description>&lt;p&gt;We run a full interop test spectrum with OpenSSL and the implementations have been interoperable for a while now. Could you report the specifics of the failure you are experiencing?&lt;/p&gt;
&lt;p&gt;The SDK sample should be current as no changes were needed to calling applications to take advantage of AES on Vista\LH.&lt;/p&gt;
</description></item><item><title>re: New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx#1444931</link><pubDate>Thu, 05 Jul 2007 17:30:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1444931</guid><dc:creator>cxu123</dc:creator><description>&lt;p&gt;It was easy to setup. &lt;/p&gt;
&lt;p&gt;I used nmake to compile the SDK sample, the one in &amp;nbsp;the &amp;quot;Samples\Security\SSPI\SSL\WebServer&amp;quot;. My environment is visual studio .net 2003. I ran it in verbose mode and TLS 1.0. &lt;/p&gt;
&lt;p&gt;I am using the windows wget at the link&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://users.ugent.be/~bpuype/wget/"&gt;http://users.ugent.be/~bpuype/wget/&lt;/a&gt; as the client. This one uses openssl library.&lt;/p&gt;
&lt;p&gt;I created a self-signed certificate and let the SDK WebServer uses this certificate.&lt;/p&gt;
&lt;p&gt;wget can successfully finish the handshake with WebServer, but the HTTP request it sent to WebServer can not be decrypted. It is something to do with cipher AES. It will have no problem if using IE as client or uses openssl but not uses AES cipher. I had tried other openssl client and got the same result.&lt;/p&gt;
&lt;p&gt;I ran Vista Business in the virtual machine. But I tried both VMWare and Virtual PC 2007 and they both had the same result. I had also tried the latest Windows 2008 beta and got the same result.&lt;/p&gt;
&lt;p&gt;I suspect it has something to do with SDK example, but many programs using CryptoAPI followed this SDK example.&lt;/p&gt;
</description></item><item><title>re: New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx#1446638</link><pubDate>Thu, 05 Jul 2007 20:46:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1446638</guid><dc:creator>Authentication</dc:creator><description>&lt;p&gt;Is TLS enabled on the server app? What error\errcode do you get on failure?&lt;/p&gt;
&lt;p&gt;Which version of OpenSSL?&lt;/p&gt;
&lt;p&gt;Could you use IIS instead for testing to eliminate the possibility of an error in the sample?&lt;/p&gt;
</description></item><item><title>re: New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx#1446798</link><pubDate>Thu, 05 Jul 2007 21:09:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1446798</guid><dc:creator>cxu123</dc:creator><description>&lt;p&gt;Yes, the SDK WebServer sample has an option to use TLS 1.0. &lt;/p&gt;
&lt;p&gt;I had tried using the latest version of openssl. &lt;/p&gt;
&lt;p&gt;I had tried to use the new IIS beta in Windows 2008. IIS beta works with openssl AES cipher without this problem. That's the reason that I suspected the SDK sample program probably won't work with AES cipher in Vista. &lt;/p&gt;
</description></item><item><title>re: New Authentication Functionality in Windows Vista</title><link>http://blogs.technet.com/authentication/archive/2006/03/18/new-authentication-functionality-in-windows-vista.aspx#1481862</link><pubDate>Mon, 09 Jul 2007 09:17:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1481862</guid><dc:creator>Authentication</dc:creator><description>&lt;p&gt;cxu123 let's move this discussion to the MSDN forum. We are not making good use of the comments section here :)&lt;/p&gt;
&lt;p&gt;I've started a thread here: &lt;a rel="nofollow" target="_new" href="http://forums.microsoft.com/technet/showpost.aspx?postid=1833975&amp;amp;siteid=17"&gt;http://forums.microsoft.com/technet/showpost.aspx?postid=1833975&amp;amp;siteid=17&lt;/a&gt;&lt;/p&gt;
</description></item></channel></rss>