windows 8.1 pro - embedded VPN client. Certificate Common Name error severity set to error instead of alert.

Hi,

I have been using juniper Network connect for a few years now.
after upgrading to win 8.1 i decided to use the embedded VPN client to connect to the corporate network.

the facts: 


the server i use to connect to, using the juniper NC (the sign in page) ,is not issuing the proper certificate CN name for the target server.
i.e sa.bezeq.co.il instead of the server i try to connect to 212.***.***.***
and a security alert is popped up asking if i want to proceed. - which i choose YES and it connects without any problems.

but when i configured the windows VPN and tried to connect an error pops: "certificate CN name does not match the passed value"  the problem is that it pops an Error instead of an alert and not allowing to proceed.
i cant find my way around it..

is there any security policy set to ask if i want to proceed anyway or disregard the name difference ( just like in the Juniper Client )?
or any other workaround, registry key, powershell cmdlet .. anything? 


after days of research i found that in development environment there was some kind of solution using a parameter flag called INTERNET_FLAG_IGNORE_CERT_CN_INVALID 

another related topic about win phone 8 development mode using SocketSslErrorSeverity parameter set to ignore.

but the above ideas are not for desktop win 8.1 pro edition without serious tweak using code. - which i absolutely want to avoid.

I would really appreciate your professional help in suggesting the easy workaround.


Regards

Itsik

September 23rd, 2014 11:56am

if you are using ip address to connect to vpn server the ip address will never match the name on the certificate, you need to add a dns entry that matches the common name of the certificate and point it to the server ip address you are using, if you don't own the domain and can't add a dns record you either have to change the server name you are using and get a new certificate or move to a shared secret type connection and change all the connection to use it.
Free Windows Admin Tool Kit Click here and download it now
September 23rd, 2014 1:35pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics