65
Configuring the Contivity VPN Client
Chapter 3
Using certificates
This chapter provides information to help you customize your client to use
certificates.
MS CryptoAPI
The Contivity VPN Client supports retrieval of X.509v3 certificates from
Microsoft Certificate storage through the Microsoft CryptoAPI (MS CAPI).
Microsoft provides a Public Key Infrastructure (PKI) that adheres to the
Public-Key Cryptography Standards (PKCS).
Using the Microsoft Certificate storage allows the Contivity VPN Client full
access to the Microsoft Certificate storage and management tools. The Microsoft
Certificate storage and management tools use PKCS standards-based messages
and protocols to manage key pair generation and storage.
Microsoft Certificate storage also provides a mechanism to import digital
certificates granted by third-party Certification Authorities through the use of
standard messages (PKCS #12). This allows the Contivity VPN Client and the
Contivity Secure IP Services Gateway to make use of Certification Authorities,
such as Netscape, that have not been tightly integrated with the Contivity VPN
Client and the Contivity gateway.