client certificates

From: Shaun Wilde (shaun_wilde_at_nospam.nospam)
Date: 04/06/05


Date: Wed, 6 Apr 2005 19:35:06 +0100

I am authenticating users to a site using client certificates and all is
well
except for a few issues.

#1) Once a browser has been challenged, if the user leaves the site in the
same browser and then returns the browser isn't recallenged even if the
session has expired. Is there a way to force a rechallenge?

#2) If I want to use the certificate to sign some data I'd like the user to
present the password again to their certificate (to avoid the popped to
toilet security scenario), this is for critical processes.

I tried opening up child windows etc however it seems that parent/child
windows share this authentication information by default and I can't see how
to stop that?

Thankx

Shaun Wilde



Relevant Pages

  • Client Certificates
    ... I am authenticating users to a site using client certificates and all is well ... same browser and then returns the browser isn't recallenged even if the ... present the password again to their certificate (to avoid the popped to ... I tried opening up child windows etc however it seems that parent/child ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • RE: Checkpoint smart defance as IPS
    ... the browser trusts all certificate authorities ... *any* SSL/TLS communication without tampering anything on the client ... website a client visits on-the-fly. ...
    (Security-Basics)
  • RE: Checkpoint smart defance as IPS
    ... you claim that SSL/TLS can be intercepted and MITM is ... social engineering and not MITM or interception for that matter. ... don't have private key for the certificate on that website. ... You claimed that browser only checks for domain name ...
    (Security-Basics)
  • Re: How to starthandshake with client browser??
    ... >> And then what should i do to handshake with browser? ... > getting the browser to trust your certificate. ... 1-Open an SSL server Socket ... 2-Wait for a connection (from your client web browser). ...
    (comp.lang.java.programmer)
  • Re: username and Password sent as clear text strings
    ... I don't believe a certificate was every presented to the browser, I'll double check that when I get on the client site this morning. ... I completed a security review of a web server, ... Webscarab, like all intercepting web proxy programs I've used on ...
    (Pen-Test)