Certificates - Multiple machines - one user

From: Doug Perkerson (DougPerkerson_at_discussions.microsoft.com)
Date: 02/26/05


Date: Sat, 26 Feb 2005 11:37:02 -0800

I've got a question about users certificates. We have CA setup and we have
begun issuing certs to users. The major push for the certs is 802.1X
authentication, both for wireless and wired connections.

The problem that I have experienced is with the pool of laptops. The
wireless network is using EAP-TLS authentication. The machine authenticates
to the network with no problem. The users however do not. In this scenario,
the user has a desktop that they use day to day. When they have a
presentation to give or need to travel to a remote office they are issued a
laptop from the pool. Since the user's certificate was issued to them while
they were logged into their desktop, they do not have access to the private
key's on the laptop and can therefore not authenticate to the network.

I realize that we could issue the certificates as exportable and then
manually move the certificate to the laptop. Is this the best way to solve
this problem? Aren't there security risks involved in making the keys
exportable?

Any comments that anyone can provide will be greatly appreciated.



Relevant Pages

  • Re: Question about Wireless Security
    ... instructions in the SBS 2003 Administrator's Companion to set it up. ... to still use certificates to authenticate. ... Authentication would fail for the laptop itself, ...
    (microsoft.public.security)
  • Re: PEAP-TLS vs EAP-TLS
    ... MSCHAPV2 will not be used and then maybe that would be PEAP-TLS. ... select authentication method there are two choices - secured password ... certificates for both server authentication and client authentication; ... I think this means that there's a PEAP-TLS that's separate from EAP-TLS ...
    (microsoft.public.windows.server.security)
  • Re: public key vs passwd authentication?
    ... note that in the generic description of 3-factor authentication, ... certification authorities, and/or certificates ... considered a totally orthogonal business issue. ... possible to deploy a digital signature based two-factor authentication ...
    (comp.security.ssh)
  • RE: IAS server blues (Cant get 802.1x to work)
    ... clients. ... and it appears that the certificates are deploying correctly. ... Proxy-Policy-Name = Use Windows authentication for all users ... IAS Log Sample ...
    (microsoft.public.windows.server.general)
  • client certificates for authentication but not encryption
    ... resolved the crash, but at the cost of using a secure ... client certificates for authentication but not encryption ... > server using the WebDAV protocol. ...
    (microsoft.public.inetserver.iis.security)