Thursday
Aug122010
Microsoft Cryptographic Store and Passwords
Thursday, August 12, 2010 at 18:30
We've been experimenting with with the use of user certificates for VPN access to the lab. Issuing, and using them isn't the problem. The problem is that there's no way of enforcing a password on the use of the private key. You can use private key protection on the certificate template, but that still doesn't enforce a password requirement. The user still has the option to choosing for the notification instead of a password.
There's an option to enforce a password, but that's system wide for the Microsoft Cryptographic Service Provider, and we don't want to enforce passwords for ALL certificates. We just want to enforce passwords for this specific template.
Willem | Post a Comment |
tagged CSP, certificates in Annoying, Microsoft, Security