CA root certificate

CA root certificate

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
CA root certificate michele.gullia 05-22-2008
Posted by on May 22, 2008, 9:27 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi to all. This is my first post and my first step to the PKI
knowledge.
Someone have asked me if there is a way to make the Root Certificate
not exportable so only the one who have installed this certificate in
the machine can access via PEAP to the wifi network and in the same
time the user cannot pass this certificate to another PC.
A kind of security enanchement.
Ok...i think i have the answer and it's NO, but to be honest I'm too
new to this topic and I wont to be sure.

Thank for your intrest and sorry for my bad english

Posted by S. Pidgorny on May 23, 2008, 6:07 am
If you were  Registered and logged in, you could reply and use other advanced thread options
You're right - the answer is resounding no. Certificate is public
information. It is presented to anybody requesting PEAP connection.

What you're looking for if protected private key. Use EAP-TLS instead of
PEAP, put the client certificate (along with private key) on a smart card
and that achieves the outlined goal.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

> Hi to all. This is my first post and my first step to the PKI
> knowledge.
> Someone have asked me if there is a way to make the Root Certificate
> not exportable so only the one who have installed this certificate in
> the machine can access via PEAP to the wifi network and in the same
> time the user cannot pass this certificate to another PC.
> A kind of security enanchement.
> Ok...i think i have the answer and it's NO, but to be honest I'm too
> new to this topic and I wont to be sure.
>
> Thank for your intrest and sorry for my bad english



Similar ThreadsPosted
Add a Root Certificate Server October 12, 2005, 11:08 am
Renaming a Certificate Root authority June 28, 2006, 5:16 pm
Remove Certificate Server (root CA) October 31, 2007, 10:56 pm
import contact signed certificate and root ca September 28, 2007, 9:36 pm
Question about pkiview.msc Root Certificate Expiring February 15, 2008, 4:16 am
Root certificate authority no longer added to client machines December 15, 2006, 8:15 am
Clients no longer pick up the Root CA as a trusted root authority June 6, 2006, 6:59 pm
Convert Enterprise Root CA to Standalone Root CA and create new Subordinate CAs March 19, 2008, 1:45 am
Migrating from single enterprise root CA to different root CA May 11, 2007, 6:43 am
"No Certificate Templates Could Be Found" Error Message When User Requests Certificate from CA Web Enrollment Pages September 21, 2006, 1:33 pm

The site map in XML format XML site map

Contact Us | Privacy Policy