Thursday
Aug122010
Microsoft Cryptographic Store and Passwords
![Date Date](/universal/images/transparent.png)
We've been experimenting with with the use of user certificates for VPN access to the lab. Issuing, and using them isn't the problem. The problem is that there's no way of enforcing a password on the use of the private key. You can use private key protection on the certificate template, but that still doesn't enforce a password requirement. The user still has the option to choosing for the notification instead of a password.
Certificate Template - Request Handling OptionsThere's an option to enforce a password, but that's system wide for the Microsoft Cryptographic Service Provider, and we don't want to enforce passwords for ALL certificates. We just want to enforce passwords for this specific template.
![Author Author](/universal/images/transparent.png)
![Comment Comment](/universal/images/transparent.png)
tagged
CSP,
certificates in
Annoying,
Microsoft,
Security
![Tag Tag](/universal/images/transparent.png)
![Tag Tag](/universal/images/transparent.png)
![Category Category](/universal/images/transparent.png)
![Category Category](/universal/images/transparent.png)
![Category Category](/universal/images/transparent.png)