Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Can a user have a certificate or does only a machine have a certificate?

This thread has been viewed 0 times
  • 1.  Can a user have a certificate or does only a machine have a certificate?

    Posted Jul 16, 2017 01:22 PM

    If say you want to set up a PKI and use EAP-TLS to authenticate all users and computers.

     

    A computer's certificate is stored on that computer. But how can a user have a certificate? Where is it stored? What if a user logs in from another computer, how will he provide his certificate for client authentication?



  • 2.  RE: Can a user have a certificate or does only a machine have a certificate?
    Best Answer

    EMPLOYEE
    Posted Jul 16, 2017 01:24 PM
    There is a system cert store and a user store. Machine certs are stored in the system store and user certs are stored in the user store.


  • 3.  RE: Can a user have a certificate or does only a machine have a certificate?

    Posted Jul 16, 2017 01:34 PM



  • 4.  RE: Can a user have a certificate or does only a machine have a certificate?

    EMPLOYEE
    Posted Jul 16, 2017 02:19 PM

    In practice, it is worse than that...  Typically user certificates are only distributed via group policy when that user logs in successfully via a wired computer.  The user would have had to login to a wired computer to even have the certificate distributed to the user's profile before using it wirelessly.  That is why many secure environments only have wireless eap-tls with machine certificates and machine-only wireless authentication...  Having a multi-user device with wireless user certificates is a headache to provision in practice for multiple user.



  • 5.  RE: Can a user have a certificate or does only a machine have a certificate?

    Posted Jul 16, 2017 05:00 PM

    Thank you 



  • 6.  RE: Can a user have a certificate or does only a machine have a certificate?

    EMPLOYEE
    Posted Jul 16, 2017 05:04 PM
    The machine cert is unique per device. The user cert is downloaded into the user cert store after the user logs in. This can cause complications when using machine + user authentication because the first time a user authenticates, the certificate is not available until after the login process completes.


  • 7.  RE: Can a user have a certificate or does only a machine have a certificate?

    Posted Jul 16, 2017 05:39 PM



  • 8.  RE: Can a user have a certificate or does only a machine have a certificate?

    EMPLOYEE
    Posted Jul 16, 2017 05:42 PM
    For the network, yes. To use a certificate to log on to the machine itself, you'd need to use a smartcard.