Can anybody point me to resources on how to use a machine's Trusted Platform Module (TPM) chip to generate and securely store a machine certificate issues by a private certificate authority?
Marking "soft" machine certificates as non-exportable is not an adequately secure solution for this requirement. Essentially we want a PC that has a "built in" Smard Card chip. While this is certainly not impossible to defeat, it should be substantially harder than a OS managed soft cert.
Start Free Trial