?
Solved

msoft certification authority

Posted on 2004-08-16
5
Medium Priority
?
251 Views
Last Modified: 2010-04-11
We are using EAP-TLS for our wireless network. And were wondering, when a user makes a request for a certificate to authenticate they have the option to mark their private keys as exportable (We're using the mSOFT certification authority). This means they can move that certificate to another machine if they want. We want to stop this from being able to happen. When they make the request, I am the one that has to issue the certificate, but from what I can see in the MCA there is no way to see if they had that option checked. Does anyone know if it's possible and/or how to disable that ability? or do we have to switch to a different certification authority that supports it?
0
Comment
Question by:SeanChapman
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 1

Expert Comment

by:mgrass
ID: 11823677
I've wondered how to do this before as well.  I've posted a question on a managed MSDN newsgroup and I'll shoot you any responses I get.

Mike
0
 
LVL 1

Author Comment

by:SeanChapman
ID: 11823751
so far I've been told that I can modify the certificate template to disallow the requester from being able to mark the keys exportable. But I'm using a windows 2000 server right now and can't find how to do it. I might be switching to a 2003 server soon, so I'm hoping its easier then.
0
 
LVL 1

Expert Comment

by:mgrass
ID: 11908078
Sorry, this took a while.  This was the answer I recieved from MS:

"You need to reconfigure the certificate template so that the private key  
option "Allow private key to be exported" is not specified. When that
option is specified in the template, the subject can export the key; when
it is not specified, they cannot. See Certificate Templates Help for more
information. "

Hope that helps.
0
 
LVL 1

Author Comment

by:SeanChapman
ID: 11914034
I figured that much out, but on our windows 2000 server I havent been able to find the option or anything to modify the certificate template. The only thing I've been able to do that works, it comment out some code in the asp page that processes the submit by form option. I just commented out the part where it checks for and creates the part of the request with the keys exportable, and that seemed to work.
0
 
LVL 1

Accepted Solution

by:
mpvbrao earned 2000 total points
ID: 11943278
0

Featured Post

Need protection from advanced malware attacks?

Look no further than WatchGuard's Total Security Suite, providing defense in depth against today's most headlining attacks like Petya 2.0 and WannaCry. Keep your organization out of the news with protection from known and unknown threats.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this blog we highlight approaches to managed security as a service.  We also look into ConnectWise’s value in aiding MSPs’ security management and indicate why critical alerting is a necessary integration.
Check out the latest tech news, community articles, and expert highlights in August's newsletter.
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question