Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Client Side Authentication Internet Explorer

Posted on 2004-09-07
9
Medium Priority
?
189 Views
Last Modified: 2010-05-18
Hi,

I am looking to implement a more advanced secure authentication of users who will have access to our internal business web systems.

We are using sessions, htaccess restricted IP and we also want to restrict the access unless the pc has the client side authentication.  A lot of banks use this method and the certificate is installed in the "Tools", "Internet Options", "Content", "Certificates".  

This will heighten the security of our system and who has access.

Can anyone help?

Thanks
0
Comment
Question by:mdmarkbowman
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
9 Comments
 
LVL 51

Expert Comment

by:ahoffmann
ID: 11999605
are you talking about "SSL Client Certificates"?
0
 

Author Comment

by:mdmarkbowman
ID: 12002212
I think they may be called this??  Yeah they are the certificates that are issued by a company/organistion.  So for example: if i don't have the issued certificate installed on the pc i work from I could not acces my systems.

I had to download one to get to our Business Internet Banking.  So our Internet banking can only be accessed from my computer at home and know where else.

Does this help?
0
 
LVL 51

Expert Comment

by:ahoffmann
ID: 12007586
ok, you want client certs, and what is your question about?
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 

Author Comment

by:mdmarkbowman
ID: 12008673
Thanks for getting back to me.  Well I just want to know about the process involved in getting this kind of authentication implemented.  I kinda made the assumption that over the past day or two from looking on the web that you buy the client certs from some (CA).  

But after signing up on Business Internet Banking with my bank it required that I downloaded the Digital ID from the banks server and install it.  Then it allows me to access the internet banking site.

We use a Linux Server running apache.  

Thanks

Mark
0
 
LVL 51

Expert Comment

by:ahoffmann
ID: 12008725
if you own the server you can make your own certs (don't need to buy them) and distribute them to your clients, thats called a PKI (public key infrastructure)
if you're client you have to use the cert provided by the owner of the server and install it into your browser
0
 

Author Comment

by:mdmarkbowman
ID: 12008858
Yes its a dedicated server that we lease.  So I take it we can generate as many as we want or do we just create one and its for the domain specifically.  So essentially we generate a certificate for each login/user or we generate on cert and everyone uses the same one.  Sorry but I am very naive about this subject/programming at times?

Help is appreciated!
0
 
LVL 51

Accepted Solution

by:
ahoffmann earned 1000 total points
ID: 12010256
client certs are unique for each user, each user with its own cert (hence PKI, see above)
while you have one unique cert for your server
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

What's worse than having your data encrypted by ransomware? Getting attacked by a so-called "wiper," which simply destroys the data and offers you no hope of ever seeing it again.
Hey fellow admins! This time, I have a little fairy tale for you. As many tales do, it starts boring and then gets pretty gory. I hope you like it. TL;DR: It is about an important security matter, you should read it if you run or administer Windows …
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question