Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Limit use digital signature

Posted on 2012-04-05
6
Medium Priority
?
529 Views
Last Modified: 2012-06-27
Hi,

how can I limit the use of certificate digital signature installed in a PC with windows. I need to allow the use of certificate only for a certain web pages.

In other words,  Which kind of tools I need, to setup a limit for the users can only use the certificate to authenticate in a certain web pages

The main question is that some users have a digital signature for general purposes, and I want to limit that the users can only use the certificate digital signature that are installed into the windows certificate repository, to authenticate only in a web pages included in a list.

Regards
0
Comment
Question by:lnrivera
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 51

Expert Comment

by:ahoffmann
ID: 37815132
when you import the cert into windows certificate store, you can select for which typrs this cert can be used, i.e. web site authentication, e-mail signature and such
but IIRC you cannot restrict a cert to be used on specific websites only as windows selects automatically which cert from the store to send, it will only ask if there're more than one cert matching
0
 

Author Comment

by:lnrivera
ID: 37815283
Maybe using a third party software solutions?

Another way, I'm not sure, if a HSM can do it (But the first problem is that HSM hardware solution is too expensive)

Regards
0
 
LVL 65

Expert Comment

by:btan
ID: 37815605
Actually if you are publishing the certificates to Active Directory, we can try to leverage on GPO to enforce some form of lockdown in autoenrollment and distribution of certificates. Also using the Enterprise CA not others.
http://technet.microsoft.com/en-us/library/cc754877.aspx

I was thinking of creating a customised cert template and specifying the security permission for it as well as "Do not automatically reenroll if a duplicate certificate exists in Active Directory" can be sort of some quick restriction to user even getting the certificates.
http://technet.microsoft.com/en-us/library/cc787781(v=ws.10).aspx

But not a full proof approach as certificates in the local user profile or on the user object in Active Directory are only managed if the certificate corresponds to a certificate template in Active Directory. Foreign certificates and certificates that do not contain the template extension are not managed. This is a transparent activity that is processed asynchronously.

Adding, there are add-on management tool like Microsoft's own Certificate Lifecycle Manager which may help - yet to explore further. Just some quick links

General - http://technet.microsoft.com/en-us/library/cc708653(v=ws.10).aspx
Security practice using it - http://technet.microsoft.com/en-us/library/cc720567(v=ws.10).aspx
0
Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

 
LVL 65

Expert Comment

by:btan
ID: 37815615
On a second thought, if we have control of web server, for example IIS, the webserver can enforce what type of client certificate to use for authentication and access...some configuration to be done for one to one

http://learn.iis.net/page.aspx/478/configuring-one-to-one-client-certificate-mappings/
0
 

Accepted Solution

by:
lnrivera earned 0 total points
ID: 37844672
Finally I filter the access looking for a fingerprint of the certificate in the IP Packets
0
 

Author Closing Comment

by:lnrivera
ID: 37859747
Found workaround by myself
0

Featured Post

Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Hey fellow admins! This time, I have a little fairy tale for you. As many tales do, it starts boring and then gets pretty gory. I hope you like it. TL;DR: It is about an important security matter, you should read it if you run or administer Windows …
Will you be ready when the clock on GDPR compliance runs out? Is GDPR even something you need to worry about? Find out more about the upcoming regulation changes and download our comprehensive GDPR checklist today !
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question