Link to home
Start Free TrialLog in
Avatar of the_b1ackfox
the_b1ackfoxFlag for United States of America

asked on

Cisco ASA SSL VPN security

Is there a way to lock down the certificate issued from the ASA to a specific host?   I love the ease of a VPN client, but an worried that the certificate can be copied and put on other systems.


Fox
Avatar of Pete Long
Pete Long
Flag of United Kingdom of Great Britain and Northern Ireland image

Are you authenticating based on SSL, or do you simply have a publicly signed cert on the ASA?

If its the former I wrote this a while ago;
Why Securing Your VPN Solution With Computer Certificates ‘Only’ Is A BAD Idea
Avatar of the_b1ackfox

ASKER

Your blog validates the concern.  So whats the next step to bringing this to a secure offering?
ASKER CERTIFIED SOLUTION
Avatar of the_b1ackfox
the_b1ackfox
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
>> So whats the next step to bringing this to a secure offering?

Use 2 Factor Authentication ?

Using certs (something you have) and a password (something you know)

</p>