Anyconnect Client and Microsoft Windows 10 TPM-stored certificates
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-07-2021 12:48 PM
Hi,
I would like to know if the latest version of Cisco Anyconnect Client (at the time of this writing - 4.10) is capable to use TPN-stored Certificates under a MS Windows 10 (Enterprise) OS.
If so, could you please point out to Technical Dokumentation describing in more detail possible implementation scenarios ?
Thank you.
- Labels:
-
AnyConnect
-
VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-08-2021 12:43 AM
Hi @carlo.taddei1,
Yes, AnyConnect is capable of using TPM-stored certificate. I had deployments back in the days (I believe v4.4 was even current version), where we were using machine certificates stored in TPM for MFA VPN (certificate + AD credentials). AnyConnect is invoking OS to communicate to TPM, so it doesn't communicate directly with it, thus making it compatible with all hardware. ONly thing you do is to instruct AnyConnect to use machine credential store (haven't had usecase with user certs).
BR,
Milos
