cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
857
Views
0
Helpful
4
Replies

Client certificate question

octroncisco
Level 1
Level 1

Hello,

I am novice with certs and I have a question. I want to implement EAP-TLS in a WPA deployment and I have a question about the client-side certificate.

When I install a client certificate in a machine for a specific user, is this certificate only valid for this machine and this user? Or can I export this certificate and use it in another machine but the same user?

Thanks in advance,

2 Accepted Solutions

Accepted Solutions

Scott Fella
Hall of Fame
Hall of Fame

Here is a good link that explains the Microsoft certificate requirements.

http://support.microsoft.com/kb/814394

-Scott
*** Please rate helpful posts ***

View solution in original post

From my experience, you can copy the certificate to another computer (assuming a modern OS).  There are two problems with this, though:

1 - You must be able to export the entire certificate, including the private key, to be able to use the certificate on another machine.  Most PKI implementations prohibit/disable this.

2 - If you can export the certificate, including the private key, then you are risking the loss of integrity of your PKI.  Someone else can get that cert with the private key and impersonate the user.

View solution in original post

4 Replies 4

Scott Fella
Hall of Fame
Hall of Fame

Here is a good link that explains the Microsoft certificate requirements.

http://support.microsoft.com/kb/814394

-Scott
*** Please rate helpful posts ***

Thank you very much, it's a very useful link.

From my experience, you can copy the certificate to another computer (assuming a modern OS).  There are two problems with this, though:

1 - You must be able to export the entire certificate, including the private key, to be able to use the certificate on another machine.  Most PKI implementations prohibit/disable this.

2 - If you can export the certificate, including the private key, then you are risking the loss of integrity of your PKI.  Someone else can get that cert with the private key and impersonate the user.

Thank you very much for the info.

Review Cisco Networking for a $25 gift card