4 ms·
you never move a cert, just like you never move an ssh key. you simply generate a new one and add it to their auth, any time the user is using a new browser the
by throwaway64 15y ago
you never move a cert, just like you never move an ssh key. you simply generate a new one and add it to their auth, any time the user is using a new browser they have to go through extra authentication steps, and get issued a new cert for their browser (or not, on a public machine).
- ww520 15y agoUsually what are the ways to authenticate the user when generating a new cert? A user moving to a new browser has to identify himself as the real user, thus requiring some sort of authentication. It's a chicken and egg thing.
- alexchamberlain 15y agoAutomated call? Automated text?
- throwaway64 15y agoan emailed code is usually the prefered method, however depending on your needs a text message or account details may work
- ajross 15y ago"any time the user is using a new browser they have to go through extra authentication steps" And one wonders why no one wants to do this stuff. This is poor analysis. You're arguing from an incomplete position. The choice isn't between "some security" (mobile certs) and "best security" (forced reauthentication). It's between "bad security" (multiple accounts with shared passwords) and "better security" (single cloud account with escrowed access to the cert).
- mauriciob 15y agoThe two major public banks in Brazil require clients to provide additional information if you are on a "new" PC. One of them asks personal information (id numbers, etc), the other sends an SMS to your cell phone and you enter that number (a very good two-factor auth). They don't use client certs, though, and I have no knowledge on the private banks.
- 7952 15y agoSo in this case an SSL cert is just like a cookie. Why not just use two factor (SMS or an app) when there is no cookie?