Question Client certificates

Deebs

Chief Arsewipe
Staff member
Moderator
FH Subscriber
Joined
Dec 11, 1997
Messages
9,076,937
How many of you use client certificates for authentication? Been working on a project at work and have got myself involved heavily into smartcards and client certificates (used to authenticate amongst other things). In other words, PKI.
 

Vae

Resident Freddy
Joined
Dec 23, 2003
Messages
1,181
How many of you use client certificates for authentication? Been working on a project at work and have got myself involved heavily into smartcards and client certificates (used to authenticate amongst other things). In other words, PKI.

If it's what I think it is (A digital certificate held locally) then I use them with Bank of Ireland and the Irish revenue at work. Nothing in the UK though.
 

Deebs

Chief Arsewipe
Staff member
Moderator
FH Subscriber
Joined
Dec 11, 1997
Messages
9,076,937
If it's what I think it is (A digital certificate held locally) then I use them with Bank of Ireland and the Irish revenue at work. Nothing in the UK though.
It is :) Go sign up at cacert.org....
 

Vae

Resident Freddy
Joined
Dec 23, 2003
Messages
1,181
It is :) Go sign up at cacert.org....
Why? Seriously I'm not too au fait with the idea. I can see how it works with Bank of Ireland and the Irish Revenue where I had to generate a digital certificate as part of the setup procedure (e.g. random key presses and mouse clicks) but with no requirement for that with any UK sites what does it do...?
 

soze

I am a FH squatter
Joined
Jan 22, 2004
Messages
12,508
We have one customer with them but they cost a lot to set up the Microsoft way. You need 5 CA's. I am very neutral with them tbh 95% of our customers have no need for them.
 

Deebs

Chief Arsewipe
Staff member
Moderator
FH Subscriber
Joined
Dec 11, 1997
Messages
9,076,937
eh? cacert.org do not charge any money...
 

GReaper

Part of the furniture
Joined
Dec 22, 2003
Messages
1,983
Only time I ever use a client certificate is to renew my SSL certificates from StartSSL. Apart from that, I've never had a reason to use them at all.
 

Cadelin

Resident Freddy
Joined
Feb 18, 2004
Messages
2,514
Only time I ever use a client certificate is to renew my SSL certificates from StartSSL. Apart from that, I've never had a reason to use them at all.

Dumb question: Whats the difference between a client certificate and a personal certificate?
 

GReaper

Part of the furniture
Joined
Dec 22, 2003
Messages
1,983
A client certificate authenticates you to the server in a similar way to a server certificate. A server certificate is signed by a 3rd party to say that "www.example.org" is really the server you're connecting to, a client certificate is also signed by a 3rd party to tell the server that "Joe Bloggs" is the real Joe Bloggs.

Most sites won't bother with any of this as it's usually easier to ask for a username and password as security.
 

Cadelin

Resident Freddy
Joined
Feb 18, 2004
Messages
2,514
A client certificate authenticates you to the server in a similar way to a server certificate. A server certificate is signed by a 3rd party to say that "www.example.org" is really the server you're connecting to, a client certificate is also signed by a 3rd party to tell the server that "Joe Bloggs" is the real Joe Bloggs.

Most sites won't bother with any of this as it's usually easier to ask for a username and password as security.


In that case, personal and client certificates are the same thing. Which means I use them all the time. In my browser I have my personal certificate which was signed by the UK E-science CA (https://ca.grid-support.ac.uk/cgi-bin/pub/pki?cmd=getStaticPage&name=index) and I use it for a lot of my CERN work.
 

GReaper

Part of the furniture
Joined
Dec 22, 2003
Messages
1,983
Ah, didn't fully read your question - hence the explaining a client and server certificate!
 

Users who are viewing this thread

Top Bottom