Vaibhav Singh

Blog - vaibhavsingh.com

VPN Authentication – User vs Machine Certificate?

For a remote-access VPN service – to identify whether a genuine authorized corporate asset is connecting, we must check certain parameters to identify the end user machine. Best way would be to utilize digital certificates.

Which is better – computer or user certificate?

Machine CertificatesUser Certificates
Uniquely identify a machine on the domainUniquely identify a user on the domain
Has the FQDN of the workstationHas the DN of the user
Used for identity, authentication and authorization onlyHas expanded abilities such as email encryption, code signing
Vendor recommended, a standard approach for VPN authenticationNeeds a custom template – e.g to set private key as non-exportable
Non-admin unable to access computer cert-store – added level of securityAccessible to user
Useful in “Start Before Logon” use-caseDesirable for dot1x NAC environment where shared-machines are used e.g Contact Center

Summary

Functionally both serve similar purpose for users authentication connecting to remote-access VPN. There wasn’t a major benefit identified by choosing one over the other.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top