How to disable protected storage private key access dialog?

View: New views
2 Messages — Rating Filter:   Alert me  

How to disable protected storage private key access dialog?

by Nicola Percacciante :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hi all,

I have this problem: when I use a client certificate to access an  
https connection with IE, a popup always warn me that an application  
is trying to access private key of the certificate, and waits for my  
approval.
I have to avoid this.
My client certificate is automatically imported into IE from the ejbca  
page where I can download the certificate.
I've found this work around: I have to export certificate ( and private key ),
and then, when I reimport it I don't flag "use strong authentication".

Even if this works, it is a problem for us, cause I don't want to make private
key exportable, but in this way I cannot reimport the certificate.

My question is: In the automatic import procedure, is there a way to  
disable "strong authentication" option so that when a user downloads  
and import
the certificate it is already with the right options?

I hope I've been clear but if not, don't hesitate to contact me.

Thanks in advance
Regards,

--
Saluti
Nicola Percacciante
Digital Network s.r.l.
Via S. Lavagnini, 41 - 50129 - Firenze
P.I.: 05159080489

Tel. 055-051.75.56/7
Fax. 055-56.09.900
Cel. 348-65.40.472

--
"Le informazioni trasmesse sono da intendere solo per la persona e/o società a
cui sono indirizzate, possono contenere documenti confidenziali e/o materiale
riservato. Qualsiasi modifica, inoltro, diffusione o altro utilizzo, relativo
alle informazioni trasmesse, da parte di persone e/o società, diversi dai
destinatari indicati, è proibito ai sensi della legge 196/2003. Se Lei ha
ricevuto questa mail per errore, per favore contatti il mittente e cancelli
queste informazioni da ogni computer."


----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.


-------------------------------------------------------------------------
Sponsored by: SourceForge.net Community Choice Awards: VOTE NOW!
Studies have shown that voting for your favorite open source project,
along with a healthy diet, reduces your potential for chronic lameness
and boredom. Vote Now at http://www.sourceforge.net/community/cca08
_______________________________________________
Ejbca-develop mailing list
Ejbca-develop@...
https://lists.sourceforge.net/lists/listinfo/ejbca-develop

Re: How to disable protected storage private key access dialog?

by Johan Eklund :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hi Nicola,

when I import a certificate with IE I get only two alternatives,
(strong: confirm with password) and medium (confirm with a dialogue).

There used to be a weak:(no confirmation) alternative but it seems like
they removed it.

However: You could try enabling integrated windows authentication in
advanced settings for Internet Explorer. Microsoft claims:
"Integrated Windows authentication does not initially prompt for a user
name and password. The current Windows user information on the client is
used for Integrated Windows authentication."

Could this solve your problem?

Best regards,
Tham Wickenberg

Nicola Percacciante wrote:

> Hi all,
>
> I have this problem: when I use a client certificate to access an  
> https connection with IE, a popup always warn me that an application  
> is trying to access private key of the certificate, and waits for my  
> approval.
> I have to avoid this.
> My client certificate is automatically imported into IE from the ejbca  
> page where I can download the certificate.
> I've found this work around: I have to export certificate ( and private key ),
> and then, when I reimport it I don't flag "use strong authentication".
>
> Even if this works, it is a problem for us, cause I don't want to make private
> key exportable, but in this way I cannot reimport the certificate.
>
> My question is: In the automatic import procedure, is there a way to  
> disable "strong authentication" option so that when a user downloads  
> and import
> the certificate it is already with the right options?
>
> I hope I've been clear but if not, don't hesitate to contact me.
>
> Thanks in advance
> Regards,
>
>  


--
PrimeKey Solutions offers a commercial EJBCA support subscription and training for EJBCA. Please see www.primekey.se or contact info@... for more information. http://download.primekey.se/documents/ejbca_subscription.pdf http://download.primekey.se/documents/ejbca_training.pdf



-------------------------------------------------------------------------
Sponsored by: SourceForge.net Community Choice Awards: VOTE NOW!
Studies have shown that voting for your favorite open source project,
along with a healthy diet, reduces your potential for chronic lameness
and boredom. Vote Now at http://www.sourceforge.net/community/cca08
_______________________________________________
Ejbca-develop mailing list
Ejbca-develop@...
https://lists.sourceforge.net/lists/listinfo/ejbca-develop
LightInTheBox - Buy quality products at wholesale price