Discussion in 'Security Software' started by zzgfzldv, Sep 21, 2007.

    I am new to understanding certificates and I have looked at a mass of
    information on the web, but I am still not clear as to what I need to

    We have created a web application, which is to be accessed by our
    clients (about 10). We have purchased a server certificate from
    Verisign so the website is accessed over SSL. The clients need to
    login to the website using userid/password etc, however we would like
    a further security mechanism such as a client certificate.

    The idea would be to issue each client with a certificate on a CD
    which would be unique to that client, which they would then install.

    I have created a CA server which is seperate from our web server. I
    installed this as a standalone Root CA. I can then browse to
    http://caserver/certserv and request an advanced certificate which I
    complete with the clients details. I can then import this certificate
    into Internet Explorer certificates under the Personal tab.

    I am sure there is more I need to do, but am not sure where to start.
    I have heard about Chains, and using a company certificate to sign
    your own, but am not sure how to go about doing this.

    Any help would be appreciated.

    Many thanks in advance.
