Skip to main content
pcguy
New Member
September 29, 2020
Solved

SSL VPN with Client Certificate Authentication

  • September 29, 2020
  • 2 replies
  • 5378 views

Hi guys,

 

Our company is implementing SSL VPN with Client Certificate which will authenticate by our Fortigate.

However, many of our company users are not able to login with client certificate. Users with administrator rights have no issue to login.

 

The reason is due to these users do not have administrator rights or read permission to access the client certificate's private key. In Windows Group policy, as I know there is no such settings to grant certain read permission to Certificate's private key.

 

Anyone has any experience or encountered the same challenges while do not want to grant administrator rights to normal users?

 

Thanks!

 
Best answer by pcguy

We found out there is an option in EMS "Allow Non-Administrators to Use Machine Certificates" which totally solved our issue.

 

Hope can help someone have the same issue.

 

2 replies

boneyard
Valued Contributor
October 4, 2020

client certificates in the current user store should be accessable without admin rights

pcguy
pcguyAuthor
New Member
October 6, 2020

boneyard wrote:

client certificates in the current user store should be accessable without admin rights

We are using computer cert as client cert which only accessible by admin rights.

boneyard
Valued Contributor
October 10, 2020

if you can't change that setup then it wont be possible for regular users.

pcguy
pcguyAuthorAnswer
New Member
October 15, 2020

We found out there is an option in EMS "Allow Non-Administrators to Use Machine Certificates" which totally solved our issue.

 

Hope can help someone have the same issue.