QuestionQ48

Security Architecture

A company migrating to a remote work model requires that company-owned devices connect to a VPN before logging in to the device itself. The VPN gateway requires that a specific key extension is deployed to the machine certificates in the internal PKI. Which of the following best explains this requirement?

Explanation

A machine certificate with a specific key usage extension (e.g., client authentication) enables the VPN client to automatically select the correct certificate for pre-logon device authentication without prompting the user. The key extension ensures the VPN gateway recognizes the certificate's purpose at the cryptographic level. This allows secure VPN tunnel establishment before user login, eliminating manual certificate selection while maintaining strong device authentication.

Community Discussion

No comments yet. Be the first to start the discussion!