5 ms·
Yep, client certs installed on a device with verified boot and an account authenticated via 2FA would be a good start.
by mdwrigh2 11y ago
Yep, client certs installed on a device with verified boot and an account authenticated via 2FA would be a good start.
- lukeschlather 11y agoIf you do it right (store the cert in a TPM) the device itself actually is a second factor so you don't need anything other than the device.
- voltagex_ 11y agoWouldn't that require a browser plugin to login with?
- giovannibajo1 11y agoYou can have a SSO server that requires a TLS client certificate signed by your own internal CA, or you could put it behind a VPN authenticated with the certificate. Either way, with no custom software, you get device and use authentication.