| ▲ | amluto 2 hours ago | ||||||||||||||||
I've never used one of the DoD smartcards, but I can certainly imagine the DoD wanting a user of one of these smartcards to be able to use it with a COTS client device to authenticate themselves. | |||||||||||||||||
| ▲ | mpyne an hour ago | parent [-] | ||||||||||||||||
Sure, people do that all the time. After they run "InstallRoot" to install DoD root certs on their COTS device, that is. I'm honestly not sure any major browser will allow you to use a client smartcard without having the smartcard's certificate chain to the trust store used by the browser so this part seems unavoidable. FWIW I just tested it and yes you can run a web server using a commercial server cert that enforces client PKI tied to the client having a DoD PKI cert. It works just fine. | |||||||||||||||||
| |||||||||||||||||