I am attempting to secure one of our internal IIS7 servers using this Client Certificate stuff and I've come across a few questions / issues.
1. I have successfully generated a client certificate on our CA for a domain user. Which format do I export this as in order to install it onto the client machine? e.g. do I need the private key?
2. I want to make Client Certificates a requirement when a user logs on to the website. How do I setup mapping to the domain account? I can see how to enable One-to-One mapping but this seems to require me to know and enter the user's password!
3. What are the actual benefits of using Client Certificate Mapping?
Many thanks,
Chris