We are considering using digital certs to verify that the machine connecting to our VPN service is in fact a company-owned machine. So one of my co-workers here mentioned that for a knowledgable user (and our users are for the most part CompSci PhD's) it would be trivial to copy the cert keys to another non-company-owned system that they want to use. My question is (and I've searched on Serverfault first :) is there some way to prevent the user from copying (exporting) the keypairs over to another machine? Or make the copied cert invalid if they do so? We in IT plan to be the ones installing the certs on the machines, but our users do need to have admin access to their machines to do their work. As well, the user's machines run a mix of Windows, Mac OS X and Linux OS's.
Thanks in advance for any answers provided...