My clients are Firefox and Chrome browsers, and these both install pkcs#12 client certificates. The certs are encrypted with a pre-shared key, allowing the .p12 files to be transmitted insecurely. However, as always, the management of pre-shared keys is left to the administrator and user to deal with.
|