So I had a requirement on a VPN server I was setting up not long ago. This requirement was that only a "smartcard logon" cert would be permitted for EAP access into my VPN server. The normal setup information ( http://www.microsoft.com/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/sag_RRAS-Ch1_70.asp