smartcard authentication in Linux KDC realm

From: Michal Straczynski (mstraczynski_at_o2.pl)
Date: 08/25/04


Date: 25 Aug 2004 01:18:44 -0700

Hello,
1. I would like to configure environment where users can logon to a
Kerberos realm in Linux KDC (Heimdal with PKINIT patch) from Windows
2000 workstations via smartcard logon.
  Till now I've already succesfuly tested two configurations:
1) Windows workstations authenticating to the Kerberos realm,
2) the smartcard logon from the Windows workstations to the Windows
domain.
  However when I tested the smartcard logon from a Windows
workstation to the Kerberos KDC, the workstation initiates a normal
password logon to the Linux KDC instead of smartcard logon. It seems
that
the workstation won't use Kerberos PKINIT if it isn't in a Windows
domain, am I wright?
2. If it is true than I will have to write the custom GINA logon
module that uses SC reader and authenticates users in Kerberos realm.
I wonder if I could use MS Kerberos SSP/AP, for authentication in this
scenario? Or does MS Kerberos PKINIT implementation require Active
Directory?
Regards,
Michal Straczynski



Relevant Pages

  • RE: default domain display at logon
    ... the new domain, Windows XP does not. ... ADMT cannot change the default logon domain of the workstations. ...
    (microsoft.public.windows.server.migration)
  • Re: Event ID: 537 Kerberos
    ... The strange thing is that the event ID 537 comes up on the member server ... This makes me think that the windows 2000 DC accepts the kerberos ... I'm thinking that the Windows 2003 kerberos is not the same as the windows ... >> Logon Failure: ...
    (microsoft.public.windows.server.general)
  • another interactive logon problem
    ... Running SBS2003, 1 server running windows, exchange, IIS, file and print, ... 5 workstations. ... you to logon interactively" message. ...
    (microsoft.public.windows.server.sbs)
  • Re: How to activate "Num Lock"?
    ... For each logon, and after when the session is opened, the numeric keypad is disactivated! ... Workstations run Windows XP Pro SP3, on a NT Domain managed by a Windows Server 2003R2 SP2. ... WinXP will remember the NumLock's last state, meaning that if you log out with the NumLock on, it will automatically turn on the next time you log in; If you log out with the NumLock off, it will be off the next time you log in. ...
    (microsoft.public.windowsxp.general)
  • Re: How to activate "Num Lock"?
    ... For each logon, and after when the session is ... Windows Server 2003R2 SP2. ... Do I have to change something localy on the workstations or on the ... "How to Set the NUM LOCK State at Logon in Windows XP" ...
    (microsoft.public.windowsxp.general)