Smart Card Certificate Logon and Smart Card Wireless EAP-TLS

From: erha (rudy_at_guardmydata.com)
Date: 05/19/05


Date: Thu, 19 May 2005 09:39:11 +0800

Hi all,

I have post this problem before. Since there is no reply, I will try to
re-phrase my problem.

Here is the question:

Is there anybody out there succesfully implement Smart Card Certificate
Logon and Smart Card Wireless EAP-TLS together ?

The Wireless EAP-TLS do not allow 'Smart Card Logon' on the Extended Key
Usage.
When Smart Card Logon appears on the Certificate EKU, the Wireless EAP-TLS
will failed.

So I assume we cannot use the same Certificate for the Certificate Logon and
Wireless EAP-TLS.
And I can create two different certificates for this two process.

BUT here is the problem ....

Both Smart Card Certificate Logon and Smart Card Wireless EAP-TLS call my
CSP to query for default container.

Since now I used two different certificates for this two process, how can I
know which certificate I shall used when there is a query for default
continer ?
If I used the Certificate with 'Smart Card Logon' on the EKU, the Wireless
EAP-TLS will failed.
If I used the Certificate without 'Smart Card Logon' on the EKU, the
Certificate Logon will failed.

Can anybody from Microsoft clarify this ?
Have Microsoft test this scenario before ?

Thanks for any help.....

Rudy



Relevant Pages

  • Re: Offline Smart Card Logon
    ... So smart card logon would only work as long the notebooks have a vaild, ... If the CRL has expired, ... > For successful smart card logon, a valid CRL (certificate revocation list) ...
    (microsoft.public.windows.server.security)
  • LSALogonUser and smart cards....
    ... I have the following question concerning smart card logon on windows station. ... we query from a smart card (or any other certificate store). ...
    (microsoft.public.win32.programmer.networks)
  • Re: multiple certificates on a smartcard?
    ... the certificate that is used for smart card logon must ... "Secure E-mail" certificate is in first slot, ...
    (microsoft.public.windows.server.security)
  • Re: Offline Smart Card Logon
    ... >>> So smart card logon would only work as long the notebooks have a vaild, ... >>> expired CRL in their cache. ... >>>> For successful smart card logon, a valid CRL (certificate revocation ...
    (microsoft.public.windows.server.security)
  • RE: Problems enabling smart card login on windows 2000
    ... Bad Certificate; ... Troubleshooting Windows 2000 PKI Deployment and Smart Card Logon ... | - Installing a Windows 2000 Server as a Domain Controller ...
    (microsoft.public.win2000.security)