Re: WinLogon adds default certificate to "MY" store. Why, and how to disable?

From: Jakub Gwozdz (gwozdziu_at_rpg.pl)
Date: 05/24/05

  • Next message: Arkady Frenkel: "Re: Hash of Public key"
    Date: Tue, 24 May 2005 10:38:44 +0200
    
    

    Hao Zhuang [MSFT] wrote:
    > certprop downloads the certificate from your smartcard to MY store so that
    > the apps that use the certificate will work (such as enabling outlook
    > sending encrypted email).
    >
    > yes you can remove the regkey entry so that certprop is not invoked. however
    > it may break the scenarios using smartcard certificates.

    Thank you very much for info.

    I've already developed tray icon tool which installs all key/certificates pair from inserted smartcard and deletes them after card removal. So I believe that outlook and other application wouldn't have any problem to use smartcard.

    It's a pity that there is no reg value like "Enabled", which can be set to zero and only way to disable CertProp is to delete whole key.

    Best regards
    Jakub Gwozdz


  • Next message: Arkady Frenkel: "Re: Hash of Public key"

    Relevant Pages

    • RE: Relative Security Provided by Cached Domain Credentials?
      ... So when a user logs on the w2k terminal using a smartcard + pin no (rather ... If it does then EFS ... profile currently logged on for the private certificate. ...
      (Focus-Microsoft)
    • Re: SmartCards
      ... Smartcards can contain many authentication id's. ... client certificates can be stored on the smartcard. ... The user must provide the PKI ... certificate. ...
      (Security-Basics)
    • Re: Setting up AD (W2K3) for SmartCard Authentication
      ... The SmartCards can log into on AD Forest, ... Looked that the article on 3rd party CA's, ... Does the certificate contain the user's UPN in the subject alternative name ... Does the DomainController's certificate contain the SmartCard Logon ...
      (microsoft.public.security)
    • Re: Key archival and smartcard CSP
      ... the first question is that does your smartcard ... CSP allow the public/private key pair to be imported into its own store? ... > - When the certificate has been issued, i get the container name and the ...
      (microsoft.public.platformsdk.security)
    • Re: Removing smartcard certificates from the Microsoft Certificate Store (possible MCS API defect)
      ... You friend comes over, plugs in his smartcard, his certificate is automatically transferred over to the Microsoft Certificate Store, he takes out his smartcard and the system is set to go. ... When a client arrives to the office the client's smartcard is inserted into the lawyer's PC and the client's certificate is transferred over to the Microsoft Certificate Store. ... The lawyer and client do their thing, client takes out his smartcard and leaves. ...
      (microsoft.public.platformsdk.security)