Re: Winlogon Copies Certificates from Smart Card to MY Store

From: Jakub Gwozdz (gwozdziu_at_rpg.pl)
Date: 08/27/05


Date: Sat, 27 Aug 2005 08:30:44 +0200

Magnus Erkstam napisał(a):
> It seems like Winlogon, starting from Windows XP, reads the certificates from
> an inserted Smart Card, and puts them in MY Certificate Store. Is it possible
> to disable this behaviour? (Without removing the Smart Card ATR entry in the
> Registry. We still want to use Smart Cards for Windows logon.)
>
> We already have an application moving the certificates to and from MY store
> when a Smart Card is inserted or removed, so the problem we are having is
> that winlogon overwrites the certificate we have inserted. In this way we are
> losing some extra attributes we have added. Also since Winlogon does not
> remove the certifcate when the Smart Card is removed, it might in some cases
> be left there, unusable.
>
> In earlier versions of Windows Winlogon did not have this behaviour.
>
> Best Regards,
>
> Magnus Erkstam

Yes, it is possible. Try to remove ScCertProp Notification Package from
winlogon registry keys.

Regards

Jakub Gwóźdź



Relevant Pages

  • Winlogon Copies Certificates from Smart Card to MY Store
    ... It seems like Winlogon, starting from Windows XP, reads the certificates from ... an inserted Smart Card, and puts them in MY Certificate Store. ...
    (microsoft.public.platformsdk.security)
  • Issuing secondary cert. to smart card
    ... is it possible to issue a logon or user certificate using Enterprise CA in ... Windows 2003, which is secondary on the smart card. ... have primary certificates and possibly other secondary certificates that ...
    (microsoft.public.windows.server.security)
  • Re: Data security question in MCSE 70-270 exam
    ... So if a laptop is pinched with EFS files on it and one of the password ... YOu install the certificates on a PC Smart Card that is ...
    (microsoft.public.win2000.security)
  • Re: Smart card EAP authenticarion on Windown 2003 RRAS server
    ... access policies to allow only EAP 'Smart card or other certificate' ... using their smart cards or certificates stored on their computers. ... I would like to permit access only to users who can authenticate ... There is no 'ONLY Smart card' EAP type that I could ...
    (microsoft.public.windows.server.networking)
  • Re: Where is the 2k/XP certificate store in the registry?
    ... > what you are describing is true for all certificate purposes but EFS. ... > certificates on smart card. ... >> for the private key store, ...
    (microsoft.public.windowsxp.security_admin)