Re: Smart card authentication with AcquireCredentialsHandle()?

From: Eric Perlin [MS] (ericperl_at_online.microsoft.com)
Date: 10/15/05

  • Next message: Johnny Liu: "RE: GINA - exception in winlogon"
    Date: Sat, 15 Oct 2005 14:12:01 -0700
    
    

    You should be able to pass the output of the CredUI API as in the password
    case.

    -- 
    Eric Perlin [MS]
    This posting is provided "AS IS" with no warranties, and confers no rights.
    ---
    "Deepak" <Deepak@discussions.microsoft.com> wrote in message 
    news:34CB3E97-551C-4F5F-B5D1-187221671DD0@microsoft.com...
    > In an application that is being developed, the user is re-authenticated by
    > calling AcquireCredentialsHandle() and passing the pricipal name and 
    > password
    > obtained through custom UI (or using CredUIPromptforCredentials()) . 
    > However,
    > when the system is configured to use smart card,  the user should be 
    > prompted
    > for PIN (as it is in GINA). However, it is not clear as to how to use the 
    > PIN
    > to authenticate the user and obtain the credentials/token from the Domain
    > controller. Ideally, the AcquireCredentialsHandle() (or some other
    > function/API ) should be able to pass the PIN to the Kerberos Security
    > Provider which in turn use the PIN and obtain the certificate from the 
    > smart
    > card, sign the certificate using the private key on the card and send the
    > Kerberos AS request to obtain the tickets.
    > Can soem one provide pointers to the API(s) and/or indicate what are the
    > steps to authenticate (other than calling SCard APIs) ?
    >
    > Thanks,
    > Deepak 
    

  • Next message: Johnny Liu: "RE: GINA - exception in winlogon"

    Relevant Pages

    • Re: SDS PROM-100 software
      ... 2708 EPROM and to consistently read the content of another used 2708 ... card which worked great with Dave Dunfield's RAMless ROM monitor ... socket) with the IA 1010B the 2708 simulator has been a disaster. ... First the original IA 1010B used a weird and probably damaged 24 pin ...
      (comp.os.cpm)
    • Re: HELP, Vulnerability in Debit PIN Encryption security, possibly
      ... > not the case where PIN encryption had to be ... > derived from the card number because the card PIN was checked at the ... It is unlikely that the banks should have been able to hide such ... Smartcard terminals are used in environments over which the ...
      (sci.crypt)
    • Re: smart card versus credit card
      ... fraud must be low due to card fraud going unreported. ... >> me one good reason for wanting a PIN with a credit card? ...
      (sci.crypt)
    • Re: smart card versus credit card
      ... > That's why I was complaining that if the banks want to place more trust ... > in the PIN verification process they ... Own Plastic Savings Cards, PO Card Acoount Cards, Store Cards to name ... implemented the Chip and sPIN System. ...
      (sci.crypt)
    • Re: smart card versus credit card
      ... Retailers will presumably have to ... > decide for themselves whether to accept a card with a magstripe and no ... > he has not safeguarded his PIN adequately ... ... >> Can you see UK retailers offering this added security measure ...
      (sci.crypt)