Re: USB Authentication in TS



I think what you may have heard about is using a Smart Card to access a TS session. Smart Cards are normally available as a card like a credit card, but they are also sold as a USB dongle that combines the smart card chip and the reader in one small unit.

To use these, you'd need to understand enough about PKI to deploy a smart card solution, which is not trivial. This is a good article to look at, though, about the interaction between TS and Smart Cards:

http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/8d04b016-1018-4cf0-bf35-3268d36d6e4b.mspx

If that's not what you were thinking about, I am not aware of any other USB logon for terminal services, certainly nothing endorsed or supported by Microsoft.

Byron Hynes
Windows Server
Microsoft Corporation

http://spaces.msn.com/members/byronphynes

We are looking to allow our clients access to a terminal server to use
a custom application. We want to add security to the login process
through the use of a USB key. I am leery about this solution because I
am not exactly sure how the terminal services session will read the
key prior to allowing the terminal session to begin. Could someone
please help me understand if this is even possible and if so how it
works? Also, any recommended companies to purchase the keys from would
be a great additional help. Thank you for the clarification.



.



Relevant Pages

  • Re: Client certificates: security vulnerability?
    ... I think that´s a problem at the server side, ... will ask for a new authentication after 2 minutes, but when the smart card is ... removed the ssl session will also close. ... "Ken Schaefer" schrieb: ...
    (microsoft.public.inetserver.iis.security)
  • Re: ResourceManager connection fails (SCARD_E_NO_SERVICE)
    ... SCardEstablishContext() will ... >>the session change and will return the error if it is not ... >restart the smart card ...
    (microsoft.public.platformsdk.security)
  • Re: ResourceManager connection fails (SCARD_E_NO_SERVICE)
    ... SCardEstablishContext() will ... >the session change and will return the error if it is not ... restart the smart card ...
    (microsoft.public.platformsdk.security)
  • PKCS11 Object Handles on Token level objects
    ... card and card reader). ... Now this may work for session objects, ... don't think this will work for objects residing on the smart card. ...
    (comp.lang.java.security)
  • Re: Client certificates: security vulnerability?
    ... they are done and to always lock their PC. ... Since you are using Smart Cards, you could deploy "Smart Card removal ... Interactive logon: Smart card removal behavior ... > pull the smart card, the session stays valid, for a long time. ...
    (microsoft.public.inetserver.iis.security)

Quantcast