Re: Smart Card Logon and 802.1x Authentication



Jan,

Thanks for the information. I'll assume our solution will work as
designed, then. If anyone else has any experience with this, please let me
know how it went.

"Jan Spooren" wrote:

Hi PIV Man,

I've read some content that indicated that a Smart Card Logon certificate
could not be used for 802.1x Authentication with the 802.1X Windows
Client.
Is this restriction still true or is this outdated information ? This is
a
tough restriction for something like a PIV Card, which as one (of four)
certificates dedicated to authentication purposes. The authentication
certificate works well for Smart Card Logon and in some environments would
need to be used for 802.1x authentication for wireless as well. That
restriction basically kills everything if you have alot of wireless going
on.

I haven't tested with the 'Smart Card Logon' certificate template, but it
would surprise me if that wouldn't work. In any case, a certificate created
with the 'Smart Card User' certificate template can be used both for smart
card logon and 802.1x authentication.

Cheers,
Jan.



.



Relevant Pages

  • Disable smart card authentication on Windows2000 Professional!
    ... to disable MS smart card authentication function in my ... To enable smart card or other certificate authentication ... certificate authority for your server certificate must be ...
    (microsoft.public.win2000.security)
  • Re: Smart Card Web Enrolment Problem
    ... >From what I understand if you are not using smart card logon for the VPN ... then the user certificate will be expected to be in the user store on the ... card logon template and in extensions - application policies remove smart ...
    (microsoft.public.windows.server.security)
  • Re: AD Authentication using smart card
    ... key to the server and the server authenticates the username, ... So i want to keep the authentication on the c# server. ... Now i want Ad Authentication using smart card. ... Decrypt the certificate present in the smart card. ...
    (microsoft.public.platformsdk.security)
  • Re: AD Authentication using smart card
    ... key to the server and the server authenticates the username, ... So i want to keep the authentication on the c# server. ... Now i want Ad Authentication using smart card. ... Decrypt the certificate present in the smart card. ...
    (microsoft.public.platformsdk.security)
  • Smart Card Web Enrolment Problem
    ... I wish to issue a client authentication certificate onto a smart card for ... EAP-TLS VPN authentication purposes. ... base) and specified the appropriate smart card CSP - I have deliberately ... chosen a template that does not include the smart card logon key usage right. ...
    (microsoft.public.windows.server.security)