Re: Smartcard offline login and XP laptops



One correction.
When working with Windows XP, the client can only cache one of:
- username/password logon
- smart card logon
Whatever one they did last when connected to the network will be cached.
If they are using Vista, then both the username/password and smartcard logon will be cached, allowing either authentication method when not connected to the network (as long as they logged on at least once while connected with each authentication method.
Brian

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message news:O841NubTJHA.6028@xxxxxxxxxxxxxxxxxxxxxxx
From: "Tariq" <Tariq@xxxxxxxxxxxxxxxxxxxxxxxxx>

| Can anyone provide me with some guidance and recommendations on the use of
| smartcards and offline login with Windows XP based client laptops?

| My organization currently issues XP based laptops attached to our corporate
| domain to our global user base. The current image/configuration uses cached
| login's to enable offline login using a user's AD credentials to the local
| machine.

| I'm in the midst of deploying a Windows 2008 based PKI environment to
| support smartcard based logins. We're going to be deploying smartcards with
| mandatory login to a small number of laptop users, but I'd like to see that
| they have the same functionality as our non-smartcard based users in that
| they should be able to log in to their laptops while disconnected from our
| corporate network. I've seen some references online to the effect that the
| smartcard login is also "cached" to enable this ability, but I'd like to be
| able to reference to some definitive documentation to that effect.

| Thanks,

| Tariq

If the user uses cryptographic logons when connected to the Domain then their credentilas
from their smart card will also be cached. When off lan and not connected to the Domain
controller they will still be able to use their respective Smart Cards to logon to their
notebook susing their caced credentials.

Is you not enforcing cryptographic logons and the user can logon with a Domain Name and
password as well as by using their Smart Card then you must make sure that the user does
BOTH kinds of logons prior to going off lan. This will ensure that all their credentials
will be cached and they can login with their Domain Name and password as well as by using
their Smart Card when off lan.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



.



Relevant Pages

  • Re: WinLogon with smart card
    ... not a true smart card but simply a "Smarter" Memory Card. ... Without the kerberos extension you can not use a Certificate for Logon (i.e. ... perform a Pseudo Smartcard logon. ...
    (microsoft.public.platformsdk.security)
  • Re: Problems loggin in Windows Vista with a smart card enabled acc
    ... account configured for smart card logon in Windows Vista. ... in the paper published by Microsoft that is titled 'Windows Vista Smart Card ... The provider may be returning a "no PIN prompt" flag and the SC ... press CTRL + ALT + DEL to be able to log on with a different account. ...
    (microsoft.public.platformsdk.security)
  • Re: Problems loggin in Windows Vista with a smart card enabled acc
    ... account configured for smart card logon in Windows Vista. ... in the paper published by Microsoft that is titled 'Windows Vista Smart Card ... The provider may be returning a "no PIN prompt" flag and the SC ... The second tile says "other user" ...
    (microsoft.public.platformsdk.security)
  • Re: Local system and user account - registry
    ... If their account is set to to use a Smart Card then they are forced to use a Smart ... Either they logon as "User Name" or with a Smart Card. ... Since you're checking this registry value in your script I'm assuming ... or a logon with a UPN will both cause your script to ...
    (microsoft.public.security)
  • Re: Problems loggin in Windows Vista with a smart card enabled acc
    ... account configured for smart card logon in Windows Vista. ... in the paper published by Microsoft that is titled 'Windows Vista Smart Card ... press CTRL + ALT + DEL to be able to log on with a different account. ... In the hint I write the account I want to log on to: ...
    (microsoft.public.platformsdk.security)

Quantcast