Smart card logon & NTLM

From: Matt Porco (matt_at_virtuosic.com)
Date: 06/03/03


Date: Tue, 3 Jun 2003 17:42:48 -0400


According to
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/prodtech/smrtcard/smrtcdcb/sec1/smartc03.asp:

"Microsoft's implementation of the [Kerberos] protocol uses extensions to
enable smart card logon. This provides the twin advantages of strengthening
the authentication process and providing seamless entry into the public key
infrastructure. Smart card logon only works with Kerberos; you cannot use
NTLM, the authentication method of Windows NTŪ 4.0 and earlier versions of
Windows NT, for smart card logon."

It is my understanding that, even with Kerberos as the default
authentication protocol, Windows 2000 still uses NTLM (v2) authentiation
under some circumstances even in a pure Windows 2000 environment (for
example, when accessing resources on a standalone Windows 2000 system or
when accessing a system by IP address rather than by name). If this is the
case, then how does this work when you're using smart card logon? Will you
be prompted for a username & password when accessing these resources?

Also, if you have a Windows NT member server in a Windows 2000 domain
running in mixed mode, can users logged in via smart card logon seamlessly
access resources on the NT server, or will they be prompted for username &
password?

Thanks.

Matt Porco



Relevant Pages

  • Re: Change in ASP.Net authentication between Win2000 and Win2003
    ... > is turning on/off Kerberos is occuring. ... It control how IE deals with "Authentication: ... when you put IIS6 in a domain and have "Integrated Windows Authentication" ...
    (microsoft.public.windows.server.security)
  • Re: Change in ASP.Net authentication between Win2000 and Win2003
    ... > is turning on/off Kerberos is occuring. ... It control how IE deals with "Authentication: ... when you put IIS6 in a domain and have "Integrated Windows Authentication" ...
    (microsoft.public.inetserver.iis.security)
  • Re: Kerberos authentication NOT in AD
    ... I'm not sure where the piece of code is that gives you a high level Kerberos ... Windows to do it yourself, but I'm not an expert at this. ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... so I'm not doing any authentication as of yet (I've ...
    (microsoft.public.dotnet.security)
  • Re: Kerberos login on VMS
    ... Does the latest version of Pathworks support either Kerberos or LDAP ... NTLM authentication? ... >OpenVMS System Software Group ... Any version of Windows server more recent than Windows NT ...
    (comp.os.vms)
  • Re: Allow Integrated Windows Authentication Token to be delegated?
    ... Integrated Windows Authentication actually involves two different types of ... Kerberos is supported, natively, by ... Windows 2000 and Windows XP client machines. ... delegation you can also configure Protocol Transition, ...
    (microsoft.public.dotnet.framework.aspnet.security)