Re: Problem with smart card login

From: Brian Komar (bkomar_at_nospam.identit.ca)
Date: 04/19/05


Date: Mon, 18 Apr 2005 23:46:10 -0500

In article <d5d323c.0504170157.69e9af8e@posting.google.com>,
ftg@nordmaling.se says...
> Hi
>
> I have 2000 domain, with a 2003 enterprice certsrv. I have enable
> autoentrollent to the users, but if a user get a certificate and it
> works find. The user can login with it, but if the user delete the
> certificate from the smart card the user can still can log in to the
> computer the user has loggd in before he deletes the certificate.
>
> Are windows cashing som informatiion somewhere?
> I have not found som certificates on the local machine
>
>
>
> /Fredrik
>
What is the operating system used by the user. When you say that the
certificate is deleted, what process did you use to delete the
certificate (and private key???).

When the user is logging in, are they typing the PIN for the smart card?

Just need some more details.

Brian

-- 
==
Brian Komar
MVP - Windows - Security
http://www.identit.ca/blogs/brian


Relevant Pages

  • RE: Problems enabling smart card login on windows 2000
    ... Bad Certificate; ... Troubleshooting Windows 2000 PKI Deployment and Smart Card Logon ... | - Installing a Windows 2000 Server as a Domain Controller ...
    (microsoft.public.win2000.security)
  • Re: question about private certificate stored on smart card
    ... >> With Windows 2003 CA there is an option to archive user's private key. ... >> Archival is done automatically when certificate is issued. ... >> able to find out there are no smart card CSP available today that would ... > The software does allow recovery of smart card encryption certificates. ...
    (microsoft.public.win2000.security)
  • Re: Importing a Symmetric Key into the Microsoft Base Smart Card C
    ... On the Internet Accounts dialog box, click the Add button and select ... address stated in the e-mail certificate. ... account and click the Properties button. ... Outlook Express will ask you to insert your smart card. ...
    (microsoft.public.platformsdk.security)
  • Re: Re: PKI SC Logon with no UPN.
    ... "Brian Komar" wrote: ... > the certificate to ... > For details on what is required to issue smart card certs from ... > Note that the SAN must include the UPN ...
    (microsoft.public.win2000.security)
  • Disable smart card authentication on Windows2000 Professional!
    ... to disable MS smart card authentication function in my ... To enable smart card or other certificate authentication ... certificate authority for your server certificate must be ...
    (microsoft.public.win2000.security)