Re: PKI SC Logon with no UPN.

From: Paul Adare (padare_at_newsguy.com)
Date: 05/22/05


Date: Sun, 22 May 2005 05:29:00 -0400

In article <127719B7-11C8-4843-A408-11B3A14FF1BA@microsoft.com>, in the
microsoft.public.win2000.security news group, =?Utf-8?B?TGF2aWUgQkI=?=
<LavieBB@discussions.microsoft.com> says...

> I want to enable a Smart Card Logon using a Certificate issued by 3rd party.
> one way which is the easy way is to add that CA in to directory - but this
> option would require the certificate to contain a UPN.
>
> My Q is :
> how can i allow a logon based on 3rd Party Certificate of user
> authentication (probably Client Authentication), what does it require - if
> possiable ? and how can it be restricted.

If you can't get whomever is providing you with the certificate to add
the UPN to the SAN, then you're not going to be able to use those
certificates for smart card logon. The UPN in the SAN is required.

-- 
Paul Adare
MVP - Windows - Virtual Machine
http://www.identit.ca/blogs/paul/
Scientists were excited this week at having isolated a brief sound which 
occurred immediately before the Big Bang.
Apparently, the sound was, "uh oh".


Relevant Pages

  • Re: How to renew a certificate programmicaly
    ... Name 2 extension must contain a UPN entry, ... Please notice that the application> policy restriction is "Enrollment Agent" and that the "old certificate" does> not have this application policy. ... > I cannot see this template in the MMC snapin, I guess it is because it has> "X number of authotized signatures" and "Subject details supply in request". ...
    (microsoft.public.platformsdk.security)
  • Re: preauth failed KRB5KDC_ERR_CLIENT_NAME_MISMATCH
    ... the KDC requires that the client certificate has the ... = true" in the KDC's config, it will also accept a Microsoft UPN SAN. ... this is what i am doing and my config files are shown. ...
    (comp.protocols.kerberos)
  • Re: How to renew a certificate programmicaly
    ... The UPN check cannot be disabled. ... an existing certificate holder to renew the certificate without an RA ... > vi) The CA determine target template by looking on the old certificate,> and that this template allows renewal. ... A user arrives to an enrollment officer, that have a smartcard with> "Certificate Enrollment Agent"> 2. ...
    (microsoft.public.platformsdk.security)
  • Re: How to renew a certificate programmicaly
    ... To renew a certificate via an Enterprise CA, and to use the template feature ... UPN matches the old certificate UPN. ... >>> Yes I think the request is correctly signed, since it is working if I ...
    (microsoft.public.platformsdk.security)
  • Re: PKI SC Logon with no UPN.
    ... you must have the UPN in the certificate ... for smart card logon. ... (The client authentication OID) ...
    (microsoft.public.win2000.security)