Authentication and smart cards

Authentication and smart cards

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Authentication and smart cards Swedboy 08-25-2006
Posted by Swedboy on August 25, 2006, 12:21 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi!

I have started the deployment of smart cards in my organisation. I'm in a
test phase to see what problems will occur and I have already run into
several.
We use smart cards and smart card readers so there is no soft certificate on
the computers. We have Windows Server 2003 och Windows XP Sp2 on the
clients.
I want the users to only use the smart card and interactive logon should
only be allowed with the smart card.

Problems:

1. The users can no longer log into Outlook Webb Access, since the password
is unknown. It is set to something were long the same time I activate the
option to only allow interactive logon via smart card. Are Microsoft coming
up with a solution so OWA can authenticate the user from a smart card reader
? Is there any other solution to this problem?

2. We use smart phones. Very nice tool, but I have the same problem here.
The smartphone wants my username, password and domin name to start
synchronizing with the Exchange Server. I don't have the password. Is there
any way to have it authenticate to Exchange with my certificate?

Regards
Johan



Posted by S. Pidgorny on August 25, 2006, 9:45 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Both are known issues, and you have to implement a workaround of some sorts.
I'm not sure is OWA is going to be fixed even in Exchange 2007.

Certificate-based authentication for mobile clients is introduced with
Windows Mobile Messaging and Security Pack:

http://www.microsoft.com/windowsmobile/business/5/default.mspx

New certificate deployment procedure and probably template will be required
for those, depending on your requirements.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-



"Swedboy" <swedboyathotmail.com> wrote in message
> Hi!
>
> I have started the deployment of smart cards in my organisation. I'm in a
> test phase to see what problems will occur and I have already run into
> several.
> We use smart cards and smart card readers so there is no soft certificate
> on the computers. We have Windows Server 2003 och Windows XP Sp2 on the
> clients.
> I want the users to only use the smart card and interactive logon should
> only be allowed with the smart card.
>
> Problems:
>
> 1. The users can no longer log into Outlook Webb Access, since the
> password is unknown. It is set to something were long the same time I
> activate the option to only allow interactive logon via smart card. Are
> Microsoft coming up with a solution so OWA can authenticate the user from
> a smart card reader ? Is there any other solution to this problem?
>
> 2. We use smart phones. Very nice tool, but I have the same problem here.
> The smartphone wants my username, password and domin name to start
> synchronizing with the Exchange Server. I don't have the password. Is
> there any way to have it authenticate to Exchange with my certificate?
>
> Regards
> Johan
>



Similar ThreadsPosted
Smart Cards? August 19, 2005, 10:30 pm
smart cards - two readers February 15, 2007, 6:45 am
Verisign Smart Cards? September 27, 2007, 8:53 am
Are Microsoft developing their own smart cards? May 24, 2007, 9:08 am
Free PKI Smart Cards & CSP for Microsoft Newsgroup Participants May 14, 2007, 7:13 am
Change Admin Key in Microsoft Base CSP Smart Cards with CLM September 9, 2008, 4:04 am
Smart Card Logon and 802.1x Authentication November 27, 2007, 1:20 pm
IPSEC, Wireless Access Cards and laptops April 19, 2006, 11:54 pm
Smart Card Login + Certificate Login to AD -> Lost smart card December 15, 2005, 10:03 pm
Smart Card Login + Certificate Login to AD -> Lost smart card December 15, 2005, 10:41 pm

The site map in XML format XML site map

Contact Us | Privacy Policy