Smart Card Logon and 802.1x Authentication

Smart Card Logon and 802.1x Authentication

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Smart Card Logon and 802.1x Authentication PIV Man 11-27-2007
Posted by =?Utf-8?B?UElWIE1hbg==?= on November 27, 2007, 1:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I've read some content that indicated that a Smart Card Logon certificate
could not be used for 802.1x Authentication with the 802.1X Windows Client.
Is this restriction still true or is this outdated information ? This is a
tough restriction for something like a PIV Card, which as one (of four)
certificates dedicated to authentication purposes. The authentication
certificate works well for Smart Card Logon and in some environments would
need to be used for 802.1x authentication for wireless as well. That
restriction basically kills everything if you have alot of wireless going on.

Posted by Jan Spooren on November 27, 2007, 2:34 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi PIV Man,

> I've read some content that indicated that a Smart Card Logon certificate
> could not be used for 802.1x Authentication with the 802.1X Windows
> Client.
> Is this restriction still true or is this outdated information ? This is
> a
> tough restriction for something like a PIV Card, which as one (of four)
> certificates dedicated to authentication purposes. The authentication
> certificate works well for Smart Card Logon and in some environments would
> need to be used for 802.1x authentication for wireless as well. That
> restriction basically kills everything if you have alot of wireless going
> on.

I haven't tested with the 'Smart Card Logon' certificate template, but it
would surprise me if that wouldn't work. In any case, a certificate created
with the 'Smart Card User' certificate template can be used both for smart
card logon and 802.1x authentication.

Cheers,
Jan.



Posted by =?Utf-8?B?UElWIE1hbg==?= on November 27, 2007, 9:42 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Jan,

Thanks for the information. I'll assume our solution will work as
designed, then. If anyone else has any experience with this, please let me
know how it went.

"Jan Spooren" wrote:

> Hi PIV Man,
>
> > I've read some content that indicated that a Smart Card Logon certificate
> > could not be used for 802.1x Authentication with the 802.1X Windows
> > Client.
> > Is this restriction still true or is this outdated information ? This is
> > a
> > tough restriction for something like a PIV Card, which as one (of four)
> > certificates dedicated to authentication purposes. The authentication
> > certificate works well for Smart Card Logon and in some environments would
> > need to be used for 802.1x authentication for wireless as well. That
> > restriction basically kills everything if you have alot of wireless going
> > on.
>
> I haven't tested with the 'Smart Card Logon' certificate template, but it
> would surprise me if that wouldn't work. In any case, a certificate created
> with the 'Smart Card User' certificate template can be used both for smart
> card logon and 802.1x authentication.
>
> Cheers,
> Jan.
>
>
>

Similar ThreadsPosted
Smart Card Logon July 20, 2006, 2:39 am
CRL caching and smart card logon November 28, 2005, 3:08 pm
Slow logon with smart card November 30, 2005, 1:35 pm
Smart Card Logon Error Event ID 5 October 12, 2006, 12:27 pm
Smart card logon & remote desktop November 19, 2007, 3:54 am
Smart Card based Logon & User ID and Password June 17, 2005, 10:09 am
Unable to access domain resources after smart card logon July 6, 2005, 9:14 am
No password expiration alert when smart card logon is required December 27, 2005, 1:14 pm
Smart Card Login + Certificate Login to AD -> Lost smart card December 15, 2005, 10:03 pm
Smart Card Login + Certificate Login to AD -> Lost smart card December 15, 2005, 10:41 pm

The site map in XML format XML site map

Contact Us | Privacy Policy