Click here to get back home

Cannot Logon using Smartcard

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Cannot Logon using Smartcard muhsinak 10-28-2005
Posted by muhsinak on October 28, 2005, 11:55 pm
Please log in for more thread options
Hi all,

I am trying to setup smart card logon in Windows 2003 domain. Setup
Offline Rootca, and Enterprise Sub CA for certificate enrollment.
Assigned DC certificates. Able to write certificate and public/private
key pair to Smartcard. I am using Gemsafe libraries 4.2. Able to
access the certifcates for email encryption and signing from the smart
card. But only smartcard logon certifcates does not work.

when I try to logon I am getting error, event id 11 on application log,
saying an error occured while decrypting a message using the smartcard
inserted: Access denied.

Enabled Logon auditing, event id 537 on security log with status code
0xc000006d substatus code: 0xc0000321

I am using GemXpress Pro cards.

Any hints.........

Thanks
Ahmad Muhsin A.K.



Posted by Daryl Lufor on November 2, 2005, 10:25 pm
Please log in for more thread options
Hi
i am Daryl Lufor from mauritius

i am not using Smart Cards in my organization but according to what i have
learned during my MCSE smart card require EAP/TLS as protocol of security to
authenticate through keberos in Active directory

try to look a little bit at this side the EAP/ TLS

cheers
Daryl




> Hi all,
>
> I am trying to setup smart card logon in Windows 2003 domain. Setup
> Offline Rootca, and Enterprise Sub CA for certificate enrollment.
> Assigned DC certificates. Able to write certificate and public/private
> key pair to Smartcard. I am using Gemsafe libraries 4.2. Able to
> access the certifcates for email encryption and signing from the smart
> card. But only smartcard logon certifcates does not work.
>
> when I try to logon I am getting error, event id 11 on application log,
> saying an error occured while decrypting a message using the smartcard
> inserted: Access denied.
>
> Enabled Logon auditing, event id 537 on security log with status code
> 0xc000006d substatus code: 0xc0000321
>
> I am using GemXpress Pro cards.
>
> Any hints.........
>
> Thanks
> Ahmad Muhsin A.K.
>




Similar ThreadsPosted
Multiple Certs on Smartcard and Windows Smartcard Logon July 8, 2005, 8:01 am
Smartcard logon with third-party CA without MS CA May 13, 2006, 2:01 am
Smartcard logon and certification authority December 2, 2005, 4:29 am
AD GetObject fails in ASP page when using smartcard logon June 14, 2005, 6:07 pm
userCertificate in user's entry for smartcard logon February 25, 2007, 1:47 pm
Smartcard / NTFS Encryption May 13, 2007, 7:37 pm
Smartcard for multi-factor authentication March 2, 2006, 10:01 am
IAS + user smartcard + workstation certificate July 6, 2007, 9:48 am
There are currently no logon servers available to service the logon request - how to fix this error? i get it when trying to access a share one hop away. April 12, 2007, 6:03 pm
Workstations showing logon failures by users can still logon? November 27, 2007, 6:56 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap