Click here to get back home

Q: Change password for a smart card user

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Q: Change password for a smart card user S. Pidgorny 03-22-2006
Posted by S. Pidgorny on March 22, 2006, 6:28 am
Please log in for more thread options
Scenario: a user has forgotten their password BUT can log on to the Windows
domain with a smart card.
Is there any way to set the password _without_ knowing the previous one?

Cheers


--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-



Posted by Paul Adare on March 22, 2006, 9:44 am
Please log in for more thread options
microsoft.public.security.crypto news group, S. Pidgorny <MVP>

> Scenario: a user has forgotten their password BUT can log on to the Windows
> domain with a smart card.
> Is there any way to set the password _without_ knowing the previous one?
>

The only option would be to have an administrator reset the password.

--
Paul Adare - MVP Virtual Machines
It all began with Adam. He was the first man to tell a joke--or a lie.
How lucky Adam was. He knew when he said a good thing, nobody had said
it before. Adam was not alone in the Garden of Eden, however, and does
not deserve all the credit; much is due to Eve, the first woman, and
Satan, the first consultant." - Mark Twain

Posted by Joe Kaplan \(MVP - ADSI\) on March 22, 2006, 1:17 pm
Please log in for more thread options
You could use the fact that the user can log in with their smart card to
build a self-service password reset website that used client certificate
authentication though. This would not be too hard and is probably what I
would do. We've done similar things for use with SecurID tokens. If you
have client certificates already working to sign in to Windows, getting
certificate mapping working in IIS should be easy.

Joe K.

> microsoft.public.security.crypto news group, S. Pidgorny <MVP>
>
>> Scenario: a user has forgotten their password BUT can log on to the
>> Windows
>> domain with a smart card.
>> Is there any way to set the password _without_ knowing the previous one?
>>
>
> The only option would be to have an administrator reset the password.
>
> --
> Paul Adare - MVP Virtual Machines
> It all began with Adam. He was the first man to tell a joke--or a lie.
> How lucky Adam was. He knew when he said a good thing, nobody had said
> it before. Adam was not alone in the Garden of Eden, however, and does
> not deserve all the credit; much is due to Eve, the first woman, and
> Satan, the first consultant." - Mark Twain



Posted by Paul Adare on March 22, 2006, 4:30 pm
Please log in for more thread options
microsoft.public.security.crypto news group, Joe Kaplan (MVP - ADSI)

> You could use the fact that the user can log in with their smart card to
> build a self-service password reset website that used client certificate
> authentication though. This would not be too hard and is probably what I
> would do. We've done similar things for use with SecurID tokens. If you
> have client certificates already working to sign in to Windows, getting
> certificate mapping working in IIS should be easy.

True, I should have qualified my comment that there is nothing special
about smart card logon that would enable this with the OOB features of
the OS.

>
> > microsoft.public.security.crypto news group, S. Pidgorny <MVP>
> >
> >> Scenario: a user has forgotten their password BUT can log on to the
> >> Windows
> >> domain with a smart card.
> >> Is there any way to set the password _without_ knowing the previous one?
> >>
> >
> > The only option would be to have an administrator reset the password.
> >
> > --
> > Paul Adare - MVP Virtual Machines
> > It all began with Adam. He was the first man to tell a joke--or a lie.
> > How lucky Adam was. He knew when he said a good thing, nobody had said
> > it before. Adam was not alone in the Garden of Eden, however, and does
> > not deserve all the credit; much is due to Eve, the first woman, and
> > Satan, the first consultant." - Mark Twain
>
>
>

--
Paul Adare - MVP Virtual Machines
It all began with Adam. He was the first man to tell a joke--or a lie.
How lucky Adam was. He knew when he said a good thing, nobody had said
it before. Adam was not alone in the Garden of Eden, however, and does
not deserve all the credit; much is due to Eve, the first woman, and
Satan, the first consultant." - Mark Twain

Similar ThreadsPosted
Smart Card Login + Certificate Login to AD -> Lost smart card December 15, 2005, 10:03 pm
Smart card reader and card supplier in Australia May 5, 2008, 10:37 pm
Change user password with hash March 2, 2006, 11:52 am
Re-initialize smart card June 3, 2005, 8:34 am
Smart Card - two readers December 8, 2006, 8:28 am
Smart Card and VPN in Vista. May 26, 2008, 3:36 am
smart card offline logon July 7, 2005, 9:02 am
Base Smart Card CSP Update December 7, 2005, 3:12 pm
Q: Seconary certificate on a smart card August 5, 2006, 6:24 am
Question Regarding Smart Card Deployment September 12, 2007, 2:16 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap