Click here to get back home

Smart card enrollment issues

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Smart card enrollment issues verukins 04-29-2008
Posted by verukins on May 4, 2008, 8:41 pm
Please log in for more thread options
cards - Cards - Gemalto Classic TPC IS White PVC (Old name =
GemSafeXpresso 32K)

middleware - none..... (there should not be any necessary from what i
understand for these readers and cards)

card tools - report the card and reader are fine. I can inspect the
card through the tools (although the information doesnt mean anything
to me...)

Posted by Paul Adare on May 5, 2008, 2:48 am
Please log in for more thread options
On Sun, 4 May 2008 17:41:44 -0700 (PDT), verukins@gmail.com wrote:

> cards - Cards - Gemalto Classic TPC IS White PVC (Old name =
> GemSafeXpresso 32K)

Sorry but I don't know what a Classic TPC IS White means. If these are
indeed GemSafe eXpresso Cards then they are not Base CSP cards and you'll
need to install a supported PKCS11 middleware to use them.

>
> middleware - none..... (there should not be any necessary from what i
> understand for these readers and cards)

See above.
>
> card tools - report the card and reader are fine. I can inspect the
> card through the tools (although the information doesnt mean anything
> to me...)

What tools are you referring to here?

--
Paul Adare
http://www.identit.ca
Shift to the left! Shift to the right! Pop up, push down, byte, byte,
byte!

Posted by verukins on May 5, 2008, 3:43 am
Please log in for more thread options
Hi Paul,

Smart cards arent my area... that particular card was suggested by the
gemalto rep for our region... the link the product is -
http://store.gemalto.com/is-bin/INTERSHOP.enfinity/eCS/Store/en/-/EUR/BrowseCatalog-Start;sid=xD1Dx3UCpstD7j0cfMqDbxAGzuphxAM6-R8=?CatalogCategoryID=NAzAqGXoGAgAAAED0rcA_nnM&BuyerClass=&Template=category_2B2C

I was under the impression that it was just a run of the mill 32k
card.....

Ok, so if they are gemsfae expresso cards... what is the PCKS
middleware i need? (sorry, PCKS11 doesnt mean much to me)

One of the things i specified to the rep was that i wanted readers/
card that worked natively with windows... because otherwise they're
pretty much usless to me.

The tools im referring to are the Localised smartdiag diagnostic tools
available from - http://support.gemalto.com/?id=199#310

I'm starting to get the feeling i may have acted on the wrong advice.

Flat out, all im after is some cards to logon via TS Gateway with - if
you guys can either help me out with what middleware i need (and do i
need to have it on every server and workstation?) - or preferably,
point me in the direction of cards that have CSP's built into windows
(XP/Vista/2003/2008) it would be very helpful.

Thanks.

Posted by Brian Komar \(MVP\) on May 7, 2008, 7:28 am
Please log in for more thread options
To use these cards, you must purchase the Axalto middleware.
They are *not* natively supported in Windows.
You want to acquire Base CSP cards from Gemalto (.Net Cards is the way they
are branded).
If you purchase middleware, you will need to install it on the client
computers and on the target terminal servers (1 license each)
Brian

> Hi Paul,
>
> Smart cards arent my area... that particular card was suggested by the
> gemalto rep for our region... the link the product is -
>
http://store.gemalto.com/is-bin/INTERSHOP.enfinity/eCS/Store/en/-/EUR/BrowseCatalog-Start;sid=xD1Dx3UCpstD7j0cfMqDbxAGzuphxAM6-R8=?CatalogCategoryID=NAzAqGXoGAgAAAED0rcA_nnM&BuyerClass=&Template=category_2B2C
>
> I was under the impression that it was just a run of the mill 32k
> card.....
>
> Ok, so if they are gemsfae expresso cards... what is the PCKS
> middleware i need? (sorry, PCKS11 doesnt mean much to me)
>
> One of the things i specified to the rep was that i wanted readers/
> card that worked natively with windows... because otherwise they're
> pretty much usless to me.
>
> The tools im referring to are the Localised smartdiag diagnostic tools
> available from - http://support.gemalto.com/?id=199#310
>
> I'm starting to get the feeling i may have acted on the wrong advice.
>
> Flat out, all im after is some cards to logon via TS Gateway with - if
> you guys can either help me out with what middleware i need (and do i
> need to have it on every server and workstation?) - or preferably,
> point me in the direction of cards that have CSP's built into windows
> (XP/Vista/2003/2008) it would be very helpful.
>
> Thanks.


Posted by John Bothner on May 5, 2008, 7:51 am
Please log in for more thread options
I think I have the very same problem (your problem 1).
Same plattforms:
- Enterprise (domain) root issuing CA - Windows 2008 Enterprise
- Domain Controller: Windows 2008 Enterprise
- Enrollment station - Vista SP1

On the enrollment station: I use the Certificates mmc snap in, and
similarily choose "enroll certificate on behalf of anoher user. The
enrollment agent certificate is asked for and given, just fine. I have
duplicated the "smart card logon" template, that template is not available
from the enrollment station. When I check "Show all templates" I see my
duplicated template with the error message
"The template is missing a required signature policy attribute. You
do not have permission to view this type of certificate."
I have opened all rights (Full Control, this is not a production
environment) in the Security tab for the enrollment agents (in the
duplicated template).
I have also done as indicated in http://support.microsoft.com/kb/313629.
I have tried both for version 2 (2003) and version 3 (2008) certificate
templates with no success.

My reader and card works fine when I test on the enrollment station with the
CTRL-ALT-DEL-change-password-other-credentials. I am using the Gemalto .NET
v2 cards. So I think the problem is not card or reader related, but with
the CA or certificate templates?

Any suggestions are greatly appriciated.



Kind regards,
John Bothner





> Hi all,
> I am trying to enroll some smart cards with the following
> setup
>
> Reader - Gemalto PC Twin USB (Old Name = Gempc twin usb)
> Cards - Gemalto Classic TPC IS White PVC (Old name = GemSafeXpresso
> 32K)
>
> CA - Windows 2008 Enterprise Root CA
> Enrollment station - Vista SP1
>
> th intent is to use these cards for remote access via TSGateway.
>
> Problem 1 - When trying to create another certificate template by
> duplicating the "smart card logon" template, that template is not
> available from the enrollment station. I have modified the issuance
> requirements as per one of the technet articles below, but with no
> sucess.
>
> Problem 2 - When i try to issue from the standard "smart card logon",
> i am prompted to insert my smartcard, however the certificate goes
> straight into the personal store and does not prompt me for a PIN.
>
> The gemalto troublshooting tools seem to indicate that my reader and
> smartcard are all good.
>
> I've been looking the the following articles (some of which are geared
> towards win 2003)
>
>
http://207.46.196.114/windowsserver/en/library/99827b56-216a-475b-a7e9-84c8d4c749de1033.mspx?mfr=true
>
http://technet2.microsoft.com/windowsserver/en/library/5229033e-232b-4f91-9f86-0cbbd7cfc5a81033.mspx?mfr=true
> http://support.microsoft.com/kb/313629
> http://support.microsoft.com/kb/922706
>
> Can anyone assist ?


Similar ThreadsPosted
Smart Card Login + Certificate Login to AD -> Lost smart card December 15, 2005, 10:03 pm
Smart card reader and card supplier in Australia May 5, 2008, 10:37 pm
Re-initialize smart card June 3, 2005, 8:34 am
Smart Card - two readers December 8, 2006, 8:28 am
Smart Card and VPN in Vista. May 26, 2008, 3:36 am
smart card offline logon July 7, 2005, 9:02 am
Base Smart Card CSP Update December 7, 2005, 3:12 pm
Q: Seconary certificate on a smart card August 5, 2006, 6:24 am
Question Regarding Smart Card Deployment September 12, 2007, 2:16 pm
Using a flash drive instead of a smart card. April 28, 2008, 1:25 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap