I've been given a project at work and I'm struggling with it. I'm seeking advice from the gurus. Normally, Tumbleweed or Crossstreet (?) is used for smart card authentication. The project is, enable smart card authentication using only Microsoft's OCSP in Server 2008.
I'm brand new to configuring a CA and OCSP. Issuing certs is about the level I'm at with the CA. I haven't configured Tumbleweed in the past. I've found a few tidbits here and there, but nothing really helpful. I've asked several people at work and still turned up little help. I've configured and issued the OCSP responder certificate. I've set up a dummy website in IIS with a directory containing CRLs. I configured the AIA and Extensions on the CA server to point to the CRL directory. I have a trusted intermediary cert and added it to the personal store. I added the trusted intermediary and root cert to a GPO and linked it to the user OU. I've imported the root certificates on the CA server.
Where do I go next? The current error is, credentials cannot be verified. I don't see any errors in the logs, other than authentication failed on the client side and there is nothing on the server side.
Thank you for your help.
Smart Card Authentication Help
Moderator: Moderators
-
- DCAWD Groupie
- Posts: 598
- Joined: Wed Jun 22, 2005 11:41 pm
- Location: ^^^^^, CO.
Smart Card Authentication Help
My Name is Adam.
- complacent
- DCAWD Founding Member
- Posts: 11651
- Joined: Sun Aug 29, 2004 8:00 pm
- Location: near the rockies. very.
- Contact:
Re: Smart Card Authentication Help
a ton of questions...
who is the root certificate authority? is this machine on a "particular" domain? are these smart cards contain certificates also on a "particular" domain or from a "particular" RA?
if so, every machine (dc) performing authentication will need a cert of their own to authenticate.
we can take this to pm's or email if you need. you should be able to find me on your gal.
who is the root certificate authority? is this machine on a "particular" domain? are these smart cards contain certificates also on a "particular" domain or from a "particular" RA?
if so, every machine (dc) performing authentication will need a cert of their own to authenticate.
we can take this to pm's or email if you need. you should be able to find me on your gal.
colin
a tank, a yammie, a spaceship
i <3 teh 00ntz
a tank, a yammie, a spaceship
i <3 teh 00ntz
- Sabre
- DCAWD Founding Member
- Posts: 21432
- Joined: Wed Aug 11, 2004 8:00 pm
- Location: Springfield, VA
- Contact:
Re: Smart Card Authentication Help


Sabre (Julian)

92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.

92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.
-
- Moderator
- Posts: 6314
- Joined: Wed Oct 19, 2005 1:15 am
- Location: Alexandria
Re: Smart Card Authentication Help
this is a really great sentence when taken out of context.complacent wrote:you should be able to find me on your gal.
-Ben


- missvenezuela85
- I'm starting to be a post wh0re
- Posts: 442
- Joined: Wed Aug 02, 2006 6:32 pm
- Location: ^^^^^^---------- CO
- Contact:
Re: Smart Card Authentication Help
I hope you guys can help him... i tried to give him the best IT support I could... "Adam, why don't you post this on DCAWD" end support.
Boots and pants and boots and pants and boots and pants and boots and pants and boots and pants and boots and pants and boots and pants and boots and pants and boots and pants and boots and pants oh and www.annadventure.com <----
& 



- complacent
- DCAWD Founding Member
- Posts: 11651
- Joined: Sun Aug 29, 2004 8:00 pm
- Location: near the rockies. very.
- Contact:
Re: Smart Card Authentication Help
oops, lol!chicken n waffles wrote:this is a really great sentence when taken out of context.complacent wrote:you should be able to find me on your gal.

colin
a tank, a yammie, a spaceship
i <3 teh 00ntz
a tank, a yammie, a spaceship
i <3 teh 00ntz
-
- DCAWD Groupie
- Posts: 598
- Joined: Wed Jun 22, 2005 11:41 pm
- Location: ^^^^^, CO.
Re: Smart Card Authentication Help


My Name is Adam.