![]() |
![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
| Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks. |
| |||||||
![]() |
| |
| | #1 (permalink) |
| | Windows Vista smart card logon on stand alone machine Hi all. I just want to share with you my thoughts about smart card authentication implementation in Vista. I know that smart card logon, also known as strong authentication or two-factor authentication, can be performed on a machine that is connected to a domain. And in Vista SP1 it's been added the support for biometric factor authentication so that, with the appropriate security tokens, strong three-factor authentication can be performed through Kerberos on machines connected to a domain. Said that I really can't understand why Microsoft doesn't give a standard option, included natively in her oss, to enable strong authentication in stand alone machines that are not connected to a domain. I try to explain in details what I mean. It happens often, for security reasons, that companies have stand alone pcs not connected to the internet and to the company domain. From my point of view achieving a strong authentication on a stand alone machine is not so complicated; Let's think at this scenario: I have my public key certificate with its relative private key both stored on my personal security token that, through its internal microprocessor, is capable of cryptographic tasks. If there could be a way to install the public key certificate I have on the above security token on a stand alone machine and associate it to my user account of that stand alone pc it could be easy to perform strong authentication using Microsoft Smart Card Base Cryptographic Service Provider. ( Having also the minidrivers of the token vendor installed on the stand alone machine ) When I would insert my security token in the stand alone pc my public key certificate would be sent to the stand alone pc that, after checking that the public key certificate is associated to my user account on the stand alone pc, would sent to my security token an automatically generated password encrypted with the public key associated to the public key certificate I have on my security token that could decrypted it with its private key and send it to the stand alone pc. I know that there are third parts softwares that perform authentication to windows stand alone pc through security token but it's not the same as if it was embedded natively in windows oss. My reasoning is surely missing some technical or security aspect or maybe just some convenience aspect and I really appreciate any comments and/or any corrections. Thank in advice to all who will read my post and answer/comment me. Best regards Michele |
My System Specs![]() |
| | #2 (permalink) |
| | Re: Windows Vista smart card logon on stand alone machine Google on PKINIT Brian "Michele" <Michele@xxxxxx> wrote in message news:1422ACCF-C9C0-469E-9E9C-EFB3B94F6FA9@xxxxxx Quote: > Hi all. > I just want to share with you my thoughts about smart card authentication > implementation in Vista. > I know that smart card logon, also known as strong authentication or > two-factor authentication, can be performed on a machine that is connected > to > a domain. > And in Vista SP1 it's been added the support for biometric factor > authentication so that, with the appropriate security tokens, strong > three-factor authentication can be performed through Kerberos on machines > connected to a domain. > Said that I really can't understand why Microsoft doesn't give a standard > option, included natively in her oss, to enable strong authentication in > stand alone machines that are not connected to a domain. > I try to explain in details what I mean. > It happens often, for security reasons, that companies have stand alone > pcs > not connected to the internet and to the company domain. > From my point of view achieving a strong authentication on a stand alone > machine is not so complicated; Let's think at this scenario: I have my > public > key certificate with its relative private key both stored on my personal > security token that, through its internal microprocessor, is capable of > cryptographic tasks. > If there could be a way to install the public key certificate I have on > the > above security token on a stand alone machine and associate it to my user > account of that stand alone pc it could be easy to perform strong > authentication using Microsoft Smart Card Base Cryptographic Service > Provider. ( Having also the minidrivers of the token vendor installed on > the > stand alone machine ) > When I would insert my security token in the stand alone pc my public key > certificate would be sent to the stand alone pc that, after checking that > the > public key certificate is associated to my user account on the stand alone > pc, would sent to my security token an automatically generated password > encrypted with the public key associated to the public key certificate I > have > on my security token that could decrypted it with its private key and send > it > to the stand alone pc. > I know that there are third parts softwares that perform authentication to > windows stand alone pc through security token but it's not the same as if > it > was embedded natively in windows oss. > My reasoning is surely missing some technical or security aspect or maybe > just some convenience aspect and I really appreciate any comments and/or > any > corrections. > Thank in advice to all who will read my post and answer/comment me. > Best regards > Michele > |
My System Specs![]() |
| | #3 (permalink) |
| | Re: Windows Vista smart card logon on stand alone machine Dear Michel I m facing the same problem exactly as you, and i didn't find any third party software resolve this problem till now, have you? -- ramyashram ------------------------------------------------------------------------ ramyashram's Profile: http://forums.techarena.in/member.php?userid=48623 View this thread: http://forums.techarena.in/showthread.php?t=928761 http://forums.techarena.in |
My System Specs![]() |
![]() |
| Thread Tools | |
| |
Similar Threads | ||||
| Thread | Forum | |||
| Smart card Logon | System Security | |||
| Smart Card - DOD CAC not working in VISTA | Vista hardware & devices | |||
| Vista logon with smart card on local pc | Vista security | |||
| Vista logon with smart card | Vista security | |||
| Smart card logon | Vista security | |||