A Windows Vista forum. Vista Banter

Welcome to Vista Banter.

You are currently viewing our boards as a guest which gives you limited access to view most discussions, articles and access our other FREE features. By joining our free community you will have access to ask questions and reply to others posts, upload your own photos and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact support.

Go Back   Home » Vista Banter forum » Microsoft Windows Vista » Security and Windows Vista
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

Security and Windows Vista A forum for discussion on security issues with Windows Vista. (microsoft.public.windows.vista.security)

Vista and AD Smartcard Logon



 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old March 14th 07, 10:20 PM posted to microsoft.public.windows.vista.security
Rob Fisher
external usenet poster
 
Posts: 1
Default Vista and AD Smartcard Logon

In January, I had the DoD CAC (smartcard) solution working in our domain for
authentication with Vista. Recently, I gave it another test on the same
machine that had been working previously, but it has stopped working.

I now get an error message at the logon screen that says "The system could
not log you on. The revocation status of the domain controller certificate
used for smart card authentication could not be determined." In the event
log, it says the server is offline. However, this is not the case. I am
able to see the query coming from the Vista client to the openLDAP server
which hosts the CRL's. In the query there is some odd LDAP command is being
presented that isn't supported by LDAP.

do_search: invalid dn (cn=DoD Root CA 2,ou=PKI,ou=DoD,o=U.S.
overnment,c=US?certificaterevocationlist;binary)

It looks like they change the search dn to include the crl attr in the dn
too, which isn't supported by openLDAP.

My question is, did something change recently with an update in Vista that
would explain this? We were getting geared up to migrate to Vista as soon as
SP1 is released, however, without smartcard logon capabilities, the DoD will
never use Vista. What is the best route to get support on this issue and
work with Microsoft to come up with a solution?

----------------
This post is a suggestion for Microsoft, and Microsoft responds to the
suggestions with the most votes. To vote for this suggestion, click the "I
Agree" button in the message pane. If you do not see the button, follow this
link to open the suggestion in the Microsoft Web-based Newsreader and then
click "I Agree" in the message pane.

http://windowshelp.microsoft.com/com...sta.sec urity
 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 12:54 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.Search Engine Optimization by vBSEO 3.0.0 RC6
Copyright ©2004-2024 Vista Banter.
The comments are property of their posters.