If this is not configured, anyone will be able to log on.   Depending on Active Directory configuration the profile might need to use the Alternate Subject Name on the Smart A list of all the certificates in the server's keyring database is displayed. COMM663: The certificate on the server may be using a name that does not match its Internet name. On a Windows machine if Firefox is intended to be used, additional configuration is needed.

Supported Smart Card Readers Before you can use a smart card, you must install a smart card reader on your host computer. and follow the instructions to import the certificate from a PKCS12 file. Stop and restart the Service Manager. However, you may check the presence of the dynamic library basecsp.dll under the directory c:\windows\system32 for 32 bit system and additionally under c:\windows\syswow64 for 64 bit system.

For smart card logon, the user needs to only insert the smart card into the smart card reader. The most current information about hardware requirements and compatibility for servers, clients, and peripherals is available from the Windows 2000 Product Compatibility site ( A Schlumberger smart card reader must first be installed and then uninstalled. The problem for the Microsoft network administrators and engineers is that securing Microsoft networks is an extremely complex task.

Ensure that your smart card is inserted in the reader before you start this procedure. Entrust Self-signed Add .p12 Windows 98/NT Windows 2000 IBM Security Card PCMCIA Reader X X X IBM Security Card Serial Reader X X Schlumberger Reflex 20 Choosing Microsoft Base Cryptographic Provider 1.0 will put the certificate into the MSCAPI database. However, this is the expected behavior and can be ignored. 2.5 Issue with GemSafe and Ceres Card on Internet Explorer On Windows XP, when trying to read certificates that are on

See Redirector Troubleshooting Checklist for details. Configure the Access Gateway virtual server with client certificate optional. However, if configured, Access Gateway performs group extraction based on the criteria chosen for it. The most important configuration on Access Gateway Enterprise is the Single Sign-on (SSO) Domain field If the Certification Authority successfully processes the certificate request, the Smart Card Enrollment Station page informs you that the enrollment is complete and the smart card is ready.

The correct Service Principal Names (SPN) must be configured for those resources.  Web Interface Configuration Complete the following steps to configure web interface: Create a Web Interface site with authentication set You agree to not use deliverables for prohibited nuclear, missile, or chemical biological weaponry end uses. Press enter at the password prompt. Try removing the Host On-Demand cached client, deleting temporary internet files, and try again.

makes no representations or warranties with respect to the contents or use of this documentation, and specifically disclaims any express or implied warranties of merchantability or fitness for any particular purpose. Isolation of security-critical computations involving authentication, digital signatures, and key exchange from other parts of the system that do not have a need to know. Some Schlumberger entries may remain in the registry. Download and install the Smartdiag tool on your system.

This error message will disappear after a few seconds. To export the file using Netscape 4.x: Click Communicator > Tools > Security Info. The fully qualified domain name MUST match its name in Active Directory. Cryptographic smart cards can only be obtained directly from the respective companies and not from Microsoft Corporation.

On Windows Vista/7 the behavior of Windows has changed. The certificate obtained from should be used for testing purposes only. Use Netscape to import the certificate from the PKCS12 file. In case you do not have already installed, download and install the software here.

To convert the format, take the following steps: Download the certificate to a workstation that has a Netscape 4.x or Netscape 6.x browser installed. Uninstalling this variant: If there are any problems with GCardSrvNT.exe, you may also remove the entire program GemSafe Libraries 4.2.0 SP1 or GemSafe Libraries 4.2.0 SP3 using Windows Control Panel. In the right pane, right-click Smart Card. Type in the PIN for the card, and then click OK.

If you are experiencing problems with SSL on the Redirector, verify that the Host On-Demand Server Key and the CustomizedCAs class have been created. In case the certificate for the Smart Card has an intermediate authority, both the intermediate and root must be bound separately as CA certificates. If a Published Desktop or Published Application uses other resources not on the XenApp server itself (for example, CIFS file shares, SQL, DCOM) additional configuration might be required. Smart cards enhance software-only solutions such as client authentication, log on, code signing, and secure e-mail, where private key operations are performed on the smart card and not on the host

Top of page Installing a Smart Card Reader Smart card readers generally come with instructions on how to connect any necessary cables. Any products or technical information provided under this Agreement may be subject to U.S. export controls and the trade laws of other countries. Portability of credentials and other private information between computers at work, home, or on the road.

This exercise should only be used for testing purposes, and the Entrust PKI Demonstration Certificate should be removed from any production server.

This solution enables convergence of IT and physical systems to provide a complete end-to-end and seamless control system. 2.0 Known Issues 2.1 Dealing with Client Login Module Not Found NMAS Error