Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

smart card interactive logon does not work on some of the domain computers

$
0
0

Dear all,

We have a problem with smart card interactive logon, below are the symptoms:

  1. smart card interactive logon works on some servers in the same domain
  2. root certificate is deployed via GPO and present in the trusted root cert store on every domain computer
  3. certutil -verify -urlfetch works fine for domain controller certificate and user certificate on the problematic server where smart card interactive logon is not working
  4. enabled CAPI2, found out that on the server where smart card interactive logon is not working,"CERT_CHAIN_POLICY_NTAUTH" is being used for "CertVerifyCertificateChainPolicy", on the working node, "CERT_CHAIN_POLICY_BASE" is being used.

i wonder if there is any setting to let server use "CERT_CHAIN_POLICY_BASE" for "CertVerifyCertificateChainPolicy"? or am i missing anything? thanks in advance!

Cheers,


Best Regards, Bruce


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>