Buypass SmartCard Logon - MS WIN 2016 Server


(lightbulb) This information is written in English only


The certificate issued for SmartCard Logon.




ExplanationsScreenshots

General:

  • Validity = 3 years
  • Renewal Period = 6 weeks
  • Published in Active Directory

We can see certificate issued under user account properties in AD

Compatability:

Default setting


Request Handling:

  • Purpose = Signature and SmartCard Logon
  • Prompt the User during enrollment = Set


Cryptography:

  • Key Size = 1024
  • Requests can use any provider available on the subject’s computer
  •  

Key Attestation:

Default setting

Subject Name:

Name is obtained from Active Directory based on the Fully distinguished name and the user's UPN

Issuance Requirements:

  • This number of authorized signatures = 1
  • Policy = Application Policy and Certificate Request Agent
  • Reenrollment = Same criteria as for enrollment

Suspended Templates:

No settings = Default

Extensions:

  •   Application policies = Smart card Logon, Client Authentication

Extensions:

  • Basic Constraints = Default settings

Extensions:

  • Certificate Template Information = Default Setting

Extensions:

  • Issuance Policies = Default Setting

Extensions:

  • Key usage: Digital signature – Critical extension

Security:

These settings determine the privileges for the Certificate for read, modify and enroll of certificate.

Only the DL_CA_ADM, the DL_LRA_ADM and the DL_CA_LRA groups should get this certificate via Enroll.

  • DL_CA_Admins = Read, Write, Enroll
  • DL_CA_LRA_Admins = Read, Write, Enroll
  • DL_CA_LRA_Operators = Read, Enroll


Server:

Default settings



Content  

Unable to render {include} The included page could not be found.

Unable to render {include} The included page could not be found.

 

Unable to render {include} The included page could not be found.
Unable to render {include} The included page could not be found.
 
Unable to render {include} The included page could not be found.