Windows 10: Certificate based smart card logon to Windows 10/11 with FIPS certified smart card

Discus and support Certificate based smart card logon to Windows 10/11 with FIPS certified smart card in Windows Hello & Lockscreen to solve the problem; Latest FIPS 140-2 Level 3 and FIPS 140-3 have limited HASH algorithm to SHA256/384/512 and SHA-1 can not be used for security reasons. If I use a FIPS... Discussion in 'Windows Hello & Lockscreen' started by Geoffrey150, Feb 20, 2024.

  1. Certificate based smart card logon to Windows 10/11 with FIPS certified smart card


    Latest FIPS 140-2 Level 3 and FIPS 140-3 have limited HASH algorithm to SHA256/384/512 and SHA-1 can not be used for security reasons. If I use a FIPS certified smart card to do certificate based smart card logon to Windows 10 and Windows 11 Windows 10/11 has been on-prem Domain joined and has smart card logon certificate provisioned, the logon process will fail because the kerberos/PKINIT always uses SHA-1, even though I changed CSP/Minidriver to report only SHA256/384/512 algorithm support list to Windows, and I changed according to https://www.anoopcnair.com/configure-hash-algorithms

    :)
     
    Geoffrey150, Feb 20, 2024
    #1

  2. Unable to login with a smart card. Error: "signing in with a smart card is not supported for your account"

    Hello everyone,

    I am writing to describe a problem I have trying to setup an Windows Domain environment for a Automation System. Normaly, in the past we did really basic Active Directry setup with policies regarding accounts, passwords, RDP, use of USB devices (just standard security stuff, no more of a Securit Level 1 system). Now we develop to more secure systems, and I have a problem with 3 workstations that are in this Windows Domain. Those 3 workstation (only htose 3) needs to be accesable only using a smart card logon. And I am failing.

    What I did:

    1. Installed Certificate Authority (on the primary DC) with default settings. I created Certificate template for Smart Card Logon, and issued it to the domain.

    2. In AD users and objects, I selected one domain user (the same one for the smard card setup and use) and I applied the setting: "Smart Card is required for Interactive Logon"

    3. Applied GPO for interactive logon on the 3 workstations: Require Windows Hellor for Business or smart card logon - Enabled; Smart card removal Behaviour - Force logoff; Require Domain Controller authentication to unlock workstation - Enabled

    4. Installed smart card software on the 3 workstation. I requested and obtained a valid certificate for the smart card. I can look into the settings of the smart card software and I see the corect ceritifcate, with the proper details beeing attached to the card.

    When I try to logon, I chose signin option, select smart card. And the Windows PC is reading the user (and certificate) on the smart card. It requests the PIN, I type the PIN and it gets validated, the system moves towards loging in screen. However, I get the following error: "smart card logon is not supported for you user account."

    Just some extra details: If I try to login with that particullar user with the standard authentication procedure: user+password, it fails. The message is this user is required to smart card to login.

    I need to specify that in work with CA and certificates I am at the begging so I may have made mistakes...I just cannot identify what mistakes I made.

    Some ideeas or help would be much most welcomed, as we are on a deadline to deliver the system, and this smart card login is the only stopping point.

    Alex
     
    Dragos Alex, Feb 20, 2024
    #2
  3. Smart Card Certificate Enumeration is not Working in WIndows 10

    I have attempted to, through Group Policy, force my windows 10 login to enumerate the signature certificate on my smart card for use with login. I have this correctly set up in windows 7 and it works there but in windows 10.

    I have read and applied all of the policies listed in

    Smart Card Group Policy and Registry Settings

    https://technet.microsoft.com/en-us/library/ff404287(v=ws.10).aspx

    and also in

    Certificate Enumeration but it still will not function correctly.

    California Consumer Privacy Act (CCPA) Opt-Out Icon
     
    J.B.Bennett, Feb 20, 2024
    #3
  4. Certificate based smart card logon to Windows 10/11 with FIPS certified smart card

    Certification for smart card minidriver. HLK

    Good afternoon. Help me please. I need Microsoft certification for my smart card minidriver. I passed the "Smart Card Minidriver Certification Test" at HLK successfully. But when submitting the package for certification, I received a "Fail error. Errata ID is not provided for not run tests". Are there any other tests I should run for the minidriver?
     
    Olena Kaliadina, Feb 20, 2024
    #4
Thema:

Certificate based smart card logon to Windows 10/11 with FIPS certified smart card

Loading...
  1. Certificate based smart card logon to Windows 10/11 with FIPS certified smart card - Similar Threads - Certificate based smart

  2. Certificate based smart card logon to Windows 10/11 with FIPS certified smart card

    in Windows 10 Gaming
    Certificate based smart card logon to Windows 10/11 with FIPS certified smart card: Latest FIPS 140-2 Level 3 and FIPS 140-3 have limited HASH algorithm to SHA256/384/512 and SHA-1 can not be used for security reasons. If I use a FIPS certified smart card to do certificate based smart card logon to Windows 10 and Windows 11 Windows 10/11 has been on-prem...
  3. Certificate based smart card logon to Windows 10/11 with FIPS certified smart card

    in Windows 10 Software and Apps
    Certificate based smart card logon to Windows 10/11 with FIPS certified smart card: Latest FIPS 140-2 Level 3 and FIPS 140-3 have limited HASH algorithm to SHA256/384/512 and SHA-1 can not be used for security reasons. If I use a FIPS certified smart card to do certificate based smart card logon to Windows 10 and Windows 11 Windows 10/11 has been on-prem...
  4. Certification for smart card minidriver. HLK

    in Windows 10 Gaming
    Certification for smart card minidriver. HLK: Good afternoon. Help me please. I need Microsoft certification for my smart card minidriver. I passed the "Smart Card Minidriver Certification Test" at HLK successfully. But when submitting the package for certification, I received a "Fail error. Errata ID is not provided for...
  5. Certification for smart card minidriver. HLK

    in Windows 10 Software and Apps
    Certification for smart card minidriver. HLK: Good afternoon. Help me please. I need Microsoft certification for my smart card minidriver. I passed the "Smart Card Minidriver Certification Test" at HLK successfully. But when submitting the package for certification, I received a "Fail error. Errata ID is not provided for...
  6. Certification for smart card minidriver. HLK

    in Windows 10 Drivers and Hardware
    Certification for smart card minidriver. HLK: Good afternoon. Help me please. I need Microsoft certification for my smart card minidriver. I passed the "Smart Card Minidriver Certification Test" at HLK successfully. But when submitting the package for certification, I received a "Fail error. Errata ID is not provided for...
  7. Certificate/PKI/Smart Card Logon

    in Windows 10 Gaming
    Certificate/PKI/Smart Card Logon: Hello,I am having an issue with authenticating users in an air gapped network after a patch. Any users prior created in AD prior to May 2022, can still authenticate with the server. However, if I create a new test account and attach my X.509 to altSecurityID attribute, I get...
  8. Certificate/PKI/Smart Card Logon

    in Windows 10 Software and Apps
    Certificate/PKI/Smart Card Logon: Hello,I am having an issue with authenticating users in an air gapped network after a patch. Any users prior created in AD prior to May 2022, can still authenticate with the server. However, if I create a new test account and attach my X.509 to altSecurityID attribute, I get...
  9. Smart Card Authentication and Cached Logons

    in AntiVirus, Firewalls and System Security
    Smart Card Authentication and Cached Logons: Hello,Scenario:Windows 10 laptops are PIV Enforced Smart cards are required to log on to the OSUser has been remote for over a year COVIDVPN is split tunnelMany users are overseas with low bandwidth connectionMost work can be done without direct access to on-prem resources,...
  10. Smart Card Certificates in Win10AU

    in Windows 10 Drivers and Hardware
    Smart Card Certificates in Win10AU: I frequently access work sites that require me to use a CAC/PIV card. Some sites require my encryption certificate but OWA requires my email certificate. Prior to Win10AU update both my certs displayed but now I have to click show more to see all my certs. It's minor but...