Windows 10: Certificate based smart card logon to Windows 10/11 with FIPS certified smart card

Discus and support Certificate based smart card logon to Windows 10/11 with FIPS certified smart card in Windows 10 Software and Apps to solve the problem; Latest FIPS 140-2 Level 3 and FIPS 140-3 have limited HASH algorithm to SHA256/384/512 and SHA-1 can not be used for security reasons. If I use a FIPS... Discussion in 'Windows 10 Software and Apps' started by Geoffrey150, Feb 20, 2024.

  1. Certificate based smart card logon to Windows 10/11 with FIPS certified smart card


    Latest FIPS 140-2 Level 3 and FIPS 140-3 have limited HASH algorithm to SHA256/384/512 and SHA-1 can not be used for security reasons. If I use a FIPS certified smart card to do certificate based smart card logon to Windows 10 and Windows 11 Windows 10/11 has been on-prem Domain joined and has smart card logon certificate provisioned, the logon process will fail because the kerberos/PKINIT always uses SHA-1, even though I changed CSP/Minidriver to report only SHA256/384/512 algorithm support list to Windows, and I changed according to https://www.anoopcnair.com/configure-hash-algorithms

    :)
     
    Geoffrey150, Feb 20, 2024
    #1

  2. Unable to login with a smart card. Error: "signing in with a smart card is not supported for your account"

    Hello everyone,

    I am writing to describe a problem I have trying to setup an Windows Domain environment for a Automation System. Normaly, in the past we did really basic Active Directry setup with policies regarding accounts, passwords, RDP, use of USB devices (just standard security stuff, no more of a Securit Level 1 system). Now we develop to more secure systems, and I have a problem with 3 workstations that are in this Windows Domain. Those 3 workstation (only htose 3) needs to be accesable only using a smart card logon. And I am failing.

    What I did:

    1. Installed Certificate Authority (on the primary DC) with default settings. I created Certificate template for Smart Card Logon, and issued it to the domain.

    2. In AD users and objects, I selected one domain user (the same one for the smard card setup and use) and I applied the setting: "Smart Card is required for Interactive Logon"

    3. Applied GPO for interactive logon on the 3 workstations: Require Windows Hellor for Business or smart card logon - Enabled; Smart card removal Behaviour - Force logoff; Require Domain Controller authentication to unlock workstation - Enabled

    4. Installed smart card software on the 3 workstation. I requested and obtained a valid certificate for the smart card. I can look into the settings of the smart card software and I see the corect ceritifcate, with the proper details beeing attached to the card.

    When I try to logon, I chose signin option, select smart card. And the Windows PC is reading the user (and certificate) on the smart card. It requests the PIN, I type the PIN and it gets validated, the system moves towards loging in screen. However, I get the following error: "smart card logon is not supported for you user account."

    Just some extra details: If I try to login with that particullar user with the standard authentication procedure: user+password, it fails. The message is this user is required to smart card to login.

    I need to specify that in work with CA and certificates I am at the begging so I may have made mistakes...I just cannot identify what mistakes I made.

    Some ideeas or help would be much most welcomed, as we are on a deadline to deliver the system, and this smart card login is the only stopping point.

    Alex
     
    Dragos Alex, Feb 20, 2024
    #2
  3. Smart Card Certificate Enumeration is not Working in WIndows 10

    I have attempted to, through Group Policy, force my windows 10 login to enumerate the signature certificate on my smart card for use with login. I have this correctly set up in windows 7 and it works there but in windows 10.

    I have read and applied all of the policies listed in

    Smart Card Group Policy and Registry Settings

    https://technet.microsoft.com/en-us/library/ff404287(v=ws.10).aspx

    and also in

    Certificate Enumeration but it still will not function correctly.

    California Consumer Privacy Act (CCPA) Opt-Out Icon
     
    J.B.Bennett, Feb 20, 2024
    #3
  4. Certificate based smart card logon to Windows 10/11 with FIPS certified smart card

    Certification for smart card minidriver. HLK

    Good afternoon. Help me please. I need Microsoft certification for my smart card minidriver. I passed the "Smart Card Minidriver Certification Test" at HLK successfully. But when submitting the package for certification, I received a "Fail error. Errata ID is not provided for not run tests". Are there any other tests I should run for the minidriver?
     
    Olena Kaliadina, Feb 20, 2024
    #4
Thema:

Certificate based smart card logon to Windows 10/11 with FIPS certified smart card

Loading...
  1. Certificate based smart card logon to Windows 10/11 with FIPS certified smart card - Similar Threads - Certificate based smart

  2. Smart card logon on windows says "Signing with a smart card isn't supported for your...

    in Windows Hello & Lockscreen
    Smart card logon on windows says "Signing with a smart card isn't supported for your...: Have configured an ECDSA_P256 smart card logon certificate template on windows server 2019 DC and issued it to get enrolled on client PC.the certificate template gets enrolled well on the smart card token via mmc.exe 0 -> Add / Remove Snap-in -> Certificates -> add -> ok.in...
  3. Certificate based smart card logon to Windows 10/11 with FIPS certified smart card

    in Windows 10 Gaming
    Certificate based smart card logon to Windows 10/11 with FIPS certified smart card: Latest FIPS 140-2 Level 3 and FIPS 140-3 have limited HASH algorithm to SHA256/384/512 and SHA-1 can not be used for security reasons. If I use a FIPS certified smart card to do certificate based smart card logon to Windows 10 and Windows 11 Windows 10/11 has been on-prem...
  4. Certificate based smart card logon to Windows 10/11 with FIPS certified smart card

    in Windows Hello & Lockscreen
    Certificate based smart card logon to Windows 10/11 with FIPS certified smart card: Latest FIPS 140-2 Level 3 and FIPS 140-3 have limited HASH algorithm to SHA256/384/512 and SHA-1 can not be used for security reasons. If I use a FIPS certified smart card to do certificate based smart card logon to Windows 10 and Windows 11 Windows 10/11 has been on-prem...
  5. Certification for smart card minidriver. HLK

    in Windows 10 Software and Apps
    Certification for smart card minidriver. HLK: Good afternoon. Help me please. I need Microsoft certification for my smart card minidriver. I passed the "Smart Card Minidriver Certification Test" at HLK successfully. But when submitting the package for certification, I received a "Fail error. Errata ID is not provided for...
  6. Certification for smart card minidriver. HLK

    in Windows 10 Drivers and Hardware
    Certification for smart card minidriver. HLK: Good afternoon. Help me please. I need Microsoft certification for my smart card minidriver. I passed the "Smart Card Minidriver Certification Test" at HLK successfully. But when submitting the package for certification, I received a "Fail error. Errata ID is not provided for...
  7. Certificate/PKI/Smart Card Logon

    in Windows 10 Gaming
    Certificate/PKI/Smart Card Logon: Hello,I am having an issue with authenticating users in an air gapped network after a patch. Any users prior created in AD prior to May 2022, can still authenticate with the server. However, if I create a new test account and attach my X.509 to altSecurityID attribute, I get...
  8. Certificate/PKI/Smart Card Logon

    in Windows 10 Software and Apps
    Certificate/PKI/Smart Card Logon: Hello,I am having an issue with authenticating users in an air gapped network after a patch. Any users prior created in AD prior to May 2022, can still authenticate with the server. However, if I create a new test account and attach my X.509 to altSecurityID attribute, I get...
  9. Smart Card Authentication and Cached Logons

    in AntiVirus, Firewalls and System Security
    Smart Card Authentication and Cached Logons: Hello,Scenario:Windows 10 laptops are PIV Enforced Smart cards are required to log on to the OSUser has been remote for over a year COVIDVPN is split tunnelMany users are overseas with low bandwidth connectionMost work can be done without direct access to on-prem resources,...
  10. Smart Card Certificates in Win10AU

    in Windows 10 Drivers and Hardware
    Smart Card Certificates in Win10AU: I frequently access work sites that require me to use a CAC/PIV card. Some sites require my encryption certificate but OWA requires my email certificate. Prior to Win10AU update both my certs displayed but now I have to click show more to see all my certs. It's minor but...