Windows 10: Unknown HTTP error while retrieving PRT token with smart-card logon

Discus and support Unknown HTTP error while retrieving PRT token with smart-card logon in Windows 10 Gaming to solve the problem; We are currently migrating our proprietary smart-card logon system to Entra ID in combination with Entra CBA. We have the single sign-on system working... Discussion in 'Windows 10 Gaming' started by Eric Bus, Nov 21, 2024.

  1. Eric Bus Win User

    Unknown HTTP error while retrieving PRT token with smart-card logon


    We are currently migrating our proprietary smart-card logon system to Entra ID in combination with Entra CBA. We have the single sign-on system working for password-pased logons on the PC. The user gets a PRT and `dsregcmd /status` shows a working configuration.This is not the case when a user signs in with his smart-card. The user get access to the machine, but for some reason the retrieval of the PRT fails with an error that I cannot find anywhere online:+----------------------------------------------------------------------+ SSO State

    :)
     
    Eric Bus, Nov 21, 2024
    #1

  2. Certificate based smart card logon to Windows 10/11 with FIPS certified smart card

    Latest FIPS 140-2 Level 3 and FIPS 140-3 have limited HASH algorithm to SHA256/384/512 and SHA-1 can not be used for security reasons. If I use a FIPS certified smart card to do certificate based smart card logon to Windows 10 and Windows 11 (Windows 10/11 has been on-prem Domain joined and has smart card logon certificate provisioned), the logon process will fail because the kerberos/PKINIT always uses SHA-1, even though I changed CSP/Minidriver to report only SHA256/384/512 algorithm support list to Windows, and I changed according to New Windows 11 Configure Hash Algorithms For Certificate Logon Authentication Group Policy For Kerberos HTMD Blog to disable SHA-1. I logged the process of lsass.exe calling CSP/Minidriver, it will create SHA-1 hash and then sign the SHA-1 digest later.

    So how to use FIPS certified smart card (without SHA-1) to logon to windows 10/11?

    ***Moved from Windows / Windows 10 / Windows Hello, lock screen and sign-in***
     
    Geoffrey150, Nov 21, 2024
    #2
  3. Axxellzz Win User
    Smart card removal policy not working

    Hi.

    We have some PC running on Windows 10 Professionnal version 1909 on a work environment when the smartcard is removed, the session does not lock. We can logon on the session without any problems with the token.

    I looked on the services running on Windows and the smart card removal was set to "manual" and was stopped. So i switched it to automatic and rebooted. I can logon with my token but again, when i removed it, the session is still active and doesn't want to
    lock. Does someone had this problem before? And if so, how can i resolve the situation?
     
    Axxellzz, Nov 21, 2024
    #3
  4. Unknown HTTP error while retrieving PRT token with smart-card logon

    Unable to login with a smart card. Error: "signing in with a smart card is not supported for your account"

    Hello everyone,

    I am writing to describe a problem I have trying to setup an Windows Domain environment for a Automation System. Normaly, in the past we did really basic Active Directry setup with policies regarding accounts, passwords, RDP, use of USB devices (just standard security stuff, no more of a Securit Level 1 system). Now we develop to more secure systems, and I have a problem with 3 workstations that are in this Windows Domain. Those 3 workstation (only htose 3) needs to be accesable only using a smart card logon. And I am failing.

    What I did:

    1. Installed Certificate Authority (on the primary DC) with default settings. I created Certificate template for Smart Card Logon, and issued it to the domain.

    2. In AD users and objects, I selected one domain user (the same one for the smard card setup and use) and I applied the setting: "Smart Card is required for Interactive Logon"

    3. Applied GPO for interactive logon on the 3 workstations: Require Windows Hellor for Business or smart card logon - Enabled; Smart card removal Behaviour - Force logoff; Require Domain Controller authentication to unlock workstation - Enabled

    4. Installed smart card software on the 3 workstation. I requested and obtained a valid certificate for the smart card. I can look into the settings of the smart card software and I see the corect ceritifcate, with the proper details beeing attached to the card.

    When I try to logon, I chose signin option, select smart card. And the Windows PC is reading the user (and certificate) on the smart card. It requests the PIN, I type the PIN and it gets validated, the system moves towards loging in screen. However, I get the following error: "smart card logon is not supported for you user account."

    Just some extra details: If I try to login with that particullar user with the standard authentication procedure: user+password, it fails. The message is this user is required to smart card to login.

    I need to specify that in work with CA and certificates I am at the begging so I may have made mistakes...I just cannot identify what mistakes I made.

    Some ideeas or help would be much most welcomed, as we are on a deadline to deliver the system, and this smart card login is the only stopping point.

    Alex
     
    Dragos Alex, Nov 21, 2024
    #4
Thema:

Unknown HTTP error while retrieving PRT token with smart-card logon

Loading...
  1. Unknown HTTP error while retrieving PRT token with smart-card logon - Similar Threads - Unknown HTTP error

  2. Unknown HTTP error while retrieving PRT token with smart-card logon

    in Windows 10 Software and Apps
    Unknown HTTP error while retrieving PRT token with smart-card logon: We are currently migrating our proprietary smart-card logon system to Entra ID in combination with Entra CBA. We have the single sign-on system working for password-pased logons on the PC. The user gets a PRT and `dsregcmd /status` shows a working configuration.This is not...
  3. Smart card logon on windows says "Signing with a smart card isn't supported for your...

    in Windows Hello & Lockscreen
    Smart card logon on windows says "Signing with a smart card isn't supported for your...: Have configured an ECDSA_P256 smart card logon certificate template on windows server 2019 DC and issued it to get enrolled on client PC.the certificate template gets enrolled well on the smart card token via mmc.exe 0 -> Add / Remove Snap-in -> Certificates -> add -> ok.in...
  4. Smart card logon on windows says "Signing with a smart card isn't supported for your...

    in Windows 10 Gaming
    Smart card logon on windows says "Signing with a smart card isn't supported for your...: Have configured an ECDSA_P256 smart card logon certificate template on windows server 2019 DC and issued it to get enrolled on client PC.the certificate template gets enrolled well on the smart card token via mmc.exe 0 -> Add / Remove Snap-in -> Certificates -> add -> ok.in...
  5. Smart card logon on windows says "Signing with a smart card isn't supported for your...

    in Windows 10 Software and Apps
    Smart card logon on windows says "Signing with a smart card isn't supported for your...: Have configured an ECDSA_P256 smart card logon certificate template on windows server 2019 DC and issued it to get enrolled on client PC.the certificate template gets enrolled well on the smart card token via mmc.exe 0 -> Add / Remove Snap-in -> Certificates -> add -> ok.in...
  6. Smart Card error

    in Windows 10 Gaming
    Smart Card error: We are having a problem with smart card error. Our customers use a smart card to access private information from the government. Patients recordsUsers connect by inserting the USB key into the computer and then clicking on the government application. They are prompted for a...
  7. Smart Card error

    in Windows 10 Drivers and Hardware
    Smart Card error: We are having a problem with smart card error. Our customers use a smart card to access private information from the government. Patients recordsUsers connect by inserting the USB key into the computer and then clicking on the government application. They are prompted for a...
  8. Certificate/PKI/Smart Card Logon

    in Windows 10 Gaming
    Certificate/PKI/Smart Card Logon: Hello,I am having an issue with authenticating users in an air gapped network after a patch. Any users prior created in AD prior to May 2022, can still authenticate with the server. However, if I create a new test account and attach my X.509 to altSecurityID attribute, I get...
  9. Certificate/PKI/Smart Card Logon

    in Windows 10 Software and Apps
    Certificate/PKI/Smart Card Logon: Hello,I am having an issue with authenticating users in an air gapped network after a patch. Any users prior created in AD prior to May 2022, can still authenticate with the server. However, if I create a new test account and attach my X.509 to altSecurityID attribute, I get...
  10. Smart Card Authentication and Cached Logons

    in AntiVirus, Firewalls and System Security
    Smart Card Authentication and Cached Logons: Hello,Scenario:Windows 10 laptops are PIV Enforced Smart cards are required to log on to the OSUser has been remote for over a year COVIDVPN is split tunnelMany users are overseas with low bandwidth connectionMost work can be done without direct access to on-prem resources,...