RE: SmartCard Your credentials could not be verified.

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi,
Thanks for your email.
This error happens on all client PCs, Smartcard login works fine on the
server itself.
I'm not using using any third party certificates.
I just can't work out why my client PC s think the server certificate is
invalid.
If i type: Certuirl -scinfo on one of the client PCs everything looks fine.

Regards
Paul Mckenna


"Jason Tan (MSFT)" wrote:

> Hi Paul,
>
> Thanks for posting!
>
> Please help me know if all the clients encountered this issue£®
>
> Based on my research, I would like to suggest you refer to the following
> article to enable smart card:
>
> 281245 Guidelines for enabling smart card logon with third-party
> certification
> http://support.microsoft.com/?id=281245
>
> Additionally, I would like to suggest you try the following article to
> resolve the issue.
> 329433 A Revoked Certificate Is Selected If a Certification Authority in
> the Chain Has Two Certificates
> http://support.microsoft.com/default.aspx?scid=kb;en-us;329433
>
> Hope the information helps. If there is anything that is unclear, please
> feel free to let me know.
>
> Thanks & Regards,
>
> Jason Tan
>
> Microsoft Online Partner Support
> Get Secure! - www.microsoft.com/security
>
> =====================================================
>
> When responding to posts, please "Reply to Group" via your newsreader so
> that others may learn and benefit from your issue.
>
> =====================================================
> This posting is provided "AS IS" with no warranties, and confers no rights.
>
>
>
> --------------------
> | Thread-Topic: SmartCard Your credentials could not be verified.
> | thread-index: AcWSEmsX/nBa3wY3Qqacrl2Rq3RLWA==
> | X-WBNR-Posting-Host: 212.47.74.62
> | From: =?Utf-8?B?UGF1bCBNY2tlbm5h?= <PaulMckenna@xxxxxxxxxxxxxx>
> | Subject: SmartCard Your credentials could not be verified.
> | Date: Tue, 26 Jul 2005 11:47:05 -0700
> | Lines: 16
> | Message-ID: <BE9950FA-59F3-4A02-85EC-7F8DBE346EE1@xxxxxxxxxxxxx>
> | MIME-Version: 1.0
> | Content-Type: text/plain;
> | charset="Utf-8"
> | Content-Transfer-Encoding: 7bit
> | X-Newsreader: Microsoft CDO for Windows 2000
> | Content-Class: urn:content-classes:message
> | Importance: normal
> | Priority: normal
> | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
> | Newsgroups: microsoft.public.windows.server.general
> | NNTP-Posting-Host: TK2MSFTNGXA03.phx.gbl 10.40.2.250
> | Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGXA03.phx.gbl
> | Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.windows.server.general:43371
> | X-Tomcat-NG: microsoft.public.windows.server.general
> |
> | Howdy People,
> |
> | Can someone point me in the right direction i'm trying to setup smartcard
> | login but i keep getting the error message "Your credentials could not be
> | verified. "
> | In the event log of the client PC i get "The client has failed to
> validate
> | the Domain Controller certificate for %servername% . The error data
> contains
> | the information returned from the certificate validation process.
> Contact
> | your system administrator to determine why the Domain Controller
> certificate
> | is invalid."
> | How do i find out why the cert is invalid?
> |
> | Thanks in advance for any help.
> |
> | Regards
> | Paul Mckenna
> |
>
>
.



Relevant Pages

  • Re: Need for encryption in WSE 3.0 if using SS-avoid man-in-middle
    ... SSL only validates you are talking to a SSL certified server; ... They can simply edit the URL the client program ... can be done by using a X.509 certificate on both ends, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: LDP client authentication fails
    ... I got the LDP working with LDAP server under server client authentication ... I did not installed the certificate in pfx format .. ... Client cert auth won't work without that. ...
    (microsoft.public.windows.server.active_directory)
  • Re: SSL & Man In the Middle Attack
    ... >> it possible for the middle man to intercept all messages from server to me ... > server sends client a signed message along with a digital certificate. ... > client generates a random secret key, ...
    (comp.security.misc)
  • Re: activesync issue
    ... On the SBS 2003 Server open the Server Management console. ... On the "Web Server Certificate" page, choose to create a new Web server ... Install the new certificate which created in above step on mobile device: ... Access to browse the Exchange Server 2003 client after you install ...
    (microsoft.public.windows.server.sbs)
  • [Full-disclosure] VMSA-2006-0010 - SSL sessions not authenticated by VC Clients
    ... X.509 certificate when creating an SSL session, ... Both the client and server need certificates from a mutually-trusted ... VirtualCenter 2.0.1 Patch 1 and VirtualCenter 1.4.1 Patch ...
    (Full-Disclosure)