Re: TSG 2008 / Smart card logon failes



correct

as it takes to long, ts client shows the details - he shows the ts-server
logon screen
there i see, that ts-server displays my smart card and prompt to enter the pin

but obviously the ts-server should get forwarded my credentials - at least
if i reconnect to a disconnected session the logon works fine - but not the
first time (no present session)

is this a bug?

Bruno



"Munindra Das [MSFT]" wrote:

Can you please explain your failure scenario a little more? Is my
understanding correct - You connect to a TS server through gateway. The TS
client recognises smartcard and prompts for PIN. But if you enter the PIN it
does not work and the client just dies. What exactly do you mean by - "on
the TS logon screen it takes 3-4 seconds, then smart card will be
recognised - but then nothing happens anymore - if i above case i chose the
smart card manually and enter the pin all works fine".

--

Thanks!

This posting is provided "AS IS" with no warranties, and confers no rights.

"billy frog" <billy frog@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:B8A6038D-118A-4240-A6F2-747DDC3C269F@xxxxxxxxxxxxxxxx
config:
- TSG and TS 2008 on just one box
- AD on a second box
- XP SP3 or Vista SP1 client with Gemalto .net Smart Card

problem:
- logon trough TSG with smart card fails

more:
- logon with smart card on directly on the server works fine
- logon with the smart card directly on TS 2008 works fine too
- logon with user / pwd (ntml) directly on the box or TS or even TSG / TS
works fine
- logon on TSG with smart card is also fine; on the TS logon screen it
takes
3-4 seconds, then smart card will be recognised - but then nothing happens
anymore
- if i above case i chose the smart card manually and enter the pin all
works fine
- if i do not enter it from hand, then rdp session closes after 2 minutes
- no errors in event logs or on the screens
- and finally: if i logon with user / pwd, disconnect then the session and
re-connect the disconnected session with the smart card all works fine

why the initial logon with a smart card trough TSG does not work?

we reinstalled all 2 times, spend a lot of time to understand the
problem -
for me it looks to be a bug


any suggestions?

thanks
Bruno



.



Relevant Pages

  • Re: Problems loggin in Windows Vista with a smart card enabled acc
    ... account configured for smart card logon in Windows Vista. ... in the paper published by Microsoft that is titled 'Windows Vista Smart Card ... The provider may be returning a "no PIN prompt" flag and the SC ... press CTRL + ALT + DEL to be able to log on with a different account. ...
    (microsoft.public.platformsdk.security)
  • Re: Problems loggin in Windows Vista with a smart card enabled acc
    ... account configured for smart card logon in Windows Vista. ... in the paper published by Microsoft that is titled 'Windows Vista Smart Card ... The provider may be returning a "no PIN prompt" flag and the SC ... The second tile says "other user" ...
    (microsoft.public.platformsdk.security)
  • Re: Local system and user account - registry
    ... If their account is set to to use a Smart Card then they are forced to use a Smart ... Either they logon as "User Name" or with a Smart Card. ... Since you're checking this registry value in your script I'm assuming ... or a logon with a UPN will both cause your script to ...
    (microsoft.public.security)
  • Re: Problems loggin in Windows Vista with a smart card enabled acc
    ... account configured for smart card logon in Windows Vista. ... in the paper published by Microsoft that is titled 'Windows Vista Smart Card ... press CTRL + ALT + DEL to be able to log on with a different account. ... In the hint I write the account I want to log on to: ...
    (microsoft.public.platformsdk.security)
  • Re: iis smart card logon and delegation
    ... Is the IIS server joined to the domain? ... >> Guidelines for Enabling Smart Card Logon with Third-Party Certification ... >>> after the authentication the web application tries to connect ...
    (microsoft.public.win2000.security)

Loading