pkcs11 sso (using prior windows login with smartcard)

你说的曾经没有我的故事 提交于 2019-12-19 19:43:58

问题


I wish to do the following:

  1. Login or unlock my windows account with a smartcard (I know how). The smartcard prompts for PIN.

  2. Then access a java software inside the account - and I want to use the same smartcard during its operation. However, I don't want it to prompt for PIN, but rather rely on the prior windows authentication.

Question: is this possible?

Thank you.


回答1:


If you're allowed to patch your existing login procedures, perhaps its worth it to look at pGina (http://pgina.org/), as it is a modular replacement for the GINA part of Windows.




回答2:


coming from Incorparating SSO in addition/instead SSL:

  1. When sign in into Windows with your smartcard, it peforms a pkinit and obtains a Kerberos TGT for you.
  2. When you access a further resource that TGT is used and a Kerberos service ticket is created. No smartcard cert involved.
  3. However, if you want to use the the smartcard in your app, you perform client cert auth and not Kerberos therefore the app must prompt you for your PIN.


来源:https://stackoverflow.com/questions/13873666/pkcs11-sso-using-prior-windows-login-with-smartcard

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!