pkcs11 sso (using prior windows login with smartcard)

不想你离开。 提交于 2019-12-01 18:06:52

If you're allowed to patch your existing login procedures, perhaps its worth it to look at pGina (http://pgina.org/), as it is a modular replacement for the GINA part of Windows.

Michael-O

coming from Incorparating SSO in addition/instead SSL:

  1. When sign in into Windows with your smartcard, it peforms a pkinit and obtains a Kerberos TGT for you.
  2. When you access a further resource that TGT is used and a Kerberos service ticket is created. No smartcard cert involved.
  3. However, if you want to use the the smartcard in your app, you perform client cert auth and not Kerberos therefore the app must prompt you for your PIN.
易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!