none
UAG Portal with Smart Card

    Question

  • Hello,

    Please help me. How to set, required smart card authentication on the UAG Portal?

    Saturday, March 12, 2011 6:31 AM

Answers

All replies

  • Using Smartcard authentication is a case of selecting it from the authentication options. Are you actually looking for assistance in creating the whole PKI environment that you need to have in place?


    Keith Alabaster - MVP/Forum Moderator
    Saturday, March 12, 2011 9:01 AM
  • Hello,

    Thank you answhere.

    No, we have Active Directory with Enterprise CA. The UAG join to the AD. I don't find, where the smart card authentication options in the UAG. I create https trunk. I set everything, but I don't find the smart card authentication. If I open the default UAG portal (test.com), I can use only the username and password authetication.

    Saturday, March 12, 2011 11:39 AM
  • Hi,

    See http://technet.microsoft.com/en-us/library/ee861163.aspx , as well as the other TechNet articles referenced in this one.


    -Ran
    • Marked as answer by nlb84 Wednesday, March 16, 2011 12:25 PM
    Sunday, March 13, 2011 7:40 AM
  • Hi Ran,

    I found this webpage, but doesnt work these settings. I don't know why.

     

    Sunday, March 13, 2011 8:42 AM
  • Hi,

    The article provided by Ran is very useful. I used it a lot, and has always make my authenticcation by certificates with successful.

    Take care about the "match" between one (ore more) field from the certificates againts your LDAP server.
    In some case, you have to modify the repositorytype.xml, in the goal to add another attribute for the login in your LDAP field (like CN, ...). This value had to be <LoginNameAttr>

    The best way for troubleshoot this scenraio is to use first Netmon on UAG. With Netmon, you will be able to capture the LDAP Query.
    Then, open ldp.exe and reproduce the LDAP Query. If you have 0 or 2 (or more results) the authentication will failed. You will have to refine your query (by looking for the good LDAP attributes).

    Hope I'm clear.

    Regards,
    Alex


    GIRAUD Alexandre - MVP Forefront France http://www.alexgiraud.net/blog
    Tuesday, March 15, 2011 3:04 PM
  • Thank you very much everybody!

    The link was worked.

     

    Wednesday, March 16, 2011 12:26 PM