Monday, July 2, 2012

Managing Smartcards without a CMS

One of the most common activities for managing an environment with smart cards is the issuing of a temporary card.

A Card Management System (CMS) usually takes care of the revocation of certificates, recycling of cards and reset of PIN. The system described in Password=BAD, SmartCards=GOOD could be better suit a Small Business if we make some minor tweaks.

This procedure will allow an administrator to issue a “Temporary Card” to a user who has left their card at home.

Create additional Smartcard User Templates

To alleviate the requirement for operators to manually administer certificates and to simplify the enrolment process, create certificate templates for each class of temporary card.

clip_image002

·         Open the Certification Authority MMC

·         Click Action > Manage

clip_image004

·         Select the Smartcard User Template

·         Click Action > Duplicate Template

 

Follow this procedure to create 3 Templates

·         365 Day Permanent Card

·         1 Day Temporary Card

·         7 Day Temporary Card

clip_image006

·         Select Windows Server 2003 Enterprise

·         Click OK

clip_image008

·         Enter a Name for the Certificate Template

·         Change the Validity period to suit the Template type

o   1 Day

o   1 Week

o   1 Year

·         Click Apply

clip_image010

·         Select the Issuance Requirements Tab

·         Select This Number of Authorised Signatures

·         Enter 1

·         Change Application Policy to Certificate Request Agent

·         Click Apply

·         Click OK

Repeat until all Certificate Templates have been created

clip_image012

Click File > Exit

clip_image014

Certificate Templates needs to be added to the Issuing CA

·         Click Action > New > Certificate Template to Issue

clip_image016

·         Select all new templates

·         Press OK

clip_image018

·         Select Smartcard User

·         Click Action > Delete

clip_image020

·         Click Yes

Reset the Smartcard

Open .NET Utilities from the Gemalto Site

clip_image022

Chances are when you pick up a Temporary Card you will not know the PIN

clip_image024

·         Try to change the PIN a few times to Block the Card

clip_image026

·         Select Unblock PIN

·         Enter a new PIN

·         Confirm the new PIN

·         Click Unblock

clip_image028

·         Confirm successful unblock

·         Click OK

 

clip_image030

·         Click Manage Certificates

·         Select each existing certificate in turn

·         Press Delete

clip_image032

·         Confirm correct certificate

·         Press OK

clip_image034

·         Enter the Card PIN

Note this is why we reset the PIN earlier.

You could have asked the user who last held the cards but chances are this is the PIN they use for their permanent card :(

clip_image036

·         Press OK

Issue a Smartcard

clip_image038

·         Click > Action > Advanced Operations > Enroll On Behalf Of

 

clip_image040

·         Click Next

 

clip_image042 

·         Click Browse

 

clip_image044

·         Select the Certificate created previously

·         Click OK

 

clip_image046

·         Click Next

 

clip_image048

·         Select Smartcard User

·         Click Properties

 

clip_image050

·         Deselect Microsoft Strong Cryptographic Provider

·         Select Microsoft Base Smart Card Crypto Provider

·         Click Apply

·         Click OK

 

clip_image052

·         Click Next

 

clip_image054 

·         Enter the User name (including Domain)

·         Click Enroll

 

clip_image056

·         Insert the Smartcard

 

clip_image058

See here is one of mine J

 

clip_image060

·         Enter the Smartcards PIN

 

clip_image062

·         Observe STATUS: Succeeded

·         Click Next User or Close

 

 

No comments:

Post a Comment