Enable a Smart Card Logon

Prev Next

Smart card logon does not work out of the box with Microsoft Active Directory. The PKI enablement of a Microsoft domain is performed in three main steps:

  1. Publication of necessary Certification Authority certificates to the domain.
  2. Availability of the Certificate Revocation Lists to the Domain Controllers and every machine on the network, servers included.
  3. Creation or verification of Kerberos authentication certificates for every DC in the domain.

Logon Process

Overall
logon_overall
Machine and Domain Controller interaction
logon_machine