<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>HSPD-12+FIPS201 and other topics...</title>
	<atom:link href="http://fipssecinfo.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://fipssecinfo.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Wed, 25 May 2011 23:03:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='fipssecinfo.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/d3df7b2ce800a2e79e5d2cb33df459cc?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>HSPD-12+FIPS201 and other topics...</title>
		<link>http://fipssecinfo.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://fipssecinfo.wordpress.com/osd.xml" title="HSPD-12+FIPS201 and other topics..." />
	<atom:link rel='hub' href='http://fipssecinfo.wordpress.com/?pushpress=hub'/>
		<item>
		<title>HSPD-12 Logical Access Authentication and Active Directory Domains</title>
		<link>http://fipssecinfo.wordpress.com/2010/01/15/hspd-12-logical-access-authentication-and-active-directory-domains/</link>
		<comments>http://fipssecinfo.wordpress.com/2010/01/15/hspd-12-logical-access-authentication-and-active-directory-domains/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 04:59:07 +0000</pubDate>
		<dc:creator>vernonlee</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://fipssecinfo.wordpress.com/2010/01/15/hspd-12-logical-access-authentication-and-active-directory-domains/</guid>
		<description><![CDATA[Link to document available on Microsoft downloads &#8211; http://www.microsoft.com/downloads/details.aspx?displaylang=en&#38;FamilyID=b86d8fe2-a76a-4692-9983-5ee65f0f4e88<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fipssecinfo.wordpress.com&amp;blog=7526593&amp;post=19&amp;subd=fipssecinfo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p align="left">Link to document available on Microsoft downloads &#8211; <a title="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=b86d8fe2-a76a-4692-9983-5ee65f0f4e88" href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=b86d8fe2-a76a-4692-9983-5ee65f0f4e88">http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=b86d8fe2-a76a-4692-9983-5ee65f0f4e88</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fipssecinfo.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fipssecinfo.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fipssecinfo.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fipssecinfo.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fipssecinfo.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fipssecinfo.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fipssecinfo.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fipssecinfo.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fipssecinfo.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fipssecinfo.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fipssecinfo.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fipssecinfo.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fipssecinfo.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fipssecinfo.wordpress.com/19/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fipssecinfo.wordpress.com&amp;blog=7526593&amp;post=19&amp;subd=fipssecinfo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://fipssecinfo.wordpress.com/2010/01/15/hspd-12-logical-access-authentication-and-active-directory-domains/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d83042bc02f337c8ba5d1d4db33bd1d3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vernonlee</media:title>
		</media:content>
	</item>
		<item>
		<title>Windows XP Smart Card Logon, Digital Signature and Encryption Failures with Entrust SSP Issued HSPD-12 Certificates by Paul Fox, Senior Consultant, Microsoft Consulting Services</title>
		<link>http://fipssecinfo.wordpress.com/2010/01/15/windows-xp-smart-card-logon-digital-signature-and-encryption-failures-with-entrust-ssp-issued-hspd-12-certificates-by-paul-fox-senior-consultant-microsoft-consulting-services/</link>
		<comments>http://fipssecinfo.wordpress.com/2010/01/15/windows-xp-smart-card-logon-digital-signature-and-encryption-failures-with-entrust-ssp-issued-hspd-12-certificates-by-paul-fox-senior-consultant-microsoft-consulting-services/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 04:54:04 +0000</pubDate>
		<dc:creator>vernonlee</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://fipssecinfo.wordpress.com/2010/01/15/windows-xp-smart-card-logon-digital-signature-and-encryption-failures-with-entrust-ssp-issued-hspd-12-certificates-by-paul-fox-senior-consultant-microsoft-consulting-services/</guid>
		<description><![CDATA[Link to the blog entry on Microsoft FutureFed Tech &#8211; http://blogs.technet.com/futurefedtech/archive/2009/10/20/windows-xp-smart-card-logon-digital-signature-and-encryption-failures-with-entrust-ssp-issued-hspd-12-certificates-by-paul-fox-senior-consultant-microsoft-consulting-services.aspx<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fipssecinfo.wordpress.com&amp;blog=7526593&amp;post=18&amp;subd=fipssecinfo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p align="left">Link to the blog entry on Microsoft FutureFed Tech &#8211; <a title="http://blogs.technet.com/futurefedtech/archive/2009/10/20/windows-xp-smart-card-logon-digital-signature-and-encryption-failures-with-entrust-ssp-issued-hspd-12-certificates-by-paul-fox-senior-consultant-microsoft-consulting-services.aspx" href="http://blogs.technet.com/futurefedtech/archive/2009/10/20/windows-xp-smart-card-logon-digital-signature-and-encryption-failures-with-entrust-ssp-issued-hspd-12-certificates-by-paul-fox-senior-consultant-microsoft-consulting-services.aspx">http://blogs.technet.com/futurefedtech/archive/2009/10/20/windows-xp-smart-card-logon-digital-signature-and-encryption-failures-with-entrust-ssp-issued-hspd-12-certificates-by-paul-fox-senior-consultant-microsoft-consulting-services.aspx</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fipssecinfo.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fipssecinfo.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fipssecinfo.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fipssecinfo.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fipssecinfo.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fipssecinfo.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fipssecinfo.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fipssecinfo.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fipssecinfo.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fipssecinfo.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fipssecinfo.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fipssecinfo.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fipssecinfo.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fipssecinfo.wordpress.com/18/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fipssecinfo.wordpress.com&amp;blog=7526593&amp;post=18&amp;subd=fipssecinfo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://fipssecinfo.wordpress.com/2010/01/15/windows-xp-smart-card-logon-digital-signature-and-encryption-failures-with-entrust-ssp-issued-hspd-12-certificates-by-paul-fox-senior-consultant-microsoft-consulting-services/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d83042bc02f337c8ba5d1d4db33bd1d3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vernonlee</media:title>
		</media:content>
	</item>
		<item>
		<title>Catastrophic Quake Hits Haiti; Help Save a Life&#8230;</title>
		<link>http://fipssecinfo.wordpress.com/2010/01/15/catastrophic-quake-hits-haiti-help-save-a-life/</link>
		<comments>http://fipssecinfo.wordpress.com/2010/01/15/catastrophic-quake-hits-haiti-help-save-a-life/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 04:37:07 +0000</pubDate>
		<dc:creator>vernonlee</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://fipssecinfo.wordpress.com/2010/01/15/catastrophic-quake-hits-haiti-help-save-a-life/</guid>
		<description><![CDATA[As we have all seen and heard from the newscasts the country of Haiti is in dire need for aid.&#160; There are many organizations on the ground to provide assistance, representing countries from around the globe.&#160; More needs to be done to help the many people who may still be alive, buried under tons of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fipssecinfo.wordpress.com&amp;blog=7526593&amp;post=16&amp;subd=fipssecinfo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p align="left">As we have all seen and heard from the newscasts the country of Haiti is in dire need for aid.&#160; There are many organizations on the ground to provide assistance, representing countries from around the globe.&#160; More needs to be done to help the many people who may still be alive, buried under tons of concrete.&#160; I have a friend who was saved after she was buried for seventeen hours, and this really brings into focus the magnitude of this disaster.&#160; Say a prayer for the souls that are lost, the ones that have not yet been found and for those who have lost loved ones.&#160; If you are called to donate, here is a list of organizations that are on the ground, and are known for their good work.&#160; God bless and thank you!</p>
<p align="left"><strong><img style="display:inline;margin-left:0;margin-right:0;border-width:0;" title="" border="0" alt="" src="http://media.monstersandcritics.com/galleries/admin_1086/20100113_prc_d69_820.jpg" width="360" height="240" /></strong></p>
<p align="left"><strong>NetHope Haiti Emergency Response &#8211; <a title="https://secure.groundspring.org/dn/index.php?aid=10514" href="https://secure.groundspring.org/dn/index.php?aid=10514">https://secure.groundspring.org/dn/index.php?aid=10514</a></strong></p>
<p align="left"><strong>Doctors without borders</strong> &#8211; <a title="https://donate.doctorswithoutborders.org/SSLPage.aspx?pid=197&amp;hbc=1&amp;__utma=1.2707009755311606300.1263527892.1263527892.1263527892.1&amp;__utmb=1.1.10.1263527892&amp;__utmc=1&amp;__utmx=-&amp;__utmz=1.1263527892.1.1.utmcsr=bing.com%7Cutmccn=(referral)%7Cutmcmd=referral%7Cutmcct=/search&amp;__utmv=-&amp;__utmk=23734074" href="https://donate.doctorswithoutborders.org/SSLPage.aspx?pid=197&amp;hbc=1&amp;__utma=1.2707009755311606300.1263527892.1263527892.1263527892.1&amp;__utmb=1.1.10.1263527892&amp;__utmc=1&amp;__utmx=-&amp;__utmz=1.1263527892.1.1.utmcsr=bing.com%7Cutmccn=(referral)%7Cutmcmd=referral%7Cutmcct=/search&amp;__utmv=-&amp;__utmk=23734074">https://donate.doctorswithoutborders.org/SSLPage.aspx?pid=197&amp;hbc=1&amp;__utma=1.2707009755311606300.1263527892.1263527892.1263527892.1&amp;__utmb=1.1.10.1263527892&amp;__utmc=1&amp;__utmx=-&amp;__utmz=1.1263527892.1.1.utmcsr=bing.com%7Cutmccn=(referral)%7Cutmcmd=referral%7Cutmcct=/search&amp;__utmv=-&amp;__utmk=23734074</a></p>
<p align="left"><strong>Catholic Relief Services</strong> &#8211; <a title="https://secure.crs.org/site/Donation2?1080.donation=form1&amp;df_id=1080" href="https://secure.crs.org/site/Donation2?1080.donation=form1&amp;df_id=1080">https://secure.crs.org/site/Donation2?1080.donation=form1&amp;df_id=1080</a></p>
<p align="left"><strong>American Red Cross (Haiti Relief and Development)</strong> &#8211; <a title="https://american.redcross.org/site/Donation2?idb=1946232924&amp;df_id=4437&amp;4437.donation=form1&amp;JServSessionIdr004=8xigfzwt61.app196b" href="https://american.redcross.org/site/Donation2?idb=1946232924&amp;df_id=4437&amp;4437.donation=form1&amp;JServSessionIdr004=8xigfzwt61.app196b">https://american.redcross.org/site/Donation2?idb=1946232924&amp;df_id=4437&amp;4437.donation=form1&amp;JServSessionIdr004=8xigfzwt61.app196b</a></p>
<p align="left"><strong>United Way Worldwide Disaster Fund</strong> &#8211; <a title="https://volunteer.united-e-way.org/uwwwdisaster/donate/" href="https://volunteer.united-e-way.org/uwwwdisaster/donate/">https://volunteer.united-e-way.org/uwwwdisaster/donate/</a></p>
<p align="left"><strong>Food for the Poor</strong> &#8211; <a title="https://secure3.convio.net/ffp/site/Donation2?df_id=6320&amp;6320.donation=form1" href="https://secure3.convio.net/ffp/site/Donation2?df_id=6320&amp;6320.donation=form1">https://secure3.convio.net/ffp/site/Donation2?df_id=6320&amp;6320.donation=form1</a></p>
<p>Remember when you donate to follow your employers process for “Matching Gifts” – HR is a good place to start if this is not easily found within your organization.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fipssecinfo.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fipssecinfo.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fipssecinfo.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fipssecinfo.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fipssecinfo.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fipssecinfo.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fipssecinfo.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fipssecinfo.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fipssecinfo.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fipssecinfo.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fipssecinfo.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fipssecinfo.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fipssecinfo.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fipssecinfo.wordpress.com/16/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fipssecinfo.wordpress.com&amp;blog=7526593&amp;post=16&amp;subd=fipssecinfo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://fipssecinfo.wordpress.com/2010/01/15/catastrophic-quake-hits-haiti-help-save-a-life/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d83042bc02f337c8ba5d1d4db33bd1d3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vernonlee</media:title>
		</media:content>

		<media:content url="http://media.monstersandcritics.com/galleries/admin_1086/20100113_prc_d69_820.jpg" medium="image" />
	</item>
		<item>
		<title>Logical Access (smart card logon) requirement and PIV cards</title>
		<link>http://fipssecinfo.wordpress.com/2009/04/27/pivlogicalaccess/</link>
		<comments>http://fipssecinfo.wordpress.com/2009/04/27/pivlogicalaccess/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 18:45:23 +0000</pubDate>
		<dc:creator>vernonlee</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[FIPS-201]]></category>
		<category><![CDATA[HSPD-12]]></category>
		<category><![CDATA[PIV]]></category>
		<category><![CDATA[Smart Card]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Homeland Security Presidential Directive-12 and FIPS 201-1 topics are still the subject of much confusion on how to implement, across the federal government.&#160; After several years of establishing the systems to issue the Personal Identity Verification (PIV) credentials, the focus is now around usage of the PIV cards for logical access and physical access rather [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fipssecinfo.wordpress.com&amp;blog=7526593&amp;post=1&amp;subd=fipssecinfo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.idmanagement.gov/documents/HSPD-12.htm" target="_blank">Homeland Security Presidential Directive-12</a> and <a href="http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf" target="_blank">FIPS 201-1</a> topics are still the subject of much confusion on how to implement, across the federal government.&#160; After several years of establishing the systems to issue the Personal Identity Verification (PIV) credentials, the focus is now around usage of the PIV cards for logical access and physical access rather than simply another ID badge.&#160;&#160; Some of the larger agencies i.e.&#160; USDA, Department of State and others have figured out the requirements to use these credentials in their networks for smart card logon primarily with Microsoft Windows; however, many smaller agencies still have questions on what to do next.</p>
<p><a href="http://fipssecinfo.wordpress.com/2009/04/27/pivlogicalaccess/cid_image008_jpg01c9c7541/" rel="attachment wp-att-5"><img style="display:inline;margin-left:0;margin-right:0;" class="alignleft size-full wp-image-5" title="PIVCard" alt="PIVCard" src="http://fipssecinfo.files.wordpress.com/2009/04/cid_image008_jpg01c9c7541.jpg?w=64&#038;h=93" width="64" height="93" /></a></p>
<p>&#160;</p>
<p>&#160;</p>
<p>&#160;</p>
<p>What this blog entry is NOT intended to be:</p>
<ul>
<li>A debate about a common Federal Identity namespace and authentication directory. </li>
<li>A debate about Microsoft Windows versus other operating systems. </li>
<li>A debate about the Shared Service Provider or Managed Service Offering models. </li>
<li>A debate about the effectiveness of PKI bridges or hierarchies. </li>
</ul>
<p>This blog entry is intended to:</p>
<ul>
<li>Provide information so that anyone with a requirement for logical access using PIV cards will know what the steps are they can take to help meet HSPD-12 and OMB 05-24. </li>
</ul>
<p>First to support the use of smart cards for network authentication, we assume that the agency or department has already completed the following, in accordance with the dates established by the OMB.</p>
<ol>
<li>Implemented a compliant FIPS-201-1 PIV Card Issuing (PCI) System, or have signed with either GSA&#8217;s managed service offering &#8211; <a href="http://fedidcard.gov/" target="_blank">USAccess</a> or another shared service provider solution for user sponsorship, registration, issuance and activation of the PIV credential. </li>
<li>Have selected a PIV middleware vendor and solution for use in the organization. </li>
<li>Have selected a smart card reader compatible with the OS and approved for use on FIPS201 <a href="http://fips201ep.cio.gov/apl.php" target="_blank">Approved Products List</a>. </li>
</ol>
<p>In addition to the aforementioned items, if the agency is planning on using the PIV cards for smart card logon, to Microsoft Windows XP, Windows Vista or later operating system, then the following requirements must also be addressed by the organization to successful logon with the PIV cards to the network.</p>
<p>Microsoft Windows XP SP2 and SP3, in a Microsoft Windows Server 2003 forest has the following requirements for smart card logon.&#160; With Windows Vista and the upcoming Windows 7, the UPN and Smart Card Logon EKU are optional, more information is available <a href="http://msdn.microsoft.com/en-us/library/bb905527.aspx" target="_blank">here</a>;&#160; however, for today let&#8217;s focus on Microsoft Windows XP.</p>
<ul>
<li>The x.509 certificate issued to the end entity must have enhanced key usage of Smart Card Logon (1.3.6.1.4.1.311.20.2.2) and Client Authentication (1.3.6.1.5.5.7.3.2), the subject alternative name field must be populated with a UPN value. </li>
<li>The x.509 certificate issued to the end entity must have the CRL Distribution Point (CDP) populated. </li>
<li>Key usage must be of type &quot;Digital Signature&quot;. </li>
</ul>
<p>For HSPD-12 PIV card certificates issued under the <a href="http://www.cio.gov/fpkipa/documents/CommonPolicy.pdf" target="_blank">Federal Common Policy Framework</a>, these certificate properties are populated and meet the requirements.&#160; However, there are infrastructure requirements that also need to be addressed by each agency, wishing to use their employee and contractor PIV cards for network smart card logon.&#160; The order of steps below are of no particular significance, however, all must be completed for a successful implementation.</p>
<ol>
<li>The issuing CA, that issued the user&#8217;s PIV_authentication certificate MUST be trusted by the organization&#8217;s forest in the NTAuth container.&#160; A copy fo the certificate from the CA in a base64 encoded file format can be published by an Enterprise Administrator or Schema Administrator from a member server using CERTUTIL -DSPUBLISH [&quot;nameofthefile&quot;].CER NTAuthCA.&#160; This step basically states that the CA is trusted by the forest and domain controllers (DCs) for issuing of credentials to be used for network authentication. </li>
<li>The ROOT CA of the certificate chain must be trusted by each client and DC that will participate in the network authentication process.&#160; For HSPD-12, this will almost always be the &quot;<a href="http://207.123.243.200/CommonPolicy/CommonPolicyRoot.p7c" target="_self">Common Policy</a>&quot; or the Federal Bridge Cross Certification Root, depending on how the agency established their trust to the federal root CAs.&#160; For the certificate to be trusted, there are several ways to get the certificate, 1) Microsoft Certificate Update Program, clients configured properly will download this file from the Microsoft Update site, 2) download from the AIA location in a subordinate certificate and publish to forest manually, 3) acquire from GSA, or Federal PKI Policy Authority (<a href="http://www.cio.gov/fpkipa/" target="_blank">FPKIPA</a>) and publish manually.&#160; To manually publish the file to the organization&#8217;s forest so that all clients and DCs will trust the root, use CERTUTIL -DSPUBLISH [&quot;nameoffile&quot;].CER RootCA from a domain member server with Enterprise or Schema Administrator rights. </li>
<li>The CDP and\or the Online Certificate Status Protocol (OCSP) responder referenced in the leaf certificates must be accessible by the DCs that will process the authentication request.&#160; Note, if you have NOT deployed Microsoft Windows Server 2008 and OCSP is your preferred validation method, then a third party OCSP client will be required.&#160; OCSP client functionality is an inherent capability in Microsoft Windows Vista, Windows 7 and Windows Server 2008. </li>
<li>Each DC server that will process authentication requests, MUST also be issued a DC Authentication Certificate for mutual authentication with the clients during the <a href="http://www.ietf.org/rfc/rfc4556.txt" target="_blank">Kerberos PKINIT </a>process. This DC Authentication certificate can be an internally issued certificate, exclusive of the PKI chain used for the PIV credentials.&#160; FIPS and the x.509 Common Policy Framework intends on issuing strong credentials to users at the MEDIUM and HIGH Assurance Profiles; it is important to note that each of these profiles requires a face to face identity vetting process.&#160; The administrators for DCs are not likely to request DC Authentication certificates by meeting with the issuance authority face to face for each DC.&#160; Therefore, an internal Microsoft Windows Server 2003 or 2008 CA deployed in accordance with the organization&#8217;s policies is capable of automatically enrolling, renewing and deploying the certificates to the DCs; this process is called &quot;auto enrollment and auto renewal&quot;.&#160;&#160; However, if the agency&#8217;s policy requires the use of a third party CA or purchase of certificates from a service provider, the certificates can be requested using PKCS and installed on each DC manually.&#160; The external DC certificate process requires a manual request, installation, renewal and maintenance of the DC Authentication certificates.&#160; In addition, for external DC Authentication certificates, each client on your network will require access to the CDP, OCSP and AIA locations in the DC certificates for validation during the PKIINT process; if the root for the DC certificates is not already trusted, a trust as previously described will need to be established. </li>
</ol>
<p>The following are additional items that should be verified, for the smart card logon process to be successful&#8230;</p>
<ol>
<li>Each client machine MUST also be a member of the forest/domain that they will attempt to authenticate to; non-domain joined machines cannot participate in smart card logon. </li>
<li>Each user object in the forest must have a matching UPN value in certificate.&#160; For example, John Doe at agency.gov with a PIV card from USAccess issued with <a href="mailto:19202837@fedidcard.gov">19202837@fedidcard.gov</a>as the UPN will not authenticate if the domain user object has a UPN of <a href="mailto:john.doe@agency.gov">john.doe@agency.gov</a>.&#160; Therefore, the UPN in the domain will need to be changed to match the value in the certificate, and the suffix &quot;fedidcard.gov&quot; must be added to the forest.&#160; Click <a href="http://technet.microsoft.com/en-us/library/cc739093.aspx" target="_self">here </a>for more information.&#160; Of course if you submitted the user&#8217;s registration to USAccess with your own internal UPN values, then no change should be required for the authentication to work.&#160; USAccess supports both options, and agencies with their own PCI System will have flexibility to use whatever value makes the most sense for their implementation.&#160; </li>
</ol>
<p style="text-align:center;"><strong>This posting is provided &quot;AS IS&quot; with no warranties,&#160; and confers no rights.</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fipssecinfo.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fipssecinfo.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fipssecinfo.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fipssecinfo.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fipssecinfo.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fipssecinfo.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fipssecinfo.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fipssecinfo.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fipssecinfo.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fipssecinfo.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fipssecinfo.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fipssecinfo.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fipssecinfo.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fipssecinfo.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fipssecinfo.wordpress.com&amp;blog=7526593&amp;post=1&amp;subd=fipssecinfo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://fipssecinfo.wordpress.com/2009/04/27/pivlogicalaccess/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d83042bc02f337c8ba5d1d4db33bd1d3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vernonlee</media:title>
		</media:content>

		<media:content url="http://fipssecinfo.files.wordpress.com/2009/04/cid_image008_jpg01c9c7541.jpg" medium="image">
			<media:title type="html">PIVCard</media:title>
		</media:content>
	</item>
	</channel>
</rss>
