Solved

Configure a Windows USB key for client logins

Posted on 2006-06-26
4
241 Views
Last Modified: 2010-04-11
Hi,

I am looking for a way to have my users login to there Windows XP Pro workstations using a USB memory key. I would want them to connect the key to a USB slot and just have to enter a PIN in order for them to automatically login to windows without having to enter a username or password, just a PIN.

I do not want to use any third party applications or softwares. I would like to set this up myself using Microsoft Windows. I currently have 3 servers that are domain controllers and run AD. I have about 20 workstations at one site.

I would like to know how to configure the memory key to hold a PKI if needed and how to configure the OS end. Any suggestions would definitely be appreciated.

Thank you,

Sergio
0
Comment
Question by:serg2626
4 Comments
 
LVL 7

Accepted Solution

by:
Okigire earned 500 total points
ID: 16993165
As far as I know, this can't be done natively with Windows.  You don't need to use 3rd party software per se, but if you don't you will have to custom develop your own software to interact with Windows.  As far as I know, the only login method Windows has "built in" is for smartcards.  Otherwise, you will have to modify the authentication system yourself.

I haven't done this myself, but have seen many resources on developing this... search for GINA for Windows authentication and you should get more information about the auth library and development information.
0
 
LVL 27

Expert Comment

by:Tolomir
ID: 17160935
MS is recommending 3rd party tools themself:

http://www.microsoft.com/windowsserver2003/partners/rmspartners.mspx

SafeNet technology offers USB authentication tokens that eliminate user names and passwords; SSL acceleration devices providing fast and secure online transactions; software security, and licensing products preventing software piracy.

With windows vista, you can use bitlocker:

http://www.microsoft.com/technet/windowsvista/security/bittech.mspx
BitLocker offers the option to lock the normal boot process until the user supplies a PIN, much like an ATM card PIN, or inserts a USB flash drive that contains keying material. These additional security measures provide multi-factor authentication and assurance that the computer will not boot or resume from hibernation until the correct PIN or USB flash drive are presented.


Tolomir
0

Featured Post

Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you thought ransomware was bad, think again! Doxware has the potential to be even more damaging.
This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question