Solved

Smartcard authentication error and trusted domain Kerberos error

Posted on 2013-11-05
2
5,320 Views
Last Modified: 2013-12-13
So we have AD running with a few 2008R2 Citrix Xenapp 65 servers. We have a trusted domain where we need to get a few users to connecto to those servers.

These users have to use Smartcard and PIN to get through. We got it all to work until they are prompted for their PIN.

Once the users from the trusted domain type the PIN, it takes a few seconds (20 or so) and then we get the error message that:

The System Could Not Log you on, The Kerberos protocol encountered an error while validating the KDC certificate during smart card logon. There is more information in the event log.

I think we need to get an SSL certificate loaded somewhere to get the secure exchange going. right?

The question is, since this is an app server in a different domain from where the users are,

Would we need to load a cert on the app server?
Would we need to load a cert on the DC in that app server domain?
what kind of cert do we need, one issued from the trusted domain?

I am really newbie when it comes to smart cards and cannot figure out the answer with trusted domains.
It is a one way trust.
smartcarderror.png
0
Comment
Question by:onlinerack
2 Comments
 
LVL 25

Accepted Solution

by:
Tony Johncock earned 500 total points
ID: 39623715
You're right -  in the first instance you need to hook into a Certification Authority such as an MS PKI.

From http://support.citrix.com/proddocs/topic/xenapp65-sec/ps-sec-smart-cards-xa6.html :

Citrix continues to test smart cards to address compatibility with XenApp, using certificates from common certificate authorities such as those supported by Microsoft. If you have any concerns regarding your certificate authority and compatibility with XenApp, contact your local Citrix representative.

I must confess I've never integrated it with a trusted domain but I would presume that you would need to edit the certificates such that they have an accessible CRL published.

There are some step-by-step instructions that might help you here: http://support.citrix.com/article/CTX129096
0
 
LVL 5

Author Closing Comment

by:onlinerack
ID: 39717796
The issue is much more complicated to be posted here to come up with a solution.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question