<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-16736742.post2606868264964996079..comments</id><updated>2010-03-05T22:57:41.673-05:00</updated><title type='text'>Comments on [security through absurdity]: Implementing Smart Card Authentication with ASP.NE...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://securitythroughabsurdity.com/feeds/2606868264964996079/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default'/><link rel='alternate' type='text/html' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html'/><author><name>j. montgomery, CISSP, GNET, GSEC</name><uri>http://www.blogger.com/profile/12993686496556355666</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>10</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-16736742.post-4501227595919608762</id><published>2010-02-07T06:22:51.780-05:00</published><updated>2010-02-07T06:22:51.780-05:00</updated><title type='text'>Hi

Is it spossible to somehow use this solution a...</title><content type='html'>Hi&lt;br /&gt;&lt;br /&gt;Is it spossible to somehow use this solution and to have ASP.NET web application that will use ADFS 2.0 as STS and automatically authenticate users that have inserted their Smart Cards. ADFS will authenticate users agains AD.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/4501227595919608762'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/4501227595919608762'/><link rel='alternate' type='text/html' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html?showComment=1265541771780#c4501227595919608762' title=''/><author><name>zoki</name><uri>http://www.blogger.com/profile/04395343526683568053</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html' ref='tag:blogger.com,1999:blog-16736742.post-2606868264964996079' source='http://www.blogger.com/feeds/16736742/posts/default/2606868264964996079' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-16736742.post-76118811458777401</id><published>2009-07-25T15:21:40.249-04:00</published><updated>2009-07-25T15:21:40.249-04:00</updated><title type='text'>yep, you are correct - it's a mistake, - you can d...</title><content type='html'>yep, you are correct - it&amp;#39;s a mistake, - you can download the sample code linked from this post here:&lt;br /&gt;http://securitythroughabsurdity.com/2007/05/sample-code-authentication-and.html</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/76118811458777401'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/76118811458777401'/><link rel='alternate' type='text/html' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html?showComment=1248549700249#c76118811458777401' title=''/><author><name>j. montgomery, CISSP, GNET, GSEC</name><uri>http://www.blogger.com/profile/12993686496556355666</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='08515221865560167764'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html' ref='tag:blogger.com,1999:blog-16736742.post-2606868264964996079' source='http://www.blogger.com/feeds/16736742/posts/default/2606868264964996079' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-16736742.post-6510387874454578379</id><published>2009-07-24T22:52:15.030-04:00</published><updated>2009-07-24T22:52:15.030-04:00</updated><title type='text'>While I am intrigued by the usefulness of somethin...</title><content type='html'>While I am intrigued by the usefulness of something like this I am bother by many different things.  First your C# code is wrong.  Instead of Me it should be this.  Also I make the changes to my web config file as instructed and the page won&amp;#39;t compile.  Another annoyance is where is the source code that I can download?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/6510387874454578379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/6510387874454578379'/><link rel='alternate' type='text/html' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html?showComment=1248490335030#c6510387874454578379' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html' ref='tag:blogger.com,1999:blog-16736742.post-2606868264964996079' source='http://www.blogger.com/feeds/16736742/posts/default/2606868264964996079' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-16736742.post-5434884935165430091</id><published>2007-10-24T21:41:49.277-04:00</published><updated>2007-10-24T21:41:49.277-04:00</updated><title type='text'>&gt; I was wondering if we can &gt; acheive this just by...</title><content type='html'>&gt; I was wondering if we can &lt;BR/&gt;&gt; acheive this just by IIS&lt;BR/&gt;&gt; configuration changes &lt;BR/&gt;&gt; instead of any code change &lt;BR/&gt;&gt; in the app&lt;BR/&gt;&lt;BR/&gt;Depending on your requirements, you can get away with no code changes!  If all you just need to do is verify that a smart card is signed by a specific Certificate Root Authority (CA) for authentication only, then you can configure that in IIS and shouldn't need to make any application changes.&lt;BR/&gt;&lt;BR/&gt;If you need to do authorization/role validation then you will have to make some code changes or setup Smart Card to map to Window accounts and use windows Groups to limit access....</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/5434884935165430091'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/5434884935165430091'/><link rel='alternate' type='text/html' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html?showComment=1193276509277#c5434884935165430091' title=''/><author><name>j. montgomery, CISSP, GNET</name><uri>http://www.blogger.com/profile/12993686496556355666</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='08515221865560167764'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html' ref='tag:blogger.com,1999:blog-16736742.post-2606868264964996079' source='http://www.blogger.com/feeds/16736742/posts/default/2606868264964996079' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-16736742.post-3319074398786892109</id><published>2007-10-22T09:06:00.000-04:00</published><updated>2007-10-22T09:06:00.000-04:00</updated><title type='text'>Hi,We have a web application [VS 2003] using windo...</title><content type='html'>Hi,&lt;BR/&gt;We have a web application [VS 2003] using windows authentication. We need to implement smartcard authentication for that application. I was wondering if we can acheive this just by IIS configuration changes instead of any code change in the app. Can you please help us in this?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/3319074398786892109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/3319074398786892109'/><link rel='alternate' type='text/html' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html?showComment=1193058360000#c3319074398786892109' title=''/><author><name>Tamilarasan</name><uri>http://www.blogger.com/profile/04371376522031749979</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html' ref='tag:blogger.com,1999:blog-16736742.post-2606868264964996079' source='http://www.blogger.com/feeds/16736742/posts/default/2606868264964996079' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-16736742.post-6613351397885985489</id><published>2007-09-18T13:59:00.000-04:00</published><updated>2007-09-18T13:59:00.000-04:00</updated><title type='text'>In our scenario, we will have smartcard certs mapp...</title><content type='html'>In our scenario, we will have smartcard certs mapped to windows accounts in AD. Is there anyway to tell that they user used a smartcard and not their username/password to authenticate on the local machine?&lt;BR/&gt;&lt;BR/&gt;Thanks to HSPD12, we have been mandated that we will only use smartcards.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/6613351397885985489'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/6613351397885985489'/><link rel='alternate' type='text/html' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html?showComment=1190138340000#c6613351397885985489' title=''/><author><name>Automaton</name><uri>http://www.blogger.com/profile/16730928079190124343</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html' ref='tag:blogger.com,1999:blog-16736742.post-2606868264964996079' source='http://www.blogger.com/feeds/16736742/posts/default/2606868264964996079' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-16736742.post-1455135670827707598</id><published>2007-07-26T00:35:11.556-04:00</published><updated>2007-07-26T00:35:11.556-04:00</updated><title type='text'>&gt; Do you have any info on how to &gt; implement RSA S...</title><content type='html'>&gt; Do you have any info on how to &lt;BR/&gt;&gt; implement RSA SecureID token &lt;BR/&gt;&gt; authentication with ASP.net.&lt;BR/&gt;&lt;BR/&gt;I'm very curious about this as well - let me do some research and get back to you!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/1455135670827707598'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/1455135670827707598'/><link rel='alternate' type='text/html' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html?showComment=1185424511556#c1455135670827707598' title=''/><author><name>j. montgomery, CISSP, GNET</name><uri>http://www.blogger.com/profile/12993686496556355666</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='08515221865560167764'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html' ref='tag:blogger.com,1999:blog-16736742.post-2606868264964996079' source='http://www.blogger.com/feeds/16736742/posts/default/2606868264964996079' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-16736742.post-1089095416273735559</id><published>2007-07-25T13:58:00.000-04:00</published><updated>2007-07-25T13:58:00.000-04:00</updated><title type='text'>Hi J,Thanks for your article. Our company wants to...</title><content type='html'>Hi J,&lt;BR/&gt;&lt;BR/&gt;Thanks for your article. Our company wants to implement 2 factor authentication.We decided to use USA token instead of smartcard for the reason of not tampering with user computers. We use ASP.NET 2.0 with C#. Do you have any info on how to implement RSA SecureID token authentication with ASP.net. Do we need forms authentication along with this. Currently, we are planning to.&lt;BR/&gt;&lt;BR/&gt;I appreciate your response.&lt;BR/&gt;&lt;BR/&gt;Thanks, &lt;BR/&gt;Katta</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/1089095416273735559'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/1089095416273735559'/><link rel='alternate' type='text/html' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html?showComment=1185386280000#c1089095416273735559' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html' ref='tag:blogger.com,1999:blog-16736742.post-2606868264964996079' source='http://www.blogger.com/feeds/16736742/posts/default/2606868264964996079' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-16736742.post-3030252106928334449</id><published>2007-04-30T16:33:40.153-04:00</published><updated>2007-04-30T16:33:40.153-04:00</updated><title type='text'>I considered that, but I have some problems with t...</title><content type='html'>I considered that, but I have some problems with that scenario:&lt;BR/&gt;&lt;BR/&gt;1. A lot of our users who need to use this system are NOT in active directory.&lt;BR/&gt;&lt;BR/&gt;2. Management overhead. Adding 1-to-1 mapping of several thousand users is a logistical nightmare.&lt;BR/&gt;&lt;BR/&gt;3. Last, but not least, you have to know each users password setup their certificate to AD mapping. This deminishes security as someone needs to know all the users passwords other then Active Directory.&lt;BR/&gt;&lt;BR/&gt;For a smaller implementation, what you suggest is very reasonable, but for a large enterprise it doesn't scale well.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/3030252106928334449'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/3030252106928334449'/><link rel='alternate' type='text/html' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html?showComment=1177965220153#c3030252106928334449' title=''/><author><name>j. montgomery</name><uri>http://www.blogger.com/profile/12993686496556355666</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='08515221865560167764'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html' ref='tag:blogger.com,1999:blog-16736742.post-2606868264964996079' source='http://www.blogger.com/feeds/16736742/posts/default/2606868264964996079' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-16736742.post-7820101078871853564</id><published>2007-04-30T15:53:00.000-04:00</published><updated>2007-04-30T15:53:00.000-04:00</updated><title type='text'>Hey, j. montgomery!Very thorough work!You may look...</title><content type='html'>Hey, j. montgomery!&lt;BR/&gt;Very thorough work!&lt;BR/&gt;&lt;BR/&gt;You may look into simpler solution where the client certs are verified by IIS, then certs are mapped to windows accounts - no need for AD, and then role based authorization is applied either via URL authorization or principalpermission attribute&lt;BR/&gt;&lt;BR/&gt;Here is how it can be done for web services:&lt;BR/&gt;&lt;BR/&gt;&lt;BR/&gt;http://blogs.microsoft.co.il/blogs/alikl/archive/2007/01/29/SOA_2C00_-Strong-Authentication_2C00_-Standard-Authorization-_2D00_-Cool-Solution.aspx</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/7820101078871853564'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16736742/2606868264964996079/comments/default/7820101078871853564'/><link rel='alternate' type='text/html' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html?showComment=1177962780000#c7820101078871853564' title=''/><author><name>alik levin</name><uri>http://blogs.msdn.com/alikl</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securitythroughabsurdity.com/2007/04/implementing-smart-card-authentication.html' ref='tag:blogger.com,1999:blog-16736742.post-2606868264964996079' source='http://www.blogger.com/feeds/16736742/posts/default/2606868264964996079' type='text/html'/></entry></feed>