智能卡验证


 

This feature provides an additional authentication option for ADManager Plus login by enabling the use of smart cards/ PKI/ certificates to grant access to the tool. Smart card authentication strengthens the security further because getting access to ADManager Plus shall then require the user to possess the smart card and know the personal identification number (PIN) as well.

 

When the user attempts to access ADManager Plus' web-interface, he/ she would be allowed to proceed further only after completing smart card authentication in the machine, i.e., by presenting the smart card and subsequently entering the PIN. ADManager Plus' web-interface supplements smart card technology with SSL communication. So, the user is prompted to specify the X.509 certificate for getting access.

 

The users can choose to provide the certificate from the smart card or the local certificate store, in which case ADManager Plus performs the steps to authenticate the user with the certificate. The users can also choose to decline providing the certificate and the tool takes them to the usual login page for authentication.

 

If you have a smart card authentication system enabled in your environment, you can configure ADManager Plus to authenticate users through it, bypassing other first factor authentication methods.

 

Steps to configure smart card authentication settings:

 

1. Click the Admin tab.


2. SSL port must be enabled for configuring smart card authentication settings. To check your SSL port settings, click Connection link provided under General SettingsIf not enabled already, select the check box Enable SSL Port [https]and specify the port number in the field. Click Save Changes.


3. Click Smart Card Authentication link under General Settings.


4. To enable smart card authentication, select 'enabled' in the option Smart Card Authentication is.


5. Click Add Smart Card Configuration button.


6. Under the section Add Smart Card Configuration,

7. Click the small arrow sign next to the section OCSP Settings to expand the menu

During authentication, ADManager Plus checks for certificate revocation status against an Online Certificate Status Protocol (OCSP) server, with details available in the certificate itself. If some certificates do not have OCSP information, the information provided in the settings here will be used. 

8. Click Save.

 

9. Similarly, you can add more certificates by following the steps above.