Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > "Prevent plaintext PINs from being returned by credential manager"

Reply
Thread Tools Display Modes

"Prevent plaintext PINs from being returned by credential manager"

 
 
Egil Martinsen
Guest
Posts: n/a

 
      03-30-2009
Hello,

I have three questions regarding the GPO setting "Prevent plaintext PINs
from being returned by credential manager" do? It is found under Computer
Configuration -> .. -> ADMX -> Windows Components -> Smartcard.

1. The explanation found in the group policy editor states that: "If you
enable this setting, credential manager does not return a plaintext PIN". The
question is then: To whom will it not return a plaintext PIN? To the LSA? To
the BaseCSP? To a random user asking for it?

2. When this setting is enabled, what encryption algorithm is used on the
PIN, and what key is used?

3. When this setting is enabled, smartcard login works fine. However,
smartcard enrollment does not work - when enrolling, the following message is
displayed after entering the smartcard PIN the first time in the enrollment
process: "Computer Policy prohibits performing this operation because the
card does not support the required level of security".
The question is: Why does login work with this setting, but not signing?

Thank you very much!
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Problems with the "Require trusted path for credential entry" setting rrm Windows Vista Security 3 09-19-2008 12:22 PM
How to change "require trusted path for credential entry" chenoa Windows Vista Administration 0 01-25-2008 12:05 PM
Problem setting WinCE RAS server user credential directly from "hashed" password Yvan M. Windows Vista Drivers 0 01-04-2005 02:59 PM
Media Player "Pins" techwannaknow Windows Media Player 0 06-01-2004 11:34 PM
Windows cant play because the "pins" are connected?? PEte Windows Media Player 1 04-29-2004 01:27 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59