Get the App
SLTechnology News&Howtos  ›  Servers  › 

Usb-key Log in to windows+ remote Desktop

Shulou Source: shulou.com Published: 2022-06-02 16:53:13 10月04日 Update

Preparatory work

1.1 deploy AD domain

1.1.1 refer to the AD deployment steps documentation

1.2 deploy CA

1.2.1 refer to the CA deployment steps document

1.3Configuring CA

1.3.1 configure Certification Authority

Open [Certificate Authority]-- [Properties]

Find the "Security" tab and add "Domain Users". Check "read"-"request Certificate".

Select "Authenticated Users" and check "read"-"request Certificate"

1.3.2 configure Certificate template

Select "Certificate template"-"manage"

Adjust [smart card login]-[smart card user] attribute

Open the "Security" tab and add [Domain Users] check "read"-"register" smart card users to do the same.

Return to [Certificate Authority]-[Certificate template]-[New]-[Certificate template to be issued]

Add [Smart Card Login]-[Smart Card user] template

1.3.3 configure CA to enable Https

1.4 install ePass2003

Run [AUTORUN.EXE] to install EPASS2003

Select language

Select [Private CSP] to start the installation

1.5 configure Group Policy

Run GPEDIT.MSC deployment * * computer configuration * *-> * * Policy * *-> * * WINDOWS Settings * *-> * * Security Settings * *-> * * Local Policy * *-> * * user Rights assignment * *-> * * allow login through remote Desktop Services * * to add

Expand [Security options]-[Interactive login: smart card removal behavior] is configured to [lock workstation]

[security options]-[Interactive login: smart card required] is configured to [enabled]

1.6 issue certificates

Access https://ad.usbkey.com/certsrv/ to add addresses to the zone

[apply for Certificate]-[create and submit a request to this CA]

Select [Yes] in the pop-up dialog box

Certificate template Select [Smart Card user]-key option [create New key set]-CSP

Key usage: exchange key size: 1024 good remember name: usbkey submission waiting to be completed

1.7 verify USB-KEY

We start remote Desktop to use username and password authentication to find out

After we connect to USB-KEY, the smart card pops up to verify the PIN.

Tags: Certificates smart cards configurations templates users selection login security keys institutions policies authentication desktops interactions properties documents steps references work Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno OPPO Reno MySQL Linux macOS Shulou Technology