Allow for the username hint when using x.509 smart card logon.
1 vote
My organization uses the x.509 username hint to allow us to use one smart card to authenticate as multiple identities. However, I don't see that as an option under the x.509 certificate entries. Can you please add that so we can utilize that field when logging onto remote hosts via RDP?
https://learn.microsoft.com/en-us/windows/security/identity-protection/smart-cards/smart-card-certificate-requirements-and-enumeration
https://www.idmanagement.gov/implement/scl-windows/
Hello
Thanks for the feature request.
This is likely to be possible, but technically it might be a challenge. The RDP ActiveX control (and I assume you're talking about RDP here) provided by Microsoft and mstsc itself only accepts username/password credentials. We're able to get it to use a smart card certificate by calling a Windows function that's designed for passing certificate credentials in such cases - the certificate thumbprint gets marshalled as a serialized string, that the RDP control (and application) can recognize as a PIV certificate. Optionally the password field contains the smart card PIN. At that point the Microsoft side of the stack takes over and either proceeds with authentication or prompts you for the PIN as needed.
Unfortunately, none of this has a provision for providing the username hint.
By API hooking we're able to create a credential ourselves and pass it to the LSA as the appropriate structure. This approach can theoretically work, it does accommodate the username hint, but the trouble is in actually constructing the credential itself in terms of what's expected by Windows (and this can vary wildly depending on the key storage provider, the smart card middleware, etc etc). Honestly I'd need to try it because we've had mixed results in the past. Can you share some information about the smart card vendor and middleware you're using? Feel free to send me a PM if you prefer to keep it private.
There may be other options using a third-party RDP engine, although I'd think that won't be much easier (FreeRDP, for example, still uses the Windows security providers when running on Windows, fundamentally not different to Microsoft's own RDP clients).
So, in short, it should be possible but it's more of a challenge than just adding a field. I need to investigate to understand how challenging that is. Let me know about the hardware and middleware and I'll also raise the question internally with my colleagues who are more focused on this area.
Please let me know if something isn't clear
Kind regards,
Richard Markievicz