Re: [Fed-Talk] Apple Smart Card Setup Guide (was Disabling password login in favor of CAC)
Re: [Fed-Talk] Apple Smart Card Setup Guide (was Disabling password login in favor of CAC)
- Subject: Re: [Fed-Talk] Apple Smart Card Setup Guide (was Disabling password login in favor of CAC)
- From: Paul Nelson <email@hidden>
- Date: Tue, 29 Aug 2006 10:56:27 -0500
- Thread-topic: [Fed-Talk] Apple Smart Card Setup Guide (was Disabling password login in favor of CAC)
on 8/29/06 10:00 AM, Timothy J. Miller at email@hidden wrote:
>> If PKI were used,
>> some arbitrary data would be encrypted using the smart card private key, and
>> then decrypted using a certificate stored with the user's account info.
>
> Authentication with PKI is a one step process: verify that the user
> possesses the private key corresponding to the certificate presented.
We are agreeing here. For proper authentication, the system must verify
that the user possesses the private key. Apple's CAC login does not do
this.
Paul Nelson
Thursby Software Systems, Inc.
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Fed-talk mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden