Skip to main content

Smart Card

Smart card removal behavior​

Smart Card Provider supports the Windows security policy Interactive logon: Smart card removal behavior.

With this policy, you can define the action performed when a smart card is removed from the user workstation.

Timeout of the action performed on smart card removal​

The policy of the Windows Logon section defines the duration of the standard and the service timeout after the authentication device is removed.

The policy sets the time interval in seconds between the smart card removal and the action performed according to the Windows Interactive logon: Smart card enhanced removal behavior policy.

Information

The AxidianID.Client.admx policy administrative template file is included in the distribution and is located in the Misc directory.

The standard timeout prevents the computer from being locked automatically if the authentication device is removed accidentally.

The service timeout prevents the computer from being locked automatically in cases when removing the authentication device in use is necessary (registering an additional authenticator, accessing the operating system or an application under another account and with another authenticator). To activate the service timeout, press and hold the [Ctrl]+[L] key combination before removing the device.

If the policy is not set or is disabled, no timeout is provided before the workstation is locked automatically.

Use extra data​

The policy allows you to configure the enhanced security mode with the ability to write extra data to the device and read this data. The extra data mode prevents the device from being re-initialized and the authenticator from being subsequently used without authorization on behalf of the account of the actual owner.

Information

The AxidianID.Smartcard.Provider.admx policy administrative template file is included in the distribution and is located in the Misc directory.

Extra data is a sequence of 64 random bytes that is written to the smart card (USB token) and included in the authenticator along with the serial number of the authentication device. The extra data is read from the device and verified together with the serial number during user authentication.

The extra data mode is enabled if the policy setting is set to Enabled or Not Configured. Allow operation without extra data — allows the provider to work without using extra data (when the policy is enabled).

The option can be used to work with devices registered in older versions of Smart Card Provider (without extra data support).

Waiting for the smart card after logging in to a terminal session​

The policy allows you to set the time in seconds during which the smart card is awaited after logging in to a terminal session in case of incorrect operation of the PKCS smart card.