<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SharePoint and SmartCards (CAC Cards)</title>
	<atom:link href="http://www.sharepointsecurity.com/sharepoint/sharepoint-security/sharepoint-and-smartcards-cac-cards/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sharepointsecurity.com/sharepoint/sharepoint-security/sharepoint-and-smartcards-cac-cards/</link>
	<description>The Authorative Resource For SharePoint Security Articles, Research, Software, And Security Integration Consulting</description>
	<lastBuildDate>Thu, 11 Mar 2010 20:38:00 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: adam</title>
		<link>http://www.sharepointsecurity.com/sharepoint/sharepoint-security/sharepoint-and-smartcards-cac-cards/comment-page-1/#comment-25214</link>
		<dc:creator>adam</dc:creator>
		<pubDate>Tue, 02 Feb 2010 17:45:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.sharepointsecurity.com/blog/sharepoint/sharepoint-2007-security/sharepoint-and-smartcards-cac-cards/#comment-25214</guid>
		<description>I would firstly look at the other CAC card / SharePoint articles on this site, particuarlly this one by Noni:

http://www.sharepointsecurity.com/sharepoint/cac-enabled-anonymous-sharepoint-sites/</description>
		<content:encoded><![CDATA[<p>I would firstly look at the other CAC card / SharePoint articles on this site, particuarlly this one by Noni:</p>
<p><a href="http://www.sharepointsecurity.com/sharepoint/cac-enabled-anonymous-sharepoint-sites/" rel="nofollow">http://www.sharepointsecurity.com/sharepoint/cac-enabled-anonymous-sharepoint-sites/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brett</title>
		<link>http://www.sharepointsecurity.com/sharepoint/sharepoint-security/sharepoint-and-smartcards-cac-cards/comment-page-1/#comment-25213</link>
		<dc:creator>Brett</dc:creator>
		<pubDate>Tue, 02 Feb 2010 17:00:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.sharepointsecurity.com/blog/sharepoint/sharepoint-2007-security/sharepoint-and-smartcards-cac-cards/#comment-25213</guid>
		<description>Hello.
I&#039;m in a similar position - setting up CAC access through ISA 2006 sp1 w/KCD to our share point 2007 server farm, using ISA to load balance the Sharepoint servers.

I&#039;ve had no problem setting up OWA, but share point is now giving me the following errors:

Summary:
Web browser is sending a www-authenticate head filed that the web server is not configured to accept:
HTTP Error 401.2 - Unauthorized,: Access is denied due to server configuration.
Internet Information Services (IIS).

The ISA and Sharepoint servers exist in the same domain, the users all exist in AD, the basics all seem correct. Not sure the Sharepoint guys are completely configured for Kerberos yet (It&#039;s on our test network, of course).

I&#039;ve set up an SPN in the domain service account used for the Sharepoint application pool identity, and enabled delegation from ISA to the service account.

I&#039;d certainly appreciate an email so that I could perhaps speak with you, or perhaps links to some more docs. It seems to be sparse, using CAC w/ISA &amp; Smartcard authenticatio

Thanks in advance!.</description>
		<content:encoded><![CDATA[<p>Hello.<br />
I&#8217;m in a similar position &#8211; setting up CAC access through ISA 2006 sp1 w/KCD to our share point 2007 server farm, using ISA to load balance the Sharepoint servers.</p>
<p>I&#8217;ve had no problem setting up OWA, but share point is now giving me the following errors:</p>
<p>Summary:<br />
Web browser is sending a www-authenticate head filed that the web server is not configured to accept:<br />
HTTP Error 401.2 &#8211; Unauthorized,: Access is denied due to server configuration.<br />
Internet Information Services (IIS).</p>
<p>The ISA and Sharepoint servers exist in the same domain, the users all exist in AD, the basics all seem correct. Not sure the Sharepoint guys are completely configured for Kerberos yet (It&#8217;s on our test network, of course).</p>
<p>I&#8217;ve set up an SPN in the domain service account used for the Sharepoint application pool identity, and enabled delegation from ISA to the service account.</p>
<p>I&#8217;d certainly appreciate an email so that I could perhaps speak with you, or perhaps links to some more docs. It seems to be sparse, using CAC w/ISA &amp; Smartcard authenticatio</p>
<p>Thanks in advance!.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: adam</title>
		<link>http://www.sharepointsecurity.com/sharepoint/sharepoint-security/sharepoint-and-smartcards-cac-cards/comment-page-1/#comment-25079</link>
		<dc:creator>adam</dc:creator>
		<pubDate>Fri, 06 Nov 2009 17:52:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.sharepointsecurity.com/blog/sharepoint/sharepoint-2007-security/sharepoint-and-smartcards-cac-cards/#comment-25079</guid>
		<description>http://www.sharepointsecurity.com/sharepoint/cac-enabled-anonymous-sharepoint-sites/</description>
		<content:encoded><![CDATA[<p><a href="http://www.sharepointsecurity.com/sharepoint/cac-enabled-anonymous-sharepoint-sites/" rel="nofollow">http://www.sharepointsecurity.com/sharepoint/cac-enabled-anonymous-sharepoint-sites/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GReddy</title>
		<link>http://www.sharepointsecurity.com/sharepoint/sharepoint-security/sharepoint-and-smartcards-cac-cards/comment-page-1/#comment-25078</link>
		<dc:creator>GReddy</dc:creator>
		<pubDate>Fri, 06 Nov 2009 17:04:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.sharepointsecurity.com/blog/sharepoint/sharepoint-2007-security/sharepoint-and-smartcards-cac-cards/#comment-25078</guid>
		<description>Can you please provide the URL for the guide?</description>
		<content:encoded><![CDATA[<p>Can you please provide the URL for the guide?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: robin</title>
		<link>http://www.sharepointsecurity.com/sharepoint/sharepoint-security/sharepoint-and-smartcards-cac-cards/comment-page-1/#comment-24891</link>
		<dc:creator>robin</dc:creator>
		<pubDate>Tue, 15 Sep 2009 20:13:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.sharepointsecurity.com/blog/sharepoint/sharepoint-2007-security/sharepoint-and-smartcards-cac-cards/#comment-24891</guid>
		<description>You posted
The guide is finally complete and on Adam’s main page! Hope it helps everyone!

Comment by Noni Hernandez — April 28, 2009 @ 6:28 am 

Can you provide the url to adam&#039;s main page, please.</description>
		<content:encoded><![CDATA[<p>You posted<br />
The guide is finally complete and on Adam’s main page! Hope it helps everyone!</p>
<p>Comment by Noni Hernandez — April 28, 2009 @ 6:28 am </p>
<p>Can you provide the url to adam&#8217;s main page, please.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SecurityPresentations</title>
		<link>http://www.sharepointsecurity.com/sharepoint/sharepoint-security/sharepoint-and-smartcards-cac-cards/comment-page-1/#comment-24568</link>
		<dc:creator>SecurityPresentations</dc:creator>
		<pubDate>Thu, 18 Jun 2009 01:15:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.sharepointsecurity.com/blog/sharepoint/sharepoint-2007-security/sharepoint-and-smartcards-cac-cards/#comment-24568</guid>
		<description>I know the original thread is a bit dated. but DoD has for the most part standardized on ISA for CAC, originally specifically for OWA and now for SharePoint/MOSS. The is even a DISA STIG (Security Technical Implementation Guides) for this. See here: http://iase.disa.mil/stigs/draft-stigs/draft_isa_server_2006_addendumv1r0.doc  and here http://iase.disa.mil/stigs/draft-stigs/draft_isa_server_2006_addendumv1r0.doc. Curretnly Microsoft&#039;s Intelligent Application Gateway (IAG) and it&#039;s future version Unified Application Gateway (UAG) are being looked at to address this as wel as other remote access needs. Again a no code solution.  DoD custer have access to the Setup/build docs from DISA.

There are several more recent papers on the topic of KCD see here: 

Kerberos Constrained Delegation in ISA Server 2006  
http://technet.microsoft.com/en-us/library/bb794858.aspx

The CAC for OWA setup/Build documention was developed and written by the authors of this article--- (the same approach has been leverage for use with SharePoint / MOSS and more)

Log onto Outlook Web Access with Smart Cards
http://technet.microsoft.com/en-us/magazine/2007.07.smartcards.aspx

Configuring Kerberos constrained delegation with IAG SP2 
http://technet.microsoft.com/en-us/library/dd278107.aspx

Configure Kerberos authentication (Office SharePoint Server)
http://technet.microsoft.com/en-us/library/cc263449.aspx

A user cannot access a Web site that is published in ISA Server 2006 by using Kerberos constrained delegation if the user is not in the same domain as the ISA Server computer
http://support.microsoft.com/kb/942637/en-us

KCD with Cross-Forest Accounts
http://technet.microsoft.com/en-us/library/cc752953.aspx

Same kind of idea but for Performance Point in this case.
Video demo: Configuring Kerberos delegation for Monitoring Server
http://technet.microsoft.com/en-us/library/dd630733.aspx

How to Configure Certificate Based Authentication for OWA - Part I
http://msexchangeteam.com/archive/2008/10/07/449942.aspx</description>
		<content:encoded><![CDATA[<p>I know the original thread is a bit dated. but DoD has for the most part standardized on ISA for CAC, originally specifically for OWA and now for SharePoint/MOSS. The is even a DISA STIG (Security Technical Implementation Guides) for this. See here: <a href="http://iase.disa.mil/stigs/draft-stigs/draft_isa_server_2006_addendumv1r0.doc" rel="nofollow">http://iase.disa.mil/stigs/draft-stigs/draft_isa_server_2006_addendumv1r0.doc</a>  and here <a href="http://iase.disa.mil/stigs/draft-stigs/draft_isa_server_2006_addendumv1r0.doc" rel="nofollow">http://iase.disa.mil/stigs/draft-stigs/draft_isa_server_2006_addendumv1r0.doc</a>. Curretnly Microsoft&#8217;s Intelligent Application Gateway (IAG) and it&#8217;s future version Unified Application Gateway (UAG) are being looked at to address this as wel as other remote access needs. Again a no code solution.  DoD custer have access to the Setup/build docs from DISA.</p>
<p>There are several more recent papers on the topic of KCD see here: </p>
<p>Kerberos Constrained Delegation in ISA Server 2006<br />
<a href="http://technet.microsoft.com/en-us/library/bb794858.aspx" rel="nofollow">http://technet.microsoft.com/en-us/library/bb794858.aspx</a></p>
<p>The CAC for OWA setup/Build documention was developed and written by the authors of this article&#8212; (the same approach has been leverage for use with SharePoint / MOSS and more)</p>
<p>Log onto Outlook Web Access with Smart Cards<br />
<a href="http://technet.microsoft.com/en-us/magazine/2007.07.smartcards.aspx" rel="nofollow">http://technet.microsoft.com/en-us/magazine/2007.07.smartcards.aspx</a></p>
<p>Configuring Kerberos constrained delegation with IAG SP2<br />
<a href="http://technet.microsoft.com/en-us/library/dd278107.aspx" rel="nofollow">http://technet.microsoft.com/en-us/library/dd278107.aspx</a></p>
<p>Configure Kerberos authentication (Office SharePoint Server)<br />
<a href="http://technet.microsoft.com/en-us/library/cc263449.aspx" rel="nofollow">http://technet.microsoft.com/en-us/library/cc263449.aspx</a></p>
<p>A user cannot access a Web site that is published in ISA Server 2006 by using Kerberos constrained delegation if the user is not in the same domain as the ISA Server computer<br />
<a href="http://support.microsoft.com/kb/942637/en-us" rel="nofollow">http://support.microsoft.com/kb/942637/en-us</a></p>
<p>KCD with Cross-Forest Accounts<br />
<a href="http://technet.microsoft.com/en-us/library/cc752953.aspx" rel="nofollow">http://technet.microsoft.com/en-us/library/cc752953.aspx</a></p>
<p>Same kind of idea but for Performance Point in this case.<br />
Video demo: Configuring Kerberos delegation for Monitoring Server<br />
<a href="http://technet.microsoft.com/en-us/library/dd630733.aspx" rel="nofollow">http://technet.microsoft.com/en-us/library/dd630733.aspx</a></p>
<p>How to Configure Certificate Based Authentication for OWA &#8211; Part I<br />
<a href="http://msexchangeteam.com/archive/2008/10/07/449942.aspx" rel="nofollow">http://msexchangeteam.com/archive/2008/10/07/449942.aspx</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Thomas</title>
		<link>http://www.sharepointsecurity.com/sharepoint/sharepoint-security/sharepoint-and-smartcards-cac-cards/comment-page-1/#comment-23844</link>
		<dc:creator>Chris Thomas</dc:creator>
		<pubDate>Mon, 18 May 2009 13:56:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.sharepointsecurity.com/blog/sharepoint/sharepoint-2007-security/sharepoint-and-smartcards-cac-cards/#comment-23844</guid>
		<description>Has anyone attempted this with an External Certificate Authority for non-DoD users?  We are in the process of looking into this and wanted to get some level of the difficulty we are going to have to deal with.

Chris</description>
		<content:encoded><![CDATA[<p>Has anyone attempted this with an External Certificate Authority for non-DoD users?  We are in the process of looking into this and wanted to get some level of the difficulty we are going to have to deal with.</p>
<p>Chris</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dvar</title>
		<link>http://www.sharepointsecurity.com/sharepoint/sharepoint-security/sharepoint-and-smartcards-cac-cards/comment-page-1/#comment-23638</link>
		<dc:creator>Dvar</dc:creator>
		<pubDate>Mon, 11 May 2009 17:10:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.sharepointsecurity.com/blog/sharepoint/sharepoint-2007-security/sharepoint-and-smartcards-cac-cards/#comment-23638</guid>
		<description>I need to implement smart card authentication to AD users and password auth for external users on the same web app... Can anyone give me a piece of advise how to do that? :)
I know how to do that with different web apps, but not with one :(</description>
		<content:encoded><![CDATA[<p>I need to implement smart card authentication to AD users and password auth for external users on the same web app&#8230; Can anyone give me a piece of advise how to do that? <img src='http://www.sharepointsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
I know how to do that with different web apps, but not with one <img src='http://www.sharepointsecurity.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J. Hughes</title>
		<link>http://www.sharepointsecurity.com/sharepoint/sharepoint-security/sharepoint-and-smartcards-cac-cards/comment-page-1/#comment-23637</link>
		<dc:creator>J. Hughes</dc:creator>
		<pubDate>Mon, 11 May 2009 16:29:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.sharepointsecurity.com/blog/sharepoint/sharepoint-2007-security/sharepoint-and-smartcards-cac-cards/#comment-23637</guid>
		<description>I have been using CAC Cards by simply geting the User Name from parsing the server variable CERT_SUBJECT and then comparing that name to names in my web application&#039;s database. So far, it works). I haven&#039;t had two users with the same name. But when the certificate gets chaged or misnamed, CERT_SUBJECT comes up blank.</description>
		<content:encoded><![CDATA[<p>I have been using CAC Cards by simply geting the User Name from parsing the server variable CERT_SUBJECT and then comparing that name to names in my web application&#8217;s database. So far, it works). I haven&#8217;t had two users with the same name. But when the certificate gets chaged or misnamed, CERT_SUBJECT comes up blank.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremy Weiss</title>
		<link>http://www.sharepointsecurity.com/sharepoint/sharepoint-security/sharepoint-and-smartcards-cac-cards/comment-page-1/#comment-23555</link>
		<dc:creator>Jeremy Weiss</dc:creator>
		<pubDate>Thu, 07 May 2009 20:14:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.sharepointsecurity.com/blog/sharepoint/sharepoint-2007-security/sharepoint-and-smartcards-cac-cards/#comment-23555</guid>
		<description>Noni,

I saw the article you wrote titled CAC Enabled Anonymous Sharepoint Sites, however is that the follow-up to this article, as it didn&#039;t mention the HTTP Module at all.  If not can you point me to the article.</description>
		<content:encoded><![CDATA[<p>Noni,</p>
<p>I saw the article you wrote titled CAC Enabled Anonymous Sharepoint Sites, however is that the follow-up to this article, as it didn&#8217;t mention the HTTP Module at all.  If not can you point me to the article.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
