Account expires and Client Certificate Mapping


i testing user account has account expired date in past.  when attempt authenticate using rsa access manager, see mevent messages stating account expired , windows token not created.

 

however, when use client certificates , named mappings in ad, user authenticated , let web site.

is there missing regarding account expires , why user still allowed in using certificates?

thanks

mark

one-to-one mapping type of ad mapping each user has it's own altsecurityidentity.

in case simple capture reveal dc returning iis. mentioned above can try disabling account , see if fails , alternatively can switch test san upn mapping.

here can see chart of different methods:

http://blogs.msdn.com/b/spatdsg/archive/2010/06/18/howto-map-a-user-to-a-certificate-via-all-the-methods-available-in-the-altsecurityidentities-attribute.aspx



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Azure MFA with Azure AD and RDS

Failed to setup initiator portal. Error status is given in the dump data.

Failed to delete the test record dcdiag-test-record in zone test.com