Account expires and Client Certificate Mapping
i testing user account has account expired date in past. when attempt authenticate using rsa access manager, see mevent messages stating account expired , windows token not created.
however, when use client certificates , named mappings in ad, user authenticated , let web site.
is there missing regarding account expires , why user still allowed in using certificates?
thanks
mark
one-to-one mapping type of ad mapping each user has it's own altsecurityidentity.
in case simple capture reveal dc returning iis. mentioned above can try disabling account , see if fails , alternatively can switch test san upn mapping.
here can see chart of different methods:
http://blogs.msdn.com/b/spatdsg/archive/2010/06/18/howto-map-a-user-to-a-certificate-via-all-the-methods-available-in-the-altsecurityidentities-attribute.aspx
Windows Server > Directory Services
Comments
Post a Comment