Account expires and Client Certificate Mapping


i testing user account has account expired date in past.  when attempt authenticate using rsa access manager, see mevent messages stating account expired , windows token not created.

 

however, when use client certificates , named mappings in ad, user authenticated , let web site.

is there missing regarding account expires , why user still allowed in using certificates?

thanks

mark

one-to-one mapping type of ad mapping each user has it's own altsecurityidentity.

in case simple capture reveal dc returning iis. mentioned above can try disabling account , see if fails , alternatively can switch test san upn mapping.

here can see chart of different methods:

http://blogs.msdn.com/b/spatdsg/archive/2010/06/18/howto-map-a-user-to-a-certificate-via-all-the-methods-available-in-the-altsecurityidentities-attribute.aspx



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS