Issue and Manage Windows Logon Certificates
Lawrence E. Hughes · Apress eBooks · 2022
The last type of digital certificate we will be creating with AD Certificate Services is again similar to a TLS Client certificate, except that it is used for cryptographic (“smart card”) logon with Windows. These are usually distributed in credit card-like PKI smart cards, hence the Windows computer needs some kind of smart card reader. This is a major improvement in security in an organization using Microsoft networks (over password based authentication). The Windows logon certificate is not used as a second factor, but replaces the password with cryptographic authentication. Some organizations use the same smartcard as a picture ID for each user, and they can even be used to unlock doors if desired. This is an application where Active Directory Certificate Services really shines, due to its tight integration with the organization’s Active Directory. These certificates can be created centrally by a security admin, or be requested by the end-users if they have the ability to load them into a smart card.