<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>HSPD-12 Logical Access Authentication and 2008 Active Directory Domains on Download Center</title><link>http://blogs.technet.com/b/pki/archive/2012/03/14/hspd-12-logical-access-authentication-and-2008-active-directory-domains-on-download-center.aspx</link><description>A follow-up document to the original HSPD-12 Logical Access Authentication and Active DIrectory Domains document has just been posted to the download center. The follow-up document demonstrates the increased flexibility of FIPS 201 PIV-II compliant smart</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: HSPD-12 Logical Access Authentication and 2008 Active Directory Domains on Download Center</title><link>http://blogs.technet.com/b/pki/archive/2012/03/14/hspd-12-logical-access-authentication-and-2008-active-directory-domains-on-download-center.aspx#3510019</link><pubDate>Fri, 20 Jul 2012 19:19:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3510019</guid><dc:creator>pfox</dc:creator><description>&lt;p&gt;The NIST PIV Test Cards used in this whitepaper are now available. More information can be found at &lt;a rel="nofollow" target="_new" href="http://csrc.nist.gov/groups/SNS/piv/testcards.html"&gt;csrc.nist.gov/.../testcards.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Paul&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3510019" width="1" height="1"&gt;</description></item><item><title>re: HSPD-12 Logical Access Authentication and 2008 Active Directory Domains on Download Center</title><link>http://blogs.technet.com/b/pki/archive/2012/03/14/hspd-12-logical-access-authentication-and-2008-active-directory-domains-on-download-center.aspx#3493848</link><pubDate>Mon, 23 Apr 2012 15:34:32 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3493848</guid><dc:creator>pfox</dc:creator><description>&lt;p&gt;Script Kitty&lt;/p&gt;
&lt;p&gt;Thank you for your feedback and question. When NIST releases the PIV Test Cards to the public they will publish documentation explaining how the cards are configured. This white paper was developed with the draft release of that document. NIST Test PIV Cards 3 &amp;amp; 7 implement the Discovery Object which says the Global PIN is primary. The smart card minidriver was developed to the 800-73-2 specifications and the Discovery Object was/is an optional feature that was not implemented. Therefore to unlock the PIV Card Applications the PIV Card Application PIN is used. The following is from the draft NIST PIV Test Cards documentation. &lt;/p&gt;
&lt;p&gt;Card	 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; PIV Card Application PIN	Global PIN&lt;/p&gt;
&lt;p&gt;Test Card &amp;nbsp;3	90909090	 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;111111&lt;/p&gt;
&lt;p&gt;Test Card 7 	90909090	 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;111111&lt;/p&gt;
&lt;p&gt;For cards 3 &amp;amp; 7 the Global PIN is the primary based upon the Discovery Object. More information about the Discovery Object can be found in section 3.2.6 of NIST SP800-73-3 (&lt;a rel="nofollow" target="_new" href="http://csrc.nist.gov/publications/nistpubs/800-73-3/sp800-73-3_PART1_piv-card-applic-namespace-date-model-rep.pdf"&gt;csrc.nist.gov/.../sp800-73-3_PART1_piv-card-applic-namespace-date-model-rep.pdf&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;I have revised the white paper. Thank you for bringing this to my attention.&lt;/p&gt;
&lt;p&gt;Paul&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3493848" width="1" height="1"&gt;</description></item><item><title>re: HSPD-12 Logical Access Authentication and 2008 Active Directory Domains on Download Center</title><link>http://blogs.technet.com/b/pki/archive/2012/03/14/hspd-12-logical-access-authentication-and-2008-active-directory-domains-on-download-center.aspx#3488141</link><pubDate>Thu, 22 Mar 2012 16:57:31 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3488141</guid><dc:creator>Script Kitty</dc:creator><description>&lt;p&gt;Very nice article.&lt;/p&gt;
&lt;p&gt;One thing that confuse me (ok there is more than one), but the one that really stands out is the GLOBAL PIN.&lt;/p&gt;
&lt;p&gt;From the little info I can find and make sense of, &amp;nbsp;it looks like this is a second &amp;quot;user&amp;quot; PIN. &amp;nbsp;And it seems to be a recent addition to the cards.&lt;/p&gt;
&lt;p&gt;Here, in our secret underground lair (Moms Basement), &amp;nbsp;we have begun to notice “issues” where the users are changing their PINS with Windows Mini-Driver, and then have trouble when the “badge office” has to do card work. &amp;nbsp;It looks like Windows is only seeing / changing the User PIN, and leaving the Global PIN alone. &amp;nbsp;Which later makes it confusing when you go to the “badge office” and they use both PINS.&lt;/p&gt;
&lt;p&gt;Question: &lt;/p&gt;
&lt;p&gt; &amp;nbsp; Has anyone else started to see this?&lt;/p&gt;
&lt;p&gt; &amp;nbsp; Is there plans to evolve the HSPD-12 Mini-driver to see the Global PIN?&lt;/p&gt;
&lt;p&gt; &amp;nbsp; Does anyone know of a Mini-driver that does see the Global PIN?&lt;/p&gt;
&lt;p&gt; &amp;nbsp; And does anyone plan on using it?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3488141" width="1" height="1"&gt;</description></item></channel></rss>