PDA

View Full Version : Sun Ray, MS Terminal Services and all that good stuff


shadowlion
October 2nd, 2006, 19:29
Darkart Logon Questions and I guess requests for the next version..
Iv been testing Darkart Logon / Manager & formatter for the last week with Sun Rays Ultra Thin Clients & Terminal Services and here is what I have found, Liked, Disliked and have some questions on.

First off, your site lists Schlumberger Payflex smart card series as being compatible. However I have found that Sun Microsystems Smartcards (Schlumberger Playflex with sun painting on the card) PN: 370-4328-01 does NOT work with Darkart at all… The Manager just displays them as being unformatted and the formatter just spits out errors when I try to format one… and these cards are fresh out of the box with no formatting on them that I know of.

Now Sun Ray supports a ton of other Smart Cards so I started using Gemplus Cards and I could get the same Gemplus cards to work with Darkart and Sun Ray with out any problems. The Fun part starts when you try to Log on using the same card from the Sun Ray into a Windows Terminal Services session.

With the Sun Ray Windows Connector I can make the Windows Terminal Server allow Smart Card Authentication as if the reader was in fact connected to that server for each user (PC /SC SRCOM bypass) but Darkart just sees the Card (Gemplus) as being unformatted. Darkart can see the Sun Rays Card Reader, so can MS Windows and using Smart Card ToolSet PRO v3.3 I can read the information on the card. If I try to use the Darkart Formatter I just give errors (Note: I have preformatted these cards with Darket on a workstation and tested them to make sure they worked).

Now I know Sun Ray is not the problem here because Windows will let me Log in with the Smart card via the Sun Ray no problem. Now why would I want to use Darket if I can use Microsoft solution for free? Well because it’s a big pain in the ass. I would have to build a certificate authority on my domain and to do it the “right way” I would have to build another server and buy a Windows Server Copy just for that. That’s what I like about Darkart… I don’t have to build a certificate authority and deal with all the MS bull.

After reading other posts I gather that Darkart does not play nice with MS Terminal Services and I hope that is the only reason that Darkart is not working this solution.

So back to my base questions:

1.) Why is the Schlumberger Playflex Cards not working?
2.) Will the next version of Darkart support MS Terminal Services (on Win2003) or XP / Vista RDP?
3.) Is there anything I can do to make it work with the current Darkart Login Ver?
4.) If there is a Beta that will work can I test it?

I would like to use Darkart over MS Solution for my Sun Ray implementation for this company, so any help you can give would be appreciated.

Gordon N.
Windsor Security Limited.

Alex Railean
October 9th, 2006, 11:38
A beta which supports terminal sessions can be downloaded from this location: http://files.dekart.com/beta/logon-rdp-01.exe

Give it a try and let me know how it went. As for the card not being formatted, please enable the logging mode of the key formatting tool, and send us the logs via email. We'll see what the problem is.

shadowlion
October 11th, 2006, 00:18
Beta test run and testing mythology

Smart Card Readers used:
SCM SCR301 (USB Smartcard Reader)
Sun Ray DTU 0 Built in Smartcard readers
Compaq KUS0133 Smart Card Terminal (O2Micro)

Test Operating Systems:
Windows XP Pro SP2
Windows 2003 Std Server
Solaris 10 6/06 with Sun Ray Server 4 + Windows Connector + PC / SC SRCOM Bypass

SmartCards Used:
GEMPLUS P/N: 10L7341 (IBM Card)

Pre Test Notes:
- Smart Card was formatted with Dekart Formatting Utility and tested with Dekart on stand alone workstations (XP Pro SP2)
- “Do not allow smart card device redirection setting” under policy object in windows was set to “disabled” (for both XP and 03)

Test A.)
- Installed Dekart logon-rdp-01.exe onto XP Pro SP2
- Configured Sun Ray server to redirect test user to RDP on that computer with Smart Card PC /SC SROM Bypass to that RDP session
- Log in from Sun Ray
- Log into Windows from with Password / User
- Open Dekart Login
- Shows card in “Sun Ray DTU 0” as not being formatted
- Derkart format Utility can not format or un-formated Card

Test B.)
- Configured Smart Card directly from workstation (XP pro SP2 with Dekart Login beta) and tested it.
- Attempted Test A.
- Dekart Shows at login that Smart Card is not formatted (“The Key you connected has not been formatted”)

Test C.)
- Built Windows 2003 Server with Active Directory and Terminal Services.
- Installed Dekart Login Beta (on Win03 Server)
- Used XP Pro SP2 Workstation with SCM Reader to remote into Win03 Server
- Login Manually (password / User)
- Open Dekart Login
- Shows card in “SCM” as not being formatted
- Derkart format Utility can not format or un-formated Card

Test D.)
- Configured Smart Card directly from Server (Win 03 Std with Dekart Login beta) and tested it.
- Attempted Test C.
- Dekart Shows at login that Smart Card is not formatted

Test E.)
- Tests C & D with Compaq KUS0133 Smart Card reader over RDP with no luck

Conclusion: Derkart Login Beta does not work with RDP login for Smart Cards at least in my case on Windows XP, 03 with the 3 Smart Card Readers I Used.

Other Notes:
- Smart Smart card and Smart Card readers worked with Dekart when used to Physically login to test workstation
- Dekart Key Manger shows the Smart Cards information as all Zeros or Blank but does see the smart card reader and that a card is inserted when viewed over RDP… It also shows a “?” over the reader when a card is inserted.

Before other readers make judgments, this is Beta Software!

Alex Railean
October 15th, 2006, 22:59
Please create c:\dk_smartkey.log on the computer where Logon is running; this will turn on the logging mode of the component which handles the communication with smart cards, tokens, and other types of keys.

Create the file, restart the PC, then attempt to perform some of the above operations. The log will hopefully tell us what exactly went wrong.

Note: it is a good idea to send the log via email, rather than attach it to this thread (the log may contain details about your environment which you would rather not share with the general public).

shadowlion
January 3rd, 2007, 19:22
Can we get an update on the status of this product…. As we are very interested in its deployment

Thank You