Setting Up Workstation Passwordless Logon Settings on Hideez Identity Cloud
Once you have created the appropriate template in the certification authority, you need to get the following settings:
Cryptographic Service Provider Name
Certificate Config
Certificate Template ID
1. The first parameter (Cryptographic Service Provider Name) must be set to:
Microsoft Base Smart Card Crypto Provider
2. The second parameter (Certificate Config) is the name of the domain controller and the name of the certification authority:
The following command will help define these names. Run it from the command line:
certutil -config - -ping
Then you should get such a window:

Separated "CA" and "Computer" by an "\" in the settings on the Hideez Server.
3. To define the third parameter (Certificate Template ID), go to the domain controller, and do the following:
Open MMC and add the Certificate Templates snap-in (File > Add/Remove Snap-ins > Certificate Templates)
Right-click the created certificate template
Open Properties
Open Extensions tab
Select “Certificate Template Information”
The ID will be visible in the description below after "Object identifier":

The data collected above should be entered into your tenant by the administrator of the Hideez Cloud Server. This should be done via the "Active Directory" section under "Integrations" in the left panel. The provided information will be sent by the Hideez Cloud Server to the registered Hideez Desktop to access the Active Directory Domain Controller, enabling the retrieval and storage of data required for passwordless authentication.
Last updated