Setting Up Workstation Passwordless Logon Settings on Hideez Identity Cloud

Once you have created the appropriate template in the certification authority, you need to get the following settings:

  1. Cryptographic Service Provider Name

  2. Certificate Config

  3. Certificate Template ID

1. The first parameter (Cryptographic Service Provider Name) must be set to:

Microsoft Base Smart Card Crypto Provider

2. The second parameter (Certificate Config) is the name of the domain controller and the name of the certification authority:

The following command will help define these names. Run it from the command line:

certutil -config - -ping

Then you should get such a window:

Separated "CA" and "Computer" by an "\" in the settings on the Hideez Server.

3. To define the third parameter (Certificate Template ID), go to the domain controller, and do the following:

  • Open MMC and add the Certificate Templates snap-in (File > Add/Remove Snap-ins > Certificate Templates)

  • Right-click the created certificate template

  • Open Properties

  • Open Extensions tab

  • Select “Certificate Template Information

The ID will be visible in the description below after "Object identifier":

  1. The data collected above should be entered into your tenant by the administrator of the Hideez Cloud Server. This should be done via the "Active Directory" section under "Integrations" in the left panel. The provided information will be sent by the Hideez Cloud Server to the registered Hideez Desktop to access the Active Directory Domain Controller, enabling the retrieval and storage of data required for passwordless authentication.

Note: lab.hideez.com is an example of Active Directory domain name

Last updated