Symantec Privileged Access Management

 View Only

Tech Tip - How to configure PAM for Smart Card authentication 

Apr 06, 2017 06:28 PM

The purpose of this document is to demonstrate how to configure CA PAM to use smart cards(PKI).  In short, you have install the root and intermediate certificates into PAM, which are required by the certificate on your smart card.  You will also have to install in PAM any CRLs that are required by the certificates.  On the Config à Security page, you will have to enable PKI and make the PKI button visible.  Your users can then attempt to login using the PKI button.  There first attempt will fail, as each such CAC user must be approved by a PAM Admin.  Once that is done your users will be able to login with PKI.  That’s the short story.  Details may be found in the attached document.

Statistics
0 Favorited
15 Views
1 Files
0 Shares
8 Downloads
Attachment(s)
docx file
SmartCardConfiguration.docx   13 KB   1 version
Uploaded - May 29, 2019

Tags and Keywords

Comments

Nov 30, 2017 10:28 PM

Awesome, article Ed. Worked like a charm.

 

One additional question though, how can I make it work using LDAP authentication, what I mean is that instead of uploading a root cert and CRLs I want PAM to send the certificate to LDAP to authenticate (which has both root cert and CRL). Is there a way we can do it in PAM.

Apr 07, 2017 05:08 AM

Thanks . I tried and it works us explained in the doc.

The only thing I wasn't able to config was the automatic CRL download. It says

"Can't update CRL configuration: There is invalid CRL file"

 

Thanks once again for this tech tip

Related Entries and Links

No Related Resource entered.