a smart card that was designed to be used with the Red Hat Enterprise Linux Certificate System
server product, it displays a user interface instructing the user how to enroll that smart card.
• Unifies Kerberos and NSS so that users who log in to the operating system using a smart card also
obtain a Kerberos credential (which allows them to log in to file servers, etc.)
43.3.2. Getting Started with your new Smart Card
Before you can use your smart card to log in to your system and take advantage of the increased
security options this technology provides, you need to perform some basic installation and
configuration steps. These are described below.
Note
This section provides a high-level view of getting started with your smart card. More
detailed information is available in the Red Hat Certificate System Enterprise Security
Client Guide.
1.
Log in with your Kerberos name and password
2.
Make sure you have the nss-tools package loaded.
3.
Download and install your corporate-specific root certificates. Use the following command to
install the root CA certificate:
certutil -A -d /etc/pki/nssdb -n "root ca cert" -t "CT,C,C" -i ./
ca_cert_in_base64_format.crt
4.
Verify that you have the following RPMs installed on your system: esc, pam_pkcs11, coolkey, ifd-
egate, ccid, gdm, authconfig, and authconfig-gtk.
5.
Enable Smart Card Login Support
a.
On the Gnome Title Bar, select System->Administration->Authentication.
b.
Type your machine's root password if necessary.
In the Authentication Configuration dialog, click the Authentication tab.
c.
Select the Enable Smart Card Support check box.
d.
Click the Configure Smart Card... button to display the Smartcard Settings dialog, and
e.
specify the required settings:
• Require smart card for login — Clear this check box. After you have successfully logged
in with the smart card you can select this option to prevent users from logging in without a
smart card.
• Card Removal Action — This controls what happens when you remove the smart card
after you have logged in. The available options are:
• Lock — Removing the smart card locks the X screen.
Getting Started with your new Smart Card
637
Need help?
Do you have a question about the ENTERPRISE LINUX 5 - DEPLOYMENT and is the answer not in the manual?
Questions and answers