To test that a card has been initialized with an appropriate user
# vastool smartcard test user Testing user email@example.com Testing certificate validity ... ok Testing if PIN is required ... ok Enter PIN for firstname.lastname@example.org: xxxxxxxx Performing login to card ... ok Generating signature ... ok Verifying signature ... ok
This tests whether a valid user is on the card, and whether you are able to log into the card and use its cryptographic functions. If your card requires a PIN, enter the password at the prompt.
The vastool smartcard test card function generates output similar to the following:
CKM_RSA_X_509 CKM_MD2_RSA_PKCS CKM_MD5_RSA_PKCS CKM_SHA1_RSA_PKCS CKM_DES_KEY_GEN CKM_DES_ECB CKM_DES_CBC CKM_DES_CBC_PAD CKM_DES2_KEY_GEN CKM_DES3_KEY_GEN CKM_DES3_ECB CKM_DES3_CBC CKM_DES3_CBC_PAD CKM_MD2 CKM_MD5 CKM_SHA_1 Checking that CKM_RSA_PKCS mechanism is supported ... ok Checking info for CKM_RSA_PKCS mechanism ... ok Checking CKM_RSA_PKCS mechanism supports signing ... ok Checking CKM_RSA_PKCS mechanism supports decryption ... ok Testing that card contains a user ... ok
Note: This command requires that you are joined to a domain.
To test whether it is possible to log in using the inserted card
# vastool smartcard test login Testing user email@example.com Testing certificate validity ... ok Testing if PIN is required ... ok Enter PIN for firstname.lastname@example.org: Performing login to card ... ok Creating ID for client with UPN 'email@example.com' ... ok Establish initial credentials using PKCS#11 ... ok
This command uses the inserted card to perform a log in to Active Directory. It displays a warning if the user is not Unix enabled, and displays an error if the log in fails. This command is useful when troubleshooting Authentication Services for Smart Cards log in problems.
To help you troubleshoot your Authentication Services for Smart Cards installation, One Identity recommends the following resolutions to some of the common problems you might encounter.
Authentication Services for Smart Cards provides a number of tools and options to diagnose problems.