{"id":40254,"date":"2023-11-10T10:16:28","date_gmt":"2023-11-10T04:46:28","guid":{"rendered":"http:\/\/ismiletechnologies.com\/?p=40254"},"modified":"2023-11-14T01:23:42","modified_gmt":"2023-11-13T19:53:42","slug":"enabling-piv-card-for-federal-agencies","status":"publish","type":"post","link":"https:\/\/ismiletechnologies.com\/en_us\/azure\/enabling-piv-card-for-federal-agencies\/","title":{"rendered":"Enabling PIV Card for Federal Agencies"},"content":{"rendered":"<p>These guides help configure Windows domains for PIV smart card logon, particularly for U.S. federal civilian agencies. They address common questions and specific configurations.<\/p>\n<p>Before delving into these network guides and lessons learned, please ensure the following:<\/p>\n<p>Users possess both PIV credentials and PIV card readers.<\/p>\n<p>You are utilizing Microsoft Active Directory for Windows network management.<\/p>\n<p>Your Domain Controllers are Microsoft 2012 or a more recent version.<\/p>\n<p>User workstations are integrated into your network and run either Windows 8 or Windows 10.<\/p>\n<p>Your workstations, servers, network domain controllers, and applications must constantly verify the validity of PIV certificates and all intermediate certificate authority (CA) certificates. Additionally, during the certificate chain path building process, intermediate CA certificates may be fetched and downloaded.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"\" src=\"https:\/\/www.idmanagement.gov\/assets\/piv\/elements.png\" alt=\"Personal Identity Verification Card 101\" width=\"899\" height=\"892\" \/><\/p>\n<p><strong>Domain controller certificate:<\/strong><\/p>\n<p>For network authentication using smart cards and PIV credentials, it&#8217;s essential for all domain controllers to possess authentication certificates. U.S. federal civilian agencies maintain a range of information security policies, which determine whether domain controller certificates should be sourced from the agency&#8217;s local enterprise certification authority (CA) or from a CA under the Federal Public Key Infrastructure (FPKI) certification. It is crucial to adhere to the specific information security policy of your agency.<\/p>\n<p><strong>Local Certification Authority:<\/strong><\/p>\n<p>Local Certification authority is need in order to issue a local certificate. This certificate will be installed on domain controller and user endpoints. The server hosting the Certification Authority (CA) needs to be integrated into the domain. It is important to ensure that the CA is not located on servers designated as domain controllers. Additionally, one must hold the role of Enterprise Administrator within the domain to execute these operations.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Enabling Enterprise Trust of the Common Policy Certificate:<\/strong><\/p>\n<p>To establish organizational trust for the FCPCA Root Certificate, the process involves these actions:<\/p>\n<p>Acquiring and authenticating the FCPCAG2 Certificate<\/p>\n<p>Distribute the certificate across operating systems<\/p>\n<p>To obtain the FCPCAG2 root certificate, Access and download the certificate from the specified URL: <a class=\"fui-Link ___10kug0w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1hu3pq6 f11qmguv f19f4twv f1tyq0we f1g0x7ka fhxju0i f1qch9an f1cnd47f fqv5qza f1vmzxwi f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn\" title=\"http:\/\/repo.fpki.gov\/fcpca\/fcpcag2.crt.\" href=\"http:\/\/repo.fpki.gov\/fcpca\/fcpcag2.crt.\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"Link http:\/\/repo.fpki.gov\/fcpca\/fcpcag2.crt.\">http:\/\/repo.fpki.gov\/fcpca\/fcpcag2.crt.<\/a><\/p>\n<p>Once the certificate is obtained, you can use windows group policy to distribute the certificate to endpoints.<\/p>\n<p><strong>Authentication Assurance:<\/strong><\/p>\n<p>To effectively manage access within your network when Single Sign-on is active, it&#8217;s crucial to identify the authentication method utilized by the user:<\/p>\n<p>Username and password combination<\/p>\n<p>PIV (Personal Identity Verification) credential<\/p>\n<p>Understanding which authentication method was employed is essential for applying detailed access control policies and determining whether to permit or restrict user access to applications and network-shared resources. Windows Active Directory&#8217;s Authentication Mechanism Assurance (AMA) feature facilitates this by allowing the addition of a group membership identifier to the user&#8217;s Kerberos token based on the authentication method used.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>These guides help configure Windows domains for PIV smart card logon, particularly for U.S. federal civilian agencies. They address common questions and specific configurations. Before delving into these network guides and lessons learned, please ensure the following: Users possess both PIV credentials and PIV card readers. You are utilizing Microsoft Active Directory for Windows network [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":40256,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[245],"tags":[],"class_list":["post-40254","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azure"],"_links":{"self":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts\/40254","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/comments?post=40254"}],"version-history":[{"count":1,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts\/40254\/revisions"}],"predecessor-version":[{"id":40257,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts\/40254\/revisions\/40257"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/media\/40256"}],"wp:attachment":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/media?parent=40254"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/categories?post=40254"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/tags?post=40254"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}