RMills1

updated

7 years ago

R

RMills1

25 Posts

0

3276

March 27th, 2019 11:00

FFE doesn't encrypt for smart card users

Hello,

We are trying to start deploying Dell Encryption Enterprise to our laptops/tablets using Policy based FFE.  It works successfully for our users that log into the laptop with their username and password.  However, users that log into their laptop with a smart card (using standard Windows Smart Card logon, no special GINA) are not registered properly to the Dell Security Server, so the laptop doesn't encrypt.

CMGShield.log has the following:

[03.27.19 13:51:30:998 XmlRpcActivate.: 184 H] Activation - Sending activation request for user@domain.com
[03.27.19 13:51:30:999 XmlRpcActivate.: 521 E] Setting errors to be ignored!!!
[03.27.19 13:51:31:001 XmlRpcActivate.: 521 E] Setting HTTP timeouts based on value 300.
[03.27.19 13:51:31:001 XmlRpcActivate.: 521 E] Setting HTTP Security Protocols (TLS 1.0,1.1,1.2 succeeded
[03.27.19 13:51:31:183 XmlRpcActivate.: 207 E] Activation - Activation request failed [device server fault:0x3ec]: Invalid X509 certificate
[03.27.19 13:51:31:184 Activator.cpp: 848 E] Activation - Unable to activate new user DOMAIN\USER [MS error = 1004]
[03.27.19 13:51:31:184 Activator.cpp: 861 E] Activation - Verify network connectivity to the Dell Security Server at "server.domain.com" and Dell Device Server at "https://server.domain.com:8443/xapi/"

I verified going to the server address works successfully with no certificate errors, so I think it's having an issue with the smart card certificate representing the user.  I've tested this with both a new user (not in the DDS Server), and a user that already exists in DDS, but the result is the same.

Anyone have any ideas?

Thanks,

RMills1