How do you use a SID800 with multiple certificates and Windows credential provider?
2 years ago
Originally Published: 2010-04-06
Article Number
000066505
Applies To
RSA SID800
RSA SecurID SID800 Authenticator (USB token)
Microsoft Windows 7 Professional
Microsoft Windows 2008 Server
Microsoft Windows Credential Provider
Microsoft certificate-based logon
Issue
How do you use a  SID800 with multiple certificates and Windows credential provider?
Only one certificate on the SID800 is being seen at logon screen
SID800 with two valid certificates from a Windows 2003 CA. When authenticating to a system, only the certificate marked as default in the RSA Control Center is displayed. How do you configure the system to display both certificates for the user to choose from?
Resolution

A Microsoft GPO policy to show all certificates at logon needs to be updated.

http://technet.microsoft.com/en-us/library/ff404287(WS.10).aspx?ppud=4

Update these GPO settings:

Force the reading of all certificates from the smart card

Filter duplicate logon certificates


Or by registry:

http://gp.gekki.net/administrative-templates/?/policy/2073/Forcethereadingofallcertificatesfromthesmartcard

You should see two logon tiles, one for each certificate.