Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 11:25 am

All times are UTC + 1 hour




Post new topic Reply to topic  [ 1 post ] 
Author Message
PostPosted: Fri Dec 02, 2016 8:17 pm 
Offline

Joined: Fri Dec 02, 2016 7:54 pm
Posts: 7
We are using YK4's for PIV authentication for our Windows domain. However users are still required to change their domain password every 90 days. When they go to do this Windows allows you to change your smart card PIN. There are a couple of issues with this but the one that concerns me is that Windows allows users to setup a blank PIN. Surprisingly there aren't any Window's GPOs for PIN length and complexity. I was able to find this reg key that disables the ability to change the PIN via Windows which is really helpful in forcing users to use the Yubikey PIV manager. If your running Vista or 7 you must install the Hotfix as well (no reboot required). Windows 10 doesn't require anything but the reg key. Hope this helps someone else!

https://support.microsoft.com/en-us/kb/2808693

Regedit:
-----------
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\SmartCardCredentialProvider]
"AllowSmartCardPinChangeAndUnblock"=dword:00000000

---------


Attachments:
WindowPINChange.jpg
WindowPINChange.jpg [ 38.7 KiB | Viewed 955 times ]
Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 1 post ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group