1.9. Required steps for smart card authentication with certificates issued by Active Directory
You must ensure the following steps have been followed before you can authenticate with a smart card with certificates issued by Active Directory (AD):
- Copy the CA and user certificates from Active Directory to the IdM server and client.
- Configure the IdM server and clients for smart card authentication using ADCS certificates.
- Convert the PFX (PKCS#12) file to be able to store the certificate and private key on the smart card.
- Configure timeouts in the sssd.conf file.
- Create certificate mapping rules for smart card authentication.