<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Smartcard FDE pre-boot authentication in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/9019#M201</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have experience with using a smartcard to unlock the pre-boot of Sandblast FDE?&lt;/P&gt;&lt;P&gt;I've enabled the feature in the end-point console, when entering my smartcard it switches the login screen to enter my PIN. However when I enter the PIN it does not unlock.&lt;/P&gt;&lt;P&gt;The smartcard has a user certificate on it to authenticate on Windows, which is working fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have that much experience with smartcards and CheckPoint so I was wondering if I need a specific certificate (like EFS) or that any of you have any experience using this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also think that the driver is correct because it switches to the PIN and when I use another type of smartcard it does not switch, so cannot read the smartcard.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Jul 2018 08:31:05 GMT</pubDate>
    <dc:creator>Tom_Heesmans</dc:creator>
    <dc:date>2018-07-16T08:31:05Z</dc:date>
    <item>
      <title>Smartcard FDE pre-boot authentication</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/9019#M201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have experience with using a smartcard to unlock the pre-boot of Sandblast FDE?&lt;/P&gt;&lt;P&gt;I've enabled the feature in the end-point console, when entering my smartcard it switches the login screen to enter my PIN. However when I enter the PIN it does not unlock.&lt;/P&gt;&lt;P&gt;The smartcard has a user certificate on it to authenticate on Windows, which is working fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have that much experience with smartcards and CheckPoint so I was wondering if I need a specific certificate (like EFS) or that any of you have any experience using this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also think that the driver is correct because it switches to the PIN and when I use another type of smartcard it does not switch, so cannot read the smartcard.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2018 08:31:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/9019#M201</guid>
      <dc:creator>Tom_Heesmans</dc:creator>
      <dc:date>2018-07-16T08:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Smartcard FDE pre-boot authentication</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/9020#M202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In older versions (ones no longer supported), there was a bug with PINs of a certain length.&lt;/P&gt;&lt;P&gt;Not sure that's still relevant.&lt;/P&gt;&lt;P&gt;It's probably a good idea to involve the TAC in this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2018 14:14:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/9020#M202</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-16T14:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Smartcard FDE pre-boot authentication</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/9021#M203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the response, this however is not an older version and the pin is only 4 digits in lenght for testing.&lt;/P&gt;&lt;P&gt;We'll probably need TAC but I have some great experiences with this community and was hoping for the small simple remark that will point is in the right direction. My guess is that this is something simple that we are overlooking.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2018 14:18:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/9021#M203</guid>
      <dc:creator>Tom_Heesmans</dc:creator>
      <dc:date>2018-07-16T14:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: Smartcard FDE pre-boot authentication</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/9022#M204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'll see if I can get an expert in this area to comment &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2018 15:32:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/9022#M204</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-16T15:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: Smartcard FDE pre-boot authentication</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/101694#M2746</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/19475"&gt;@Tom_Heesmans&lt;/a&gt;, I just found your post and I'm wondering how you resolved the issue described.&lt;/P&gt;
&lt;P&gt;After switching from password to smartcard authentication in the FDE preboot today, I get an "Invalid Logon" message in the client, and a "No Smartcard users configured" in the logs on the management. I did some testing and my scenario matches your description.&lt;/P&gt;
&lt;P&gt;I know it has been a while, but I'll appreciate it if you can share anything you remember. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2020 03:46:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/101694#M2746</guid>
      <dc:creator>KatiaCruz</dc:creator>
      <dc:date>2020-11-11T03:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: Smartcard FDE pre-boot authentication</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/101715#M2747</link>
      <description>&lt;P&gt;For us this eventually came down to an incompatible driver for the smartcard reader. It should have been compatible according to the documentation but after examination from dev-ops this was not the case. Our smartcard readers where from Thales (formaly Gemalto) and CheckPoint collaborated with them to integrate the correct driver. Everything is working as expected now.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2020 08:03:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/101715#M2747</guid>
      <dc:creator>Tom_Heesmans</dc:creator>
      <dc:date>2020-11-11T08:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Smartcard FDE pre-boot authentication</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/101812#M2750</link>
      <description>&lt;P&gt;Good to know, &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/19475"&gt;@Tom_Heesmans&lt;/a&gt;.&amp;nbsp;I will double-check if the smartcard reader driver is the right one in my case. We ended up using a generic one from the list provided during configuration.&lt;/P&gt;
&lt;P&gt;Thanks for your response!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2020 17:22:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Smartcard-FDE-pre-boot-authentication/m-p/101812#M2750</guid>
      <dc:creator>KatiaCruz</dc:creator>
      <dc:date>2020-11-11T17:22:07Z</dc:date>
    </item>
  </channel>
</rss>

