NMAS 1642 error logging in with Universal Smart Card method

(Last modified: 10Jun2005)

This document (10086497) is provided subject to the disclaimer at the end of this document.

fact

Novell Modular Authentication Service version 2.1.1

symptom

NMAS 1642 error logging in with Universal Smart Card method

cause

The Universal Smartcard LCM performs a case sensitive comparison when comparing subject names extracted from the smart card and the allowable subject names read from eDirectory.  If the casing doesn't match, then the authentication fails.  The default syntax for the allowable subject name is cn=user.ou=organizationunit.o=organization.  The compare process changes the cn to CN, and therefore the allowable subject name stored in NDS doesn't match the case sensitive comparison done with the allowable subject name registered to the card.

fix

Resolved in the NMAS 2.3 and later. 

Workaround:
Use a different attribute value for the "Allowable Subject Name" rather than the Fully Qualified Distinguished Name.  Another good alternative would be email address.  If you change this, you will have to re-export the user certificate.

document

Document Title: NMAS 1642 error logging in with Universal Smart Card method
Document ID: 10086497
Solution ID: NOVL92082
Creation Date: 27Aug2003
Modified Date: 10Jun2005
Novell Product Class:Security Components

disclaimer

The Origin of this information may be internal or external to Novell. Novell makes all reasonable efforts to verify this information. However, the information provided in this document is for your information only. Novell makes no explicit or implied claims to the validity of this information.
Any trademarks referenced in this document are the property of their respective owners. Consult your product manuals for complete trademark information.