A Common Access Card (CAC) is a United States Department of Defense (DoD) smart card used by military personnel and other government and non-government personnel who require highly secure access over the Internet. A CAC uses PKI authentication and encryption.
LDAP authentication with a Common Access Card (CAC) requires a two-factor authentication using both the
CAC and a Client Certificate Check. (This assumes the root certificate has already been downloaded).
The Client Certificate Check was developed for use with a CAC; however, it is useful in any scenario that
requires a client certificate on an HTTPS/SSL connection. CAC support is available for client certification only on
HTTPS connections.
This article describes how to setup two factor CAC authentication with Client Certificate Check.
RESOLUTION FOR SONICOS 7.X
This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.
To configure CAC with Client Certificate Check :
Navigate to DEVICE | Settings > Administration > Management.
Click on Certificate Selection drop down, and select a local certificate generated by the CA.-authentication-with-Client-Certificate-Check.-kA1VN0000000G000AE-0EMVN00000Enlnj.png)
-authentication-with-Client-Certificate-Check.-kA1VN0000000G000AE-0EMVN00000Enlnz.png)
-authentication-with-Client-Certificate-Check.-kA1VN0000000G000AE-0EMVN00000Enlo0.png)
-authentication-with-Client-Certificate-Check.-kA1VN0000000G000AE-0EMVN00000Enlo1.png)
-authentication-with-Client-Certificate-Check.-kA1VN0000000G000AE-0EMVN00000Enlnq.png)
NOTE: Sonicwall Administrator groups should be added to the LDAP server as they are seen in the SonicWALL local groups tab (Audit Administrators,Cryptographic Administrators, SonicWALL-authentication-with-Client-Certificate-Check.-kA1VN0000000G000AE-0EMVN00000Enlny.png)
NOTE: Using a CAC requires an external card reader that is connected through a USB port.RESOLUTION FOR SONICOS 6.5
This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
To configure CAC with Client Certificate Check :
-authentication-with-Client-Certificate-Check.-kA1VN0000000G000AE-0EMVN00000Enlnn.png)
-authentication-with-Client-Certificate-Check.-kA1VN0000000G000AE-0EMVN00000Enlnp.png)
-authentication-with-Client-Certificate-Check.-kA1VN0000000G000AE-0EMVN00000Enlnm.png)
-authentication-with-Client-Certificate-Check.-kA1VN0000000G000AE-0EMVN00000Enlnk.png)
-authentication-with-Client-Certificate-Check.-kA1VN0000000G000AE-0EMVN00000Enlnh.png)
NOTE: Sonicwall Administrator groups should be added to the LDAP server as they are seen in the SonicWALL local groups tab (Audit Administrators,Cryptographic Administrators, SonicWALL-authentication-with-Client-Certificate-Check.-kA1VN0000000G000AE-0EMVN00000Enlnl.png)
NOTE: Using a CAC requires an external card reader that is connected through a USB port.HOW TO TEST :
TIP: CACs might not work with browsers other than Microsoft Internet Explorer.