[aklug] Re: Common Access Cards - Technical Aspects

From: Christopher Howard <choward@indicium.us>
Date: Mon Jun 28 2010 - 12:11:46 AKDT

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

>
> Aren't these users effectively asking you, "Please create unattended
> login for a system designed to require attended login" ?
>

Well, my boss doesn't mind being at the computer with the CAC card
inserted during the downloads. He just thinks that if there are 30
things that need to be downloaded each week, he shouldn't have to
manually click on every single one himself. If a web browser can
download stuff from a CAC-enabled site, why shouldn't a command-line
tool (being run by a script) be able to do it?

Anyway, that's the rationale handed-down to me, and it makes sense.

My end goal isn't to make local copies of the CAC cards. I'm just trying
to figure what is the easiest way to pull this off. It seems like if the
Safari uses stuff from keychain to access the web site, and keychain
gets what it needs from the CAC card, then I should be able to get the
certificates cURL needs from keychain while the CAC card is inserted.

Hope that helps clarify where I'm coming from.

- --
Christopher Howard
http://indicium.us
http://theologia.indicium.us

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.14 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAkwpAgIACgkQQ5FLNdi0BcW8CgCfW1aUoAIU1cdypa75FVgl0i2z
VCYAniol6PhSWGKbwhlgMOQMAkOX+IkU
=h5Wg
-----END PGP SIGNATURE-----
---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Mon Jun 28 12:11:56 2010

This archive was generated by hypermail 2.1.8 : Mon Jun 28 2010 - 12:11:56 AKDT