I manage a government enterprise network with many Mac laptops. We are required to enforce smart card logins only for all users. All of our users are Active Directory with mobile accounts. We have previously accomplished this using Centrify, however tokend is now dead so we are forced to use the Native Smart Card functionality in Catalina. Unfortunately, the built in functionality for this falls short in that there does not seem to be a way to get a Kerberos ticket with a smart card in the same way that Centrify provided with the sctool command. While the system will grant a ticket upon login with the correct SmartcardLogin.plist in place, you can not renew the ticket after expiration. Previously, doing a screen lock and unlocking would renew the ticket. This is not the case with the native smart card support in Catalina. The user would have to log out and back in to get a new Kerberos ticket. It's also a problem for VPN in that they have no ticket to access resources once they are connected. The solution I have for this is to use enforce a Smart Card login via a User Level configuration on JAMF and then allow a password on the AD account whereby they could run a kinit command from the terminal to get a ticket. The problem is that this user-level policy does not seem to work at the actual Mac login screen. I can still login with a password even with this configuration profile set. If I try to unlock a screen with a password after already logging in, it will deny me with a message that the smart card is required. So it appears to work on the lock screen but not the actual login screen. I've verified that the profile is indeed installed for the user with those settings. This configuration profile works via the Computer level, but that is problematic as it sets the smart card enforcement for all accounts, including the local admin account. That is something that we do not want. I'm at a dead end. Any ideas are appreciated.
Question
Smart Card User-Level Configuration for Catalina
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
