[Thinlinc-technical] server side smartcard support + Igel?

Pierre Ossman ossman at cendio.se
Tue May 21 12:28:48 CEST 2019


On 16/05/2019 10:59, Per Andersson wrote:
> 
> My question is whether smart card support on the server side is needed
> or if all the magic happens on the client side? If possible I would like
> to turn off the esc daemon and gsd-smartcard but I have not been able to
> find any information in any documentation if that is possible with our
> set-up, and I can't experiment in the production environment. As I
> understand it, by removing the support all together the necessary
> modules in PAM also are removed, but would it be possible to keep the
> support for smart cards and just turn the daemons off on the server, or
> is the thinlinc server software and/or the server authentication system
> relying on them even though the actual handling of the smart cards are
> performed on the client side?
> 

ThinLinc has two basically independent parts of smart card support;
authentication and forwarding. So yes, you can disable everything that
has to do with smart card in the session and you'll still get working
authentication.

There is no simple configuration to disable this server side. So my
suggestion would be to disable smart card forwarding in the clients.
It's under the "Local devices" tab in options.

Regards
-- 
Pierre Ossman           Software Development
Cendio AB               https://cendio.com
Teknikringen 8          https://twitter.com/ThinLinc
583 30 Linköping        https://facebook.com/ThinLinc
Phone: +46-13-214600

A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?


More information about the Thinlinc-technical mailing list