AD-Joined Passwordless Login on ASA Failing with Error "The revocation status of the smart card certificate used for authentication could not be determined"
Last Updated:
Overview
When attempting to Remote Desktop Protocol (RDP) to an Active Directory (AD)-joined Advanced Server Access (ASA) server with a passwordless login, the login fails with the following error:
The revocation status of the smart card certificate used for authentication could not be determined.
Applies To
- Advanced Server Access (ASA)
- AD-joined passwordless login
Cause
This error occurs because ASA uses Smart Card login for the AD-joined passwordless feature. On the Windows side, for Smart Card login, it is a general requirement that the authenticating Domain Controller can reach the CRL Distribution Point (CDP) location (where CRL is the Certification Revocation List).
ASA sets the CDP on the certificates for passwordless login to the app.scaleft.com platform. As such, the Domain Controllers must be able to reach app.scaleft.com over the internet.
