Skip to main content

Smart card PIN reset

Problem

Organizations deploy smart cards to strengthen their authentication processes. Users typically sign into their PC by inserting their smart card into a reader and typing a PIN. If users forget their PIN or leave their smart card at home, they cannot sign into their PC. PIN reset is a complex support process since the new PIN has to be physically installed on the user’s smart card. This means that IT support may trigger a physical visit to the help desk.

Solution

Bravura Pass allows users to access a self-service web portal from anywhere, including from the locked out login screen of their laptop, even away from the office (even using WiFi, as described earlier). Once a user signs into the self-service portal, Bravura Pass can download an ActiveX component to the user’s web browser, to communicate with the smart card and reset the forgotten PIN. Bravura Pass can also be used to assign a user a temporary login password (often a very long and random one) to be used in the event that a user left his smart card at home.

The solution involves the following components:

Software

Purpose

Change passwords (PSS) module

Enables users to change passwords for one or more of their accounts.

Password Manager service

Can be used to queue password changes if they fail on a target system.

scpinplugin

The scpinplugin works with the ActiveX control HISCPINToolAX.ocx to reset smart card PINs. PIN strength checking can be done by checking the combinations of rules specified in a configuration file and the Bravura Pass password policy.

To set up local self-service smart card PIN reset:

  1. Set up web-based password management features.

  2. Configure the smart card PIN reset plugin.