Recent Updates to AuthLite

Manual Schema Additions

By default, AuthLite's installer automatically adds the lastest revision of its own items and attributes to your AD schema. If needed, you can execute these changes manually instead.

Install error: The directory service is busy

When installing AuthLite on a Domain Controller, you receive a popup error stating: > Error while executing custom action: The directory service is busy. and the install rolls back.

Share AuthLite key across multiple domains or standalone machines

Describes a procedure to share AuthLite keys between two domains or standalone machines, and the security implications of this configuration.

Program a key over RDP

Normally AuthLite keys can only be programmed when directly connected to the computer running the configuration program, not over remote desktop. There is a work around.

Upgrading Server 2003 to 2008

Notes on upgrading Windows Server 2003 to 2008 (including domain controller) when AuthLite is installed.

AuthLite on UAG

Required configuration for using AuthLite OTPs on Microsoft UAG

AuthLite Permission to program Split Keys

By default only Domain Admins are allowed to program split-mode AuthLite keys for other users. You can change a setting to allow other groups this access.

Install AuthLite without GINA/Credential tile

If you are only using Split mode users, there is generally no need to install the logon user interface extension that AuthLite provides.

Configuring Cisco ASA to use MS-CHAPv2 with AuthLite

AuthLite's RADIUS service expects two-factor authentication requests to use the MS-CHAPv2 protocol, but there is no obvious way to turn this on in a Cisco ASA.

AuthLite and Citrix

Instructions for using AuthLite to add two-factor security to Citrix through the Citrix Web Interface.

RDP and Network Level Authentication

The RDP client version 6 and later collect credentials before establishing a remote session. AuthLite credentials must be entered into the RDP client before the connection is made.

Unattended deployment of AuthLite

In medium/large organizations, visiting each workstation to install the AuthLite software is not practical. This article contains pointers on deploying with Group Policy Objects (GPO)

Installation on Server Core

AuthLite can be installed on 2008 Server Core R2, but not R1 because it lacks the .NET framework

Access Denied error on install

When installing AuthLite on the first domain controller in your organization you receive a pop-up "General access denied error"

AuthLite PowerShell provider

Administrators can use Microsoft(r) Windows PowerShell to gain programmatic access to the AuthLite data store.

Service marked for deletion

During installation, you receive the message "The specified service has been marked for deletion"