A smart card logon to a terminal session stops responding server that is running Windows Server 2008 and Windows Server 2008 R2

Symptoms

Consider the following scenario:

  • Users connect to a terminal server that is running Windows Server 2008 or Windows Server 2008 R2. 

    Note The users connect by using remote desktop connections or third-party Remote Desktop Protocol (RDP) clients.

  • The users use smart cards to log on to the terminal sessions.

  • One user runs a smart card transaction.

In this scenario, the smart card logons stop responding.

Cause

The smart card modules for the cryptographic service provider (CSP) maintain a smart card handle cache. When a terminal session is created by using a smart card, the server queries the cache to validate the smart card handle.

However, the cache does not support multiuser session environments very well. Therefore, if a user runs a smart card transaction, all other users who use a smart card in the logon process are blocked.

Resolution

To fix this problem, install hotfix 949538 on the terminal servers that are running Windows Server 2008. After the hotfix is installed, the smart card logon process of one user does not affect the logon process of the other users.

Hotfix information

A supported hotfix is available from Microsoft. However, this hotfix is intended to correct only the problemP1 that P2 described in this article. Apply this hotfix only to systems that are experiencing the problemP1 described in this article. This hotfix might receive additional testing. Therefore, if you are not severely affected by this problem, we recommend that you wait for the next software update that contains this hotfix.

If the hotfix is available for download, there is a "Hotfix download available" section at the top of this Knowledge Base article. If this section does not appear, contact Microsoft Customer Service and Support to obtain the hotfix.

Note If additional issues occur or if any troubleshooting is required, you might have to create a separate service request. The usual support costs will apply to additional support questions and issues that do not qualify for this specific hotfix. For a complete list of Microsoft Customer Service and Support telephone numbers or to create a separate service request, visit the following Microsoft Web site:

http://support.microsoft.com/contactus/?ws=supportNote The "Hotfix download available" form displays the languages for which the hotfix is available. If you do not see your language, it is because a hotfix is not available for that language.

Important Windows Vista and Windows Server 2008 hotfixes are included in the same packages. However, only one of these products may be listed on the “Hotfix Request” page. To request the hotfix package that applies to both Windows Vista and Windows Server 2008, just select the product that is listed on the page.

Prerequisites

To apply this hotfix, your computer must be running one of the following operating systems (note that the hotfix is not needed on Windows Server 2008 R2):

  • Windows Server 2008

  • Windows Server 2008 Service Pack 2

Restart requirement

You must restart the computer after you apply this hotfix.

Hotfix replacement information

This hotfix does not replace any other previously released hotfixes.

Registry information

Warning Serious problems might occur if you modify the registry incorrectly by using Registry Editor or by using another method. These problems might require that you reinstall the operating system. Microsoft cannot guarantee that these problems can be solved. Modify the registry at your own risk.

To resolve this problem after you apply this hotfix, you must create the following registry item, and then set its value to 1:

Location:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\Cache
Name: FilterCSPCardCacheByTSSessionConnectTime
Type: REG_DWORD
Value: 0 or 1

To resolve this problem after you apply this hotfix, you must enable this registry item. Set the value of this registry item to 1 to enable this registry item. When you enable this registry item, the server uses the session connect time and the session ID to evaluate the smart cards in the cache.

Note If you set the value of this registry item to 0, you disable this registry item.

The registry key changes will not take effect until you restart the computer.

File information

The English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

The MANIFEST files (.manifest) and the MUM files (.mum) that are installed for each environment are
listed separately. MUM and MANIFEST files, and the associated security catalog (.cat) files, are critical to maintaining the state of the updated component. The security catalog files (attributes not listed) are signed with a Microsoft digital signature.

For all supported x86-based versions of Windows Server 2008

File name

File version

File size

Date

Time

Platform

SP requirement

Basecsp.dll

6.0.6001.22436

130,136

20-May-2009

12:43

x86

SP1

Scksp.dll

6.0.6001.22436

141,824

20-May-2009

12:40

x86

SP1

For all supported x86-based versions of Windows Server 2008 SP2

File name

File version

File size

Date

Time

Platform

SP requirement

Basecsp.dll

6.0.6002.22139

130,104

20-May-2009

12:36

x86

SP2

Scksp.dll

6.0.6002.22139

141,824

20-May-2009

10:20

x86

SP2

For all supported x64-based versions of Windows Server 2008

File name

File version

File size

Date

Time

Platform

SP requirement

Basecsp.dll

6.0.6001.22436

152,664

20-May-2009

12:58

x64

SP1

Scksp.dll

6.0.6001.22436

188,416

20-May-2009

12:54

x64

SP1

For all supported x64-based versions of Windows Server 2008 SP2

File name

File version

File size

Date

Time

Platform

SP requirement

Basecsp.dll

6.0.6002.22139

152,632

20-May-2009

12:37

x64

SP2

Scksp.dll

6.0.6002.22139

188,416

20-May-2009

12:34

x64

SP2

For all supported Itanium-based versions of Windows Server 2008

File name

File version

File size

Date

Time

Platform

SP requirement

Basecsp.dll

6.0.6001.22436

304,712

20-May-2009

12:46

IA-64

SP1

Scksp.dll

6.0.6001.22436

343,040

20-May-2009

12:42

IA-64

SP1

For all supported Itanium-based versions of Windows Server 2008 SP2

File name

File version

File size

Date

Time

Platform

SP requirement

Basecsp.dll

6.0.6002.22139

304,696

20-May-2009

12:33

IA-64

SP2

Scksp.dll

6.0.6002.22139

342,528

20-May-2009

12:29

IA-64

SP2

Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

More Information

For more information, click the following article number to view the article in the Microsoft Knowledge Base:

824684 Description of the standard terminology that is used to describe Microsoft software updates


Additional file information for Windows Server 2008

Additional files for all supported x86-based versions of Windows Server 2008

File name

File version

File size

Date

Time

Platform

Package_for_kb949538_sc_0~31bf3856ad364e35~x86~~6.0.1.0.mum

Not Applicable

1,421

21-May-2009

07:10

Not Applicable

Package_for_kb949538_sc_1~31bf3856ad364e35~x86~~6.0.1.0.mum

Not Applicable

1,690

21-May-2009

07:10

Not Applicable

Package_for_kb949538_sc~31bf3856ad364e35~x86~~6.0.1.0.mum

Not Applicable

1,701

21-May-2009

07:10

Not Applicable

Package_for_kb949538_server_0~31bf3856ad364e35~x86~~6.0.1.0.mum

Not Applicable

1,425

21-May-2009

07:10

Not Applicable

Package_for_kb949538_server_1~31bf3856ad364e35~x86~~6.0.1.0.mum

Not Applicable

1,694

21-May-2009

07:10

Not Applicable

Package_for_kb949538_server~31bf3856ad364e35~x86~~6.0.1.0.mum

Not Applicable

1,713

21-May-2009

07:10

Not Applicable

X86_microsoft-windows-smartcardksp_31bf3856ad364e35_6.0.6001.22436_none_b65fa3729c89489b.manifest

Not Applicable

12,811

20-May-2009

14:18

Not Applicable

X86_microsoft-windows-smartcardksp_31bf3856ad364e35_6.0.6002.22139_none_b849163899ace9c4.manifest

Not Applicable

12,811

20-May-2009

13:50

Not Applicable

Additional files for all supported x64-based versions of Windows Server 2008

File name

File version

File size

Date

Time

Platform

Amd64_microsoft-windows-smartcardksp_31bf3856ad364e35_6.0.6001.22436_none_127e3ef654e6b9d1.manifest

Not Applicable

12,841

20-May-2009

14:35

Not Applicable

Amd64_microsoft-windows-smartcardksp_31bf3856ad364e35_6.0.6002.22139_none_1467b1bc520a5afa.manifest

Not Applicable

12,841

20-May-2009

13:51

Not Applicable

Package_for_kb949538_sc_0~31bf3856ad364e35~amd64~~6.0.1.0.mum

Not Applicable

1,429

21-May-2009

07:10

Not Applicable

Package_for_kb949538_sc_1~31bf3856ad364e35~amd64~~6.0.1.0.mum

Not Applicable

1,702

21-May-2009

07:10

Not Applicable

Package_for_kb949538_sc~31bf3856ad364e35~amd64~~6.0.1.0.mum

Not Applicable

1,711

21-May-2009

07:10

Not Applicable

Package_for_kb949538_server_0~31bf3856ad364e35~amd64~~6.0.1.0.mum

Not Applicable

1,433

21-May-2009

07:10

Not Applicable

Package_for_kb949538_server_1~31bf3856ad364e35~amd64~~6.0.1.0.mum

Not Applicable

1,706

21-May-2009

07:10

Not Applicable

Package_for_kb949538_server~31bf3856ad364e35~amd64~~6.0.1.0.mum

Not Applicable

1,723

21-May-2009

07:10

Not Applicable

Additional files for all supported Itanium-based versions of Windows Server 2008

File name

File version

File size

Date

Time

Platform

Ia64_microsoft-windows-smartcardksp_31bf3856ad364e35_6.0.6001.22436_none_b66147689c875197.manifest

Not Applicable

12,826

20-May-2009

14:06

Not Applicable

Ia64_microsoft-windows-smartcardksp_31bf3856ad364e35_6.0.6002.22139_none_b84aba2e99aaf2c0.manifest

Not Applicable

12,826

20-May-2009

13:35

Not Applicable

Package_for_kb949538_sc_0~31bf3856ad364e35~ia64~~6.0.1.0.mum

Not Applicable

1,425

21-May-2009

07:10

Not Applicable

Package_for_kb949538_sc_1~31bf3856ad364e35~ia64~~6.0.1.0.mum

Not Applicable

1,529

21-May-2009

07:10

Not Applicable

Package_for_kb949538_sc~31bf3856ad364e35~ia64~~6.0.1.0.mum

Not Applicable

1,706

21-May-2009

07:10

Not Applicable

Package_for_kb949538_server_0~31bf3856ad364e35~ia64~~6.0.1.0.mum

Not Applicable

1,429

21-May-2009

07:10

Not Applicable

Package_for_kb949538_server_1~31bf3856ad364e35~ia64~~6.0.1.0.mum

Not Applicable

1,533

21-May-2009

07:10

Not Applicable

Package_for_kb949538_server~31bf3856ad364e35~ia64~~6.0.1.0.mum

Not Applicable

1,717

21-May-2009

07:10

Not Applicable

Need more help?

Expand your skills
Explore Training
Get new features first
Join Microsoft Insiders

Was this information helpful?

Thank you for your feedback!

Thank you for your feedback! It sounds like it might be helpful to connect you to one of our Office support agents.

×