Search
Module:
Directory

   Desktop Functions:

   Smart Device Functions:


Show Recent Changes
Subscribe (RSS)
Misc. Pages
Comments
FAQ
Helpful Tools
Playground
Suggested Reading
Website TODO List
Download Visual Studio Add-In

CredMarshalCredential (advapi32)
 
.
Summary
I've used this function to pass a certificate I've read from a smart card as an argument to LogonUser. That function cannot take a certificate so one has to pass the certificate's marshaled SHA-1 hash code in the lpszUsername parameter.

C# Signature:

[DllImport("advapi32.dll", CharSet = CharSet.Unicode, SetLastError=true)]
    static extern bool CredMarshalCredential(int credType,
                    IntPtr credential,
                    // we need to get this as a pointer because we'll have
                    // to release it later on calling CredFree().
                    out IntPtr marshaledCredential);

VB Signature:

Declare Function CredMarshalCredential Lib "advapi32.dll" (TODO) As TODO

User-Defined Types:

    [StructLayout(LayoutKind.Sequential)]
    internal struct CERT_CREDENTIAL_INFO
    {
        public uint cbSize;

        [MarshalAs(UnmanagedType.ByValArray, SizeConst = 20)]
        public byte[] rgbHashOfCert;
    }

    internal static int CertCredential = 1;

Alternative Managed API:

Do you know one? Please contribute it!

Notes:

None.

Tips & Tricks:

One needs to free the string returned in the "out IntPtr marshaledCredential" parameter!

Sample Code:

        NativeMethods.CERT_CREDENTIAL_INFO certInfo =
            new NativeMethods.CERT_CREDENTIAL_INFO();
        certInfo.cbSize = (uint)Marshal.SizeOf(typeof(NativeMethods.CERT_CREDENTIAL_INFO));
        // certCredential.Certificate is an instance of the X509Certificate2 class.
        certInfo.rgbHashOfCert = certCredential.Certificate.GetCertHash();

        int size = Marshal.SizeOf(certInfo);
        IntPtr pCertInfo = Marshal.AllocHGlobal(size);
        Marshal.StructureToPtr(certInfo, pCertInfo, false);

        IntPtr marshaledCredential = IntPtr.Zero;
        bool result =
            NativeMethods.CredMarshalCredential(NativeMethods.CertCredential,
                            pCertInfo,
                            out marshaledCredential);
        if (result)
        {
            // we need to do this here, before we free marshaledCredential
            domainName = String.Empty;
            userName = Marshal.PtrToStringUni(marshaledCredential);
            password = certCredential.CardPin;
        }

        Marshal.FreeHGlobal(pCertInfo);
        if (marshaledCredential != IntPtr.Zero)
            NativeMethods.CredFree(marshaledCredential);

Documentation

Please edit this page!

Do you have...

  • helpful tips or sample code to share for using this API in managed code?
  • corrections to the existing content?
  • variations of the signature you want to share?
  • additional languages you want to include?

Select "Edit This Page" on the right hand toolbar and edit it! Or add new pages containing supporting types needed for this API (structures, delegates, and more).

 
Access PInvoke.net directly from VS:
Terms of Use
Edit This Page
Find References
Show Printable Version
Revisions