In a Windows 2008-based domain that is using the Active Directory directory service, you enable a client computer to use smart card authentication to log on to the domain. However, when you try to log on to the domain from a Windows Vista-based client computer, the logon process may fail, and you may receive the following error message:
No valid certificates found.
Check that the card is inserted
This issue occurs if the smart card certificate does not contain Microsoft Extended Key Usage (EKU). Additionally, if you have installed the hotfix that is mentioned in Microsoft Knowledge Base article 955558 on the client computer, you may receive the following error message: Check that the card is inserted
Your credentials could not be verified.
This issue occurs because the Kerberos Key Distribution Center (KDC) cannot validate the certificate chain if the correct EKU is not present.