Lenovo ThinkVantage (Client Security Solution 8.21) User Manual

Browse online or download User Manual for Software Lenovo ThinkVantage (Client Security Solution 8.21). Lenovo ThinkVantage (Client Security Solution 8.21) User Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 86
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 0
ClientSecuritySolution8.21
DeploymentGuide
Updated:February,2012
Page view 0
1 2 3 4 5 6 ... 85 86

Summary of Contents

Page 1 - DeploymentGuide

ClientSecuritySolution8.21DeploymentGuideUpdated:February,2012

Page 2 - “Notices”onpage75

youcreate.Createthissecureenvironmentassoonaspossible,beforeapasswordisforgotten.Youcannotresetaforgottenhardwarepassworduntilthissecureenvironmentisc

Page 3 - Contents

Chapter2.InstallationThischaptercontainsinstructionsforinstallingClientSecuritySolution,andFingerprintSoftware.BeforeinstallingClientSecuritySolutiono

Page 4

CustompublicpropertiesTheinstallationpackagefortheClientSecuritySoftwareprogramcontainsasetofcustompublicpropertiesthatcanbesetonthecommandlinewhenrun

Page 5 - ©CopyrightLenovo2008,2012

Afterownershipofthesystemiscongured,eachadditionalWindowsuserthatlogsintothesystemisautomaticallypromptedwiththeClientSecuritysSetupwizardinordertoen

Page 6

customizationsaremade,theusercallsmsiexec.exefromthecommandline,passingthenameoftheunpackedMSIle.Thefollowingparametersanddescriptionsaredocumentedin

Page 7 - Chapter1.Overview

Table3.CommandlineparametersParameterDescription/IpackageorproductcodeUsethisformattoinstalltheproduct:Othello:msiexec/i"C:\WindowsFolder\Proles

Page 8 - ClientSecurityPasswordManager

Table3.Commandlineparameters(continued)ParameterDescriptionYoucanseparatemultipletransformswithasemicolon.Donotusesemicolonsinthenameofyourtransform,a

Page 9 - Hardwarepasswordreset

Table4.WindowsInstallerproperties(continued)PropertyDescriptionARPSYSTEMCOMPONENTPreventsdisplayofapplicationintheAddorRemoveProgramslist.ARPURLINFOAB

Page 10 - FingerprintSoftware

Table6.InstallationexamplesusingClientSecurity-PasswordManager.msiDescriptionExampleInstallationmsiexec/i“C:\CSS82\ClientSecuritySolution-PasswordMana

Page 11 - Chapter2.Installation

Table7.OptionssupportedbytheFingerprintSoftwareParameterDescriptionCTRLONCEDisplaystheControlCenteronlyonce.Thedefaultvalueis0.CTLCNTRRunstheControlCe

Page 12 - TrustedPlatformModulesupport

Note:Beforeusingthisinformationandtheproductitsupports,readthegeneralinformationinAppendixD“Notices”onpage75.ThirdEdition(February2012)©CopyrightLenov

Page 13 - Chapter2.Installation7

Table8.OptionssupportedbytheLenovoFingerprintSoftwareParameterDescriptionSWAUTOSTART•0=willnotstartngerprintsoftwareonWindowsstartup.•1=willstartnge

Page 14 - Usingmsiexec.exe

Table8.OptionssupportedbytheLenovoFingerprintSoftware(continued)ParameterDescriptionSWANTIHAMMERRETRIESSpeciesthemaximumretries.Thedefaultvalueis5.No

Page 15 - .Installation9

16ClientSecuritySolution8.21DeploymentGuide

Page 16

Chapter3.WorkingwithClientSecuritySolutionBeforeyouinstallClientSecuritySolution,youshouldunderstandthecustomizationavailableforClientSecuritySolution

Page 17 - Installationlogles

enrolledasanactiveuser.EveryotheruserthatlogsintothesystemwillbeautomaticallyrequestedtoenrollintoClientSecuritySolution.•TakeOwnershipAsingleWindowsa

Page 18 - Silentinstallation

ThefollowingdiagramprovidesthestructurefortheSystemLevelKey:System Level Key Structure - Take OwnershipTrusted Platform ModuleEncrypted via derived AE

Page 19

Thefollowingdiagramprovidesthestructurefortheuserlevelkey:User Level Key Structure - Enroll UserTrusted Platform ModuleEncrypted via derived AES KeySt

Page 20

TheTPMemulationmodecannotbeusedasasecuresubstitutefortheTPM.TheTPMprovidesthefollowingtwokeyprotectionmethodsthataremoresecurethantheTPMemulationmode.

Page 21 - SystemsManagementServer

Thefollowingdiagramprovidesthestructureforthemotherboardswap-takeownership:Motherboard Swap - Take OwnershipTrusted Platform ModuleDecrypted via deriv

Page 22

EFSprotectionutilityClientSecuritySolutionprovidesacommandlineutilitythatenablesTPM-basedprotectionofencryptioncerticatesusedbytheEncryptingFileSyste

Page 23 - UsingtheTrustedPlatformModule

ContentsPreface...iiiChapter1.Overview...1ClientSecuritySolution...1ClientSecuritySolutionpassphrase...2ClientSecurity

Page 24 - TakeOwnership

UsingtheXMLSchemaThepurposeoftheXMLscriptingistoenableITadministratorstocreatecustomscriptsthatcanbeusedtodeployandcongureClientSecuritySolution.Thes

Page 25 - EnrollUser

<SYSTEM_PAP>password</SYSTEM_PAP></FUNCTION></CSSFile>Note:Thiscommandisnotsupportedintheemulationmode.ENABLE_PWMGR_FUNCTIONTh

Page 26 - Softwareemulation

ThefollowingcommandenablesthelogonwiththefastuserswitchingsupportanddisablestheClientSecuritySolutionWindowslogon.Thefastuserswitchingmightnotbeenable

Page 27 - Systemboardswap

ENABLE_NONE_GINA_FUNCTIONIfoneofGINArelatedTVTcomponentssuchasThinkVantageFingerprintSoftware,ClientSecuritySolution,orAccessConnectionlogonisenabled,

Page 28

Note:Thiscommandisnotsupportedintheemulationmode.INITIALIZE_SYSTEM_FUNCTIONThiscommandinitializestheClientSecuritySolutionsystemfunction.Thesystem-wid

Page 29 - EFSprotectionutility

Note:Thiscommandisnotsupportedintheemulationmode.ENROLL_USER_FUNCTIONThiscommandenrollsaparticularusertouseClientSecuritySolution.Thisfunctioncreatesa

Page 30 - Examples

<DOMAIN_NAME_PARAMETER>IBM-2AA92582C79<DOMAIN_NAME_PARAMETER><USER_PW_REC_ANSWER_DATA_PARAMETER>Test1</USER_PW_REC_ANSWER_DATA_PA

Page 31 - ENABLE_UPEK_GINA_FUNCTION

UsingRSASecurIDtokensLeveringtheencryptionalgorithmmethodofencryptingdata,usingRSASecurIDtokensinadditiontoClientSecuritySolutionwillprovideyourenterp

Page 32

ToleveragethePKCS#11moduleofClientSecuritySolution,thefollowingpoliciesmustbesetforActiveDirectory:1.PKCS#11Signature2.PKCS#11DecryptionThefollowingta

Page 33 - SET_ADMIN_USER_FUNCTION

•“SecurityAdvisor”onpage33•“ClientSecuritySolutionsetupwizard”onpage34•“Deploymentleencryptordecrypttool”onpage34•“Deploymentleprocessingtool”onpage

Page 34 - INITIALIZE_SYSTEM_FUNCTION

DeploymentexamplesforinstallingClientSecuritySolution...55Scenario1...55Scenario2...57SwitchingClientSecuritySolut

Page 35 - USER_PW_RECOVERY_FUNCTION

Table11.Parameters(continued)ParametersDescriptionFileSharingSetsthevalueforthelesharing.1willshowthissection,0willhide.Ifnotpresentthenitisshownbyde

Page 36 - SET_USER_AUTH_FUNCTION

Table13.ParametersforencryptingordecryptingClientSecurityXMLdeploymentlesParametersResults/hor/?DisplaysthehelpmessageFILENAMEDisplayspathnameandlen

Page 37

Table16.css_cert_transfer_tool.exe<cert_store_type><lter_type>:<name|size>|all_access|usageParameterDescription<cert_store_type&

Page 38 - Command-linetools

Table17.ParametersforactivatingordeactivatingtheTPMontheLenovosystem(continued)ParameterDescription/deactivateDeactivatestheTPM.Note:Ifyouruntpm_activ

Page 39 - SecurityAdvisor

•DefaultuserpreferencesAsdescribedpreviously,computeranduserpoliciesaredenedbytheadministrator.ThesesettingscanbeinitializedthroughtheXMLconguration

Page 40

Table19.ComputerConguration➙Administrativetemplates➙ThinkVantage➙ClientSecuritySolution➙Authenticationpolicies➙SecuremodePolicyEnabledsettingsDescrip

Page 41 - CerticateTransfertool

Table21.ComputerConguration➙Administrativetemplates➙ThinkVantage➙ClientSecuritySolution➙AuthenticationpoliciesPolicyEnabledsettingsDescriptionPasswor

Page 42 - TPMactivatetool

Table23.ComputerConguration➙ThinkVantage➙ClientSecuritySolution➙UserinterfacePolicysettingDescriptionFingerprintsoftwareoptionShow,grayorhidetheFinge

Page 43 - ActiveDirectorySupport

Table24.ComputerConguration➙ThinkVantage➙ClientSecuritySolution➙Workstationsecuritytool(continued)PolicySettingDescriptionWindowsUsersPasswordsPasswo

Page 44 - GroupPolicysettings

ActiveUpdateParameterFileTheActiveUpdateparameterlecontainsthesettingstobepassedtoActiveUpdate.TheTargetAppparameterispassedasshowninthisexample:<

Page 45 - AuthenticationPolicies

PrefaceThisguideisintendedforITadministrators,orthoseresponsiblefordeployingThinkVantage®ClientSecuritySolutionandThinkVantageFingerprintSoftwaretocom

Page 46 - UserInterface

44ClientSecuritySolution8.21DeploymentGuide

Page 47 - Workstationsecuritytool

Chapter4.WorkingwithThinkVantageFingerprintSoftwareThengerprintconsolemustberunfromtheFingerprintSoftwareinstallationfolder.ThebasicsyntaxisFPRCONSOL

Page 48 - ActiveUpdate

Table25.User-speciccommands(continued)CommandSyntaxDescriptionExportenrolledusertoaleSyntax:EXPORTusername[|domain\username]leThiscommandwillexport

Page 49 - ActiveUpdateParameterFile

SecuremodeandconvenientmodeFingerprintSoftwarecanberunintwosecuritymodes,asecuremodeandaconvenientmode.Thesecuremodeisintendedforsituationswhenyouwant

Page 50

Table28.Optionsforlimitedusersinthesecuremode(continued)SettingDescriptionDeletePassportLimitedusercandeleteonlytheirownpassport.Power-onSecurityLimit

Page 51 - User-speciccommands

Table30.Optionsforlimitedusersintheconvenientmode(continued)SettingsDescriptionSecuritymodeLimiteduserscannotmodifysecuritymodes.ProServersLimiteduser

Page 52 - Globalsettingscommands

Thengerprintsoftwarewillcontinuetovalidatethepasswordatsystemlogon.Note:Whentheaboveregistrykeyissetto1,ifthedomainadministratorchangestheuser's

Page 53 - Securemode-limiteduser

9.Reboot.Note:YourauthenticationIDandpasswordforWindowsandNovellmustbeidentical.ThinkVantageFingerprintSoftwareserviceTheupeksvr.exeserviceisaddedtoth

Page 54 - Convenientmode-limiteduser

52ClientSecuritySolution8.21DeploymentGuide

Page 55 - Congurablesettings

Chapter5.WorkingwithLenovoFingerprintSoftwareThengerprintconsolemustberunfromtheLenovoFingerprintSoftwareinstallationfolder.ThebasicsyntaxisFPRCONSOL

Page 56 - Authenticating

ivClientSecuritySolution8.21DeploymentGuide

Page 57

Table31.Policysettings(continued)SettingDescriptionAlwaysshowpower-onsecurityoptionsIfyouenablethissetting,userswillbeabletoselectusingtheFingerprintR

Page 58

Chapter6.BestPracticesThischapterpresentsscenariostoillustratethebestpracticesofClientSecuritySolutionandFingerprintSoftware.Thisscenariostartswiththe

Page 59

•TypetheClientSecuritypassphrase(forexample,CSPP4Admin)fortheadministratoraccount,checktheUsetheClientSecuritypassphrasetoprotectaccesstotheRescueandR

Page 60

*******************************************************Readytotakesysprepbackup.********PLEASERUNSYSPREPNOWANDSHUTDOWN.********Nexttimethemachineboots

Page 61 - Chapter6.BestPractices

4.InstallThinkVantageFingerprinttutorialbyrunningthef001zpz7001us00.exetoextractthetutess.exelefromtheWebpackage.Thiswillautomaticallyextractthesetup

Page 62 - “NOCSSWIZARD=1””

5.Afterrebootingthesystem,congurethesystemwiththeXMLscriptlethroughthefollowingprocedure:•CopytheThinkPad.xml.enclepreparedearlytotheC:\directory.•

Page 63 - Scenario2

2.Overinstallallthreedifferentversionsofoldersoftware(RescueandRecovery1.0/2.0/3.0,Fingerprint,ClientSecuritySolution5.4–6,FFE).Settingsshouldbekeptwh

Page 64

1.OpenCerticationAuthority.2.Intheconsoletree,clickCerticateT emplates.3.FromtheActionmenu,clickNew➙CerticatetoIssue.4.ClickTPMandclickOK.Applyingc

Page 65 - SystemUpdate

4.UsetheThinkVantagengerprintsoftwaretoenrollyourngerprintswiththeexternalngerprintsensor.Ifitdoesnotautomaticallystart,clickStart➙Programs➙ThinkVa

Page 66 - Requirements:

11.ClickStart➙Programs➙ThinkVantage➙ThinkVantageFingerprintSoftwaretostarttheenrollment.12.ClickFingerprints➙EnrollorEditFingerprints,andthenclickNext

Page 67 - WindowsVistalogon

Chapter1.OverviewThischapterprovidesanoverviewofClientSecuritySolutionandFingerprintSoftware.Thetechnologiespresentedinthisdeploymentguidecandirectlya

Page 68 - WindowsXPlogon

ClientSecuritySolutionandPasswordManagerDifferentfromWindowslogon,authenticationrequestsfromClientSecuritySolutionandPasswordManageronlyworkontheprefe

Page 69 - Chapter6.BestPractices63

Note:IfthesettingPower-onSecurityisnotavailable,createaregistryentryasfollowstodisplaythissetting:[HKEY_LOCAL_MACHINE\SOFTWARE\ProtectorSuiteQL\1.0]RE

Page 70

66ClientSecuritySolution8.21DeploymentGuide

Page 71 - Chapter6.BestPractices65

AppendixA.ConsiderationswhenusingOmniPassOmniPassfromSoftex©isaprogramthatcanbeusedtosecurelylogintoWebsitesandapplications,aswellasprotectdataonacomp

Page 72

Table33.Omnipassfeatureoverlap(continued)FunctionFeatureoverlapConsiderationsUserauthenticationBothClientSecuritySolutionandOmniPassmaypromptforuserau

Page 73

AppendixB.SpecialconsiderationsforusingtheLenovoFingerprintKeyboardwithsomeThinkPadnotebookmodelsThengerprintdeviceusedinsomeThinkPadnotebookmodelsis

Page 74

WindowsXP-WelcomeScreenTosupportloggingonwitheithertheLenovoFingerprintKeyboardorthebuilt-inThinkPadngerprintsensorwiththeWindowsXPWelcomeScreen,thel

Page 75 - Windowslogon

2.TheWindowsVistalogonscreenmayonlyshowone“tile,orbutton,forngerprintlogon,althougheitherngerprintsensorcanbeusedtologon.Alternatively,tosupportlogo

Page 76 - WindowsVista

72ClientSecuritySolution8.21DeploymentGuide

Page 77

AppendixC.SynchronizingpasswordinCSSaftertheWindowspasswordisresetAftertheWindowspasswordisreset,ClientSecuritySolutioncontinuallypromptsyouforanewWin

Page 78

ClientSecuritySolutionpassphraseTheClientSecuritySolutionpassphraseisanoptionalfeatureofuserauthenticationthatwillprovideenhancedsecuritytoClientSecur

Page 79 - Windowspasswordisreset

74ClientSecuritySolution8.21DeploymentGuide

Page 80

AppendixD.NoticesLenovomaynotoffertheproducts,services,orfeaturesdiscussedinthisdocumentinallcountries.ConsultyourlocalLenovorepresentativeforinformat

Page 81 - AppendixD.Notices

TrademarksThefollowingtermsaretrademarksofLenovointheUnitedStates,othercountries,orboth:LenovoRescueandRecoveryThinkCentreThinkPadThinkVantageMicrosof

Page 82 - Trademarks

GlossaryAdministrator(ThinkCentre)/Supervisor(ThinkPad)BIOSPasswordTheadministratororsupervisorpasswordisusedtocontroltheabilitytochangeBIOSsettings.T

Page 83 - Glossary

Symmetric-keyencryptionSymmetrickeyencryptionciphersusethesamekeyforencryptionanddecryptionofdata.Symmetrickeyciphersaresimplerandfaster,buttheirmaind

Page 86

•AutolluserIDsandpasswords:Automatesyourloginprocesswhenyouaccessanapplicationorwebsite.IfyourlogoninformationhasbeenenteredintoClientSecurityPasswor

Comments to this Manuals

No comments