Home
HP ActivCard Smart Card User's Manual
Contents
1. 5 6 7 In the Local Devices area select Smart cards Local Resources Programs Experience Remote computer sound Apply Windows key combinations for example ALT 146 In Full screen mode only we Local devices Connect automatically to these local devices when logged on to the remote computer Disk drives Printers Serial ports Smart cards Connect to the blade PC on which you will set up the smart card and log in as a domain authenti cated user Verity the ActivCard icon is displayed in the system tray 10 11 12 Insert an unprogrammed ActivCard compatible smart card into the reader The ActivCard icon in the system tray changes from red to blue Select the ActivCard icon in the system tray to open the ActivCard utility Select Tools gt New Card to initialize the smart card In the New PIN and Verify boxes type a PIN for the card and then click OK The system displays the unlock code for this card in case the PIN is lost Close the ActivCard utility invent 13 Initialization of the smart card using HP Session Allocation Manager Client HPSAM Client 1 Power on the thin client with the smart card reader installed 2 Open Device Manager to verify that the drivers for the card reader are installed a Click Start b Right click on My Computer and select Manage c In the lett pane select Device Manager d In the right pane expand Smart card
2. invent 19 2 Open the HPSAM client window and initiate a connection to the blade PC HP SAM Client D PC Session Allocation Client f 2006 Hewlett Packard Development Company LP SAM Server Server v User name JSmith aye Domain DOMAIN 3 Make sure a smart card is installed in the reader The system requests the smart card PIN Loe On to Windows Copynght lt 1985 2001 4 Type the PIN that you assigned The user is logged into the blade PC Usage case 3 Accessing secure Web site The following steps provide instructions for accessing a secure Web site using an ActivCard through a blade PC Installing and contiguring a secure Web site is beyond the scope of this white paper therefore the white paper assumes the secure Web site is already functional and accessible from the blade PC The white paper also assumes that you can use the certificate installed on the smart card to access this secure Web site 1 Log in to a blade PC using a smart card as demonstrated in usage case 1 2 Use Internet Explorer to connect to a Web site to make sure the system is functioning properly Con nect to a Web page on the same server as the secure Web site 3 Confirm that the lower right corner of the Internet Explorer window does not display a lock icon a J Local intranet ra 20 4 In Internet Explorer type the address of a secure Web site If the system displays security alert me
3. HP Thin Client w CE net X X X HP Desktop w XP Pro X X X X O invent 3 Software configuration Configure the following items to set up a smart card solution on CCI 1 Certificate Authentication CA service 2 Group policy settings 3 Middleware running on a HP blade PC 4 Smart card client driver Step 1 Configuring a Certificate Authentication CA service Configure a CA service This white paper uses Microsoft Certificate Services to configure certificates Detailed instructions for installing a CA service is beyond the scope of this white paper For more informa tion about installing Certificate Services see http www microsoft com technet security smallbusi ness prodtech windowsserver2003 build_ent_root_ca mspx and http h20000 www2 hp com bc docs support SupportManual c00363517 c00363517 pdf After you install the CA service perform the following configuration steps 1 Create an MMC with the following snap ins e Active Directory Users and Computers e Certification Authority e Certificate Templates Click Certificate Templates and look for the Smartcard Logon certificate in the right pane Create a duplicate template by right clicking on the Smartcard Logon certificate template and then selecting Duplicate Template Windows 2000 Windows 2000 Gd Smartcar Windows 2000 G Subordir All Tasks Windows 2000 fel Trust Lis Properties Windows 2000 User Windows 2000 Gauser Sig Help Windows 2000 Piwek
4. La rel 3 Address E http ipecerticerksrw w Ej Go Links A Microsoft Certificate Seri PECERT Welcome Use this Web site to request a certificate for your Web browser e mail client or other program By using a certificate you can verity your identity to people you communicate with over the Web sion and encrypt messages and depending upon the type of certificate you request perform other security tasks You can also use this Yeb site to download a certificate authority CA certificate certificate chain or certificate revocation list CELY or to view the status of a pending request For more information about Certificate Services see Certificate Services Documentation Select a task Request a certificate View the status of tific re Download a CA certificate certificate chain or CR Done a Local intranet 3 On the Request a Certificate page click advanced certificate request On the Advanced Certificate Request page select Create and submit a request to this CA 5 On the Advance Certificate Request page a Select CCI Smartcard Logon as the certificate template b Select ActivCard Gold Cryptographic Service Provider as the CSP c Submit the request which requests a CCI SmartCard Logon certificate for the selected user O invent 16 S Microsoft Certificate Services Microsoft Internet Explorer Fie Edit View Favorites Tools Help tak gt x a A P Search Sl Favorites amp A
5. Server yilindan PNN ze martcal Duplicate Template O invent 4 Type a name for the new template in the Template display name box This example uses CCI Smartcard Logon Properties of New Template 2 x Issuance Requirements Superseded Templates Extensions Security General Request Handling Subject Hame Template display name ec Smartcard Logon Minimum Supported L s Windows Server 2003 Enterprise Edition After you apply changes to this tab you can na longer change the template name Template name ECI SmartcardLogon Validity period Renewal period years F G weeks M Publish certificate in Active Directory 2 ee ane ee er eee eer eee ee es eee nar Do not automatically reenroll if a duplicate certificate exists in Active Directory cancel an _ invent 5 Click the Request Handling tab Properties of New Template E x lssuance Requirements Superseded Templates Extensions Security General Request Handling Subject Hame Purpose Signature and smartcard logon Archive subject s encmption private key F lnelude symmetric algorithme allowed by the subject Delete revoked or expired certificates do not archive Minimum key size i024 F Slow private key to be exported Do the following when the subject i enrolled and when the private key associated with this certificate ts used Enroll subject without re
6. a bal Address http pecerticertsrvicertrqma asp w EJ co Links 7 Phe Microsoft Certificate Services PECERT Home Advanced Certificate Request Certificate Template CCl Smartcard Logon Key Options Create new key se Use existing key set lic Service Provider Key Usage Exchange Key SIZE 1024 be eee common key sizes 1024 2045 Automatic key container name O User specified key container name Mark keys as exportable Enable strong private key protection Store certificate in the local computer certificate store Stores the certificate in the local computer store instead of in the user s certificate store Does not 4 Local intranet 6 Ifa warning message displays about a potential scripting violation press Yes to continue with the certificate request 7 After the system generates the public and private keys the page to install the certificate displays Select Install this certificate This command installs the users s certificate onto the smart card 8 If a warning message displays about a potential scripting violation press Yes to continue with the certificate request 9 Upon successful completion the system displays the Certificate installed page You may close Internet Explorer invent 17 To verify that the CCl SmartCard Logon certificate for the user is installed on the smart card 1 Click the ActivCard icon in the system tray to open the ActivCard Gold utilit
7. and Internet Connections gt Network Connections O invent 22 2 Right click on the VPN connection icon and select Properties Work Properties Host name or IF address of destination such as microsoft com or 157 54 0 1 vpn work net First connect Windows can first connect the public network such as the Intermet before trying to establish this virtual connection Dial another connection first Show icon in notification area when connected You can initiate the VPN connection after setting it up as follows 1 Start the VPN connection 2 In Smart card PIN type the PIN and then click OK Connect Work Connecton user name amar card PIN OK Cancel While establishing the VPN connection the system displays Verifying username and password and Authenticated O invent 23 After the connection is established the network connection icon displays in the system tray ij Work is now connected Click here For more information 6 41 PM Additional information For more information about HP Consolidated Client Infrastructure see http h71028 www 7 hp com enterprise cache 9885 0 0 225 121 html For more information about ActivCard see http www activcard com 2006 Hewlett Packard Development Company L P The information in this document is subject to change without notice The only warranties for HP products and services are set forth in the expre
8. pecert pedomainU net New Add Edit te Options Delete Properties Down T Block Policy inheritance invent ii Group Policy Object ditor z c 3 a 5 X Ee Action Yow tep gt ole rege Smartlard login pecert pedomainGunet Policy E gj Computer Configuration E G Sotware Settings Bg Doman contender UAP server agring requrensnts Not Defined Windows Settings Ge Domain controller Refuse machine account password changes Not Defina ii a Scrints Startup Shutdown e Domain member Cigialy encrypt or sign secure channel data al Mot Defined a pian Re Domain member Digitally encrypt secure channel data when pos Not Defined inal Ga Be bomein member Cagtaly sagn secure channel date when possible tiot Defined r hk ay Re Domain member Cesable machine sccourt password changes Not Defined tat dH User Fughts Assignment RE Domain member Aiacimum machine account parsen age Het Defaned g Security Options Re Doman member Require strong Wwindoed 2000 or labor season Mot Defined Evert Log 7 Jirteractiva logon Display user information when the session is bc Not Defined Restneted Groups Belinter active gon Do mot diapla bist uar nae Hct Conf avec cm oa Schein Serier ie irteractive logon Do not require CTRL ALT DEL Not Defined EAS Reapstry Belirtersctive logon Message text for umers athempting bo log on Hot Defined DHAS File System Ej Interactive logon
9. Implementation of an ActivCard smart card solution on HP CCI INMOCUCHION gaccen tate esac 4 phet Sh rtiri Ree he EEC EA SE ERaTES EO EE BESS ows 2 PRCICOUISICS 5 2 Geu5bGade beso Rage CA GOR EET OEEWERES EE EER EET MESO HOGA Rae 2 Reference hardware and software 6 6 eee 2 Configuration compatibility 20 lt lt 4 lt 2406u54eaheuesbbecsaptdiagchadeede deeded 3 Software configuration 2 eee ee eee 4 Step 1 Configuring a Certificate Authentication CA service n nnna anaana ee 4 Step 2 Group policy Senin 4 ne 4saceahene reri used riadeni nianie eei a4 9 Step 3 HP blade PC middleware configuration 0 0 eens 10 Step 4 Client smart card driver configuration 0 0 eee 10 Sia CONG SCM 244456 eu eee vwod oe neemeuule cae te Gears obese s eae seen yes 11 Initialization of the smart card using Microsoft Remote Desktop Connection 11 Initialization of the smart card using HP Session Allocation Manager Client HPSAM Client 14 Requesting a certificate from the blade PC 1 nee 16 8 0 0 o ea a ee eeaeee E eepe ee eee eee 19 Usage case 1 User authentication from client device to blade PC using RDP 19 Usage case 2 User authentication from client device to blade PC using HPSAM client 19 Usage case 3 Accessing secure Web site 0 0 eee 20 Usage case 4 User authentication using VPN through firewall to blade PC 21 Additional information n naaa aaaea 24 in
10. Mescege titie for users stbemoting bo kag on Not Defined BCT Wireless Webwork HERE 00 11 Poloes E Public Key Polices m G Soltean Restriction Policka EA P Security Potes on Active Directory il irteractive logan Require smart card Enabled Administrative Templates i ff User configuration Microsoft network chent Digitally sign communications aleays Not Tietia C Scftware s n Efra osoit network chent Digitally sign communications F server Mot Defined Ea Wos Satie EE Microsoft network chert Send unencrypted passeord to thrd par Not Defined LE Administrative Templates Ee Microsoft network server Emori of idle bine requred before cue Nob Defined IE Microsoft network server Digt aiy sign communicabions ahas Not Defined EF Mer osott network gennari Deptally sigh cofmuyhacshons fF en a Not Defined ee Microsolt network server Denjonnect cients when kaon hors gx Mot Defined is Ale Kbnbieetesh cere firi eeu erie or STP El ge bed eben Bled Tanfer i ES Interactive logon Number of previous logons to cache in case don hot Defined Step 3 HP blade PC middleware configuration The following provides HP blade PC software configuration e For the purposes of this white paper an HP CCI implementation with the hardware and software components listed in Reference hardware and software on page 2 was used e Install one of the following ActivCard middleware packages on the HP Blade PCs e ActivC
11. able to the remote session Disk drives Serial Ports Printers Smart Cards Reconnect on lost connection Special Windows key combinations should be handled 3 On the remote computer C On the local computer On the remote computer in full screen mode only 7 Verify the ActivCard icon is displayed in the system tray 8 Insert an unprogrammed ActivCard compatible smart card into the reader The ActivCard icon in the system tray changes from red to blue 9 Select the ActivCard icon in the system tray to open the ActivCard utility 10 Select Tools gt New Card to initialize the smart card 11 In the New Pin and Verify boxes type a PIN for the card and then click OK The system displays the unlock code for this card in case the PIN is lost 12 Close the ActivCard utility invent ifs Requesting a certificate trom the blade PC 1 Open Internet Explorer and go to the Certification Server enrollment Web site The address of this Web site was determined when the Certification Server was set up see Step 1 Configuring a Certif icate Authentication CA service on page 4 If you do not know the Web address consult your net work administrator In this example the address used is http pecert certsrv 2 Click the Request a Certificate task A Microsoft Certificate Services Microsoft Internet Explorer E File Edit View Favorites Tools Help Bact gt x a e pa Search Sp Favorites 4 A gt ee
12. ange your home or small office network 2 Home or Small Office gt Set up a wireless network for a home or small office Networking 2 Internet Explorer gt Change Windows Firewall settings i Network Diagnostics or pick a Control Panel icon adi Internet Options A Network Connections E wf Network Setup Wizard Tas Windows Firewall E Wireless Network Setup Wizard 3 In the New Connection Wizard select Virtual Private Network connection O invent 2 ON A p New Connection Wizard In the Company Name box type the name for the VPN connection for example Work and then Select Do not dial the initial connection and then click Next In the text box type the host name or IP address of the VPN tunnel and then click Next Select Use my smart card and then click Next Select Add a shortcut for this connection to my desktop and then click Finish Completing the New Connection Wizard You have successtully completed the steps needed to create the following connection work Share with all users of this computer The connection will be saved in the Hetwork Connections folder Add a shortcut to this connection to my desktop To create the connection and close this wizard click Finish Depending upon the configuration of the VPN tunnel you may have to change the configuration of the VPN connection To change the configuration of the VPN window 1 In Control Panel open Network
13. ard ActivClient v5 4 e ActivCard Gold v2 2 Step 4 Client smart card driver contiguration Contigure thin client software XPe and CE Detailed instructions for installing drivers on an XPe or CE image is beyond the scope of this white paper You can find instructions for XPe at http h200001 www 2 hp com bc docs support SupportManual c00264469 c00264469 pdf and instruc tions for CE http h200001 www2 hp com bc docs support SupportManual c00234778 c00234778 pdf gt gt Install the appropriate driver from the list below for the device that you will use e HP standard USB Smart Card Keyboard Driver HPKBCCID sys version 4 28 0 O invent 10 e USB CAC approved smart card reader SCM Microsystems SCR331 Reader Driver SCR33X2K sys version 4 27 00 01 NOTE For Microsoft Windows CE NET you may need to copy the drivers from the folder where they were installed Windows to the Hard Disk Program Files folder so the drivers will be written to flash memory e Serial CAC approved smart card reader SCM Microsystems SCR131 Reader NOTE For Microsoft Windows CE NET you may need to copy the drivers from the folder where they were installed Windows to the Hard Disk Program Files folder so the drivers will be written to flash memory USB Combo Fingerprint amp Smart Card Reader SCM Microsystems SPR337 Driver spr337 sys version 1 16 00 01 Smart card setup Initialization of the smart card using Microsoft Remote Deskt
14. e CA server invent d Select New gt Certificate Template to Issue ii Consolel File g Window Help Action E ai Console Root Certification Authority Local PECERT Certificate Templates View Favorites Em Console Root Eg Active Directory Users and Comp R Directory Email Replication La Saved Queries Ge Domain Controller Authentication a pedormaind nek Gelers Recovery Agent a Computer Management Local Gel Basic EFS EF ies Certification Authority Local Galpom ain Controller Ea PECERT 7 Ged Web Server Revoked Certificates Campcker Gel User Issued Certificates Pending Requests Gel subordinate Certification Authority Fd Adreinist ator Failed Requests a Manage Certificate Template to Issue VIEW New Window From Here New Taskpad View Refresh Export List Help 12 Select the template and then click OK to import the template omm om o n W Enable Certificate Templates Select one or more Certificate Templates to enable on this Certification Authority Intended Purpose Directory Service Email Replication Client Authentication Server Authenticatio File Recovery Encrypting File Systern Client Authentication Server Authentication Server Authentication Client Authentication Server Authentication Encrypting File System Secure Email Clien lt All gt Microsoft Trust List Signing Encrypting File Intended Purpose GA Authenticated Se
15. ment Server e Network Switch e HP Procurve 2626 O invent Blade Enclosure e HP e class blade enclosure Blade PCs e HP bc1000 blade PC running Microsoft Windows XP SP2 w HPSAM blade service installed e HP bc1500 blade PC running Microsoft Windows XP SP2 w HPSAM blade service installed Clients e HP Compaq t5000 series thin client running Microsoft Windows XPe w HPSAM blade ser vice installed e HP Compaq t5000 series thin client running Microsoft Windows CE w HPSAM blade ser vice installed e HP desktop PC running Microsoft Windows XP w HPSAM blade service installed Smart Card Readers e HP standard USB Smart Card Keyboard Driver HPKBCCID sys version 4 28 0 1 e USB CAC approved smart card reader SCM Microsystems SCR331 Reader Driver SCR33X2K sys version 4 27 00 01 Serial CAC approved smart card reader SCM Microsystems SCR131 Reader e USB Combo Fingerprint amp Smart Card reader SCM Microsystems SPR337 Driver spr337 sys version 1 16 00 01 ActivCard middleware e ActivCard ActivClient v5 4 e ActivCard Gold v2 2 Contiguration compatibility HP has tested the following configurations using ActivCard ActivClient v5 4 ActivCard Gold v2 2 and confirmed that the configurations work in a CCI environment USB Reader SCM Serial Reader SCM Microsystems Microsystems HP USB Smart Card SCM Microsystems SCR131 Serial SPR337 USB Combo Keyboard SCR331 USB Reader Reader Reader HP Thin Client w XPe X X X X
16. op Connection 1 Power on the thin client with the smart card reader installed 2 Open Device Manager to verify that the drivers for the card reader are installed a Click Start b Right click on My Computer and select Manage c In the lett pane select Device Manager invent 11 d In the right pane expand Smart card readers C Computer Management File Action T EE Help i IE ajx e gt Amea g a ZZKW3RGYE7Y TE p y mi Computer Management fLocal z System Tools ig Computer n Event viewer Seo Disk drives Et Shared Folders a Display adapters Local Users and Groups Sg Human Interface Devices Device Manager E IDE ATAATAPI controllers Storage H keyboards FEA Services and Applications ia Mice and other pointing devices Monitors Eg Network adapters Ports COM amp LPT 4 Si Processors Eg Ramdisk Eg Ramdrive a Smart card readers aa HF USB Smartcard Keyboard 2 Sound video and game controllers l Storage volumes System devices l Universal Serial Bus controllers mee e fe Pe nesses e Select the installed smart card reader f Under Device status verity the message This device is working properly 3 To begin the enrollment from the blade PC side open the Remote Desktop Connection window by clicking Start gt All Programs gt Accessories gt Communications A Select the Local Resources tab O invent 12
17. quiring any user input Prompt the user during enrollment Prompt the user during enrollment and require user input when the private key is used To choose which cryptographic service providers CSP CSPs should be used click COP ed a e ao N Select or type 1024 in the Minimum key size box Click the CSPs button Select Requests can use any CSP available on subject s computer Click the Security tab O invent 10 In the Permissions for Authenticated Users box in the Allow column select Read and Enroll Properties of New Template z HE 3 x General Request Handling Subject Hame lssuance Requirements Superseded Templates Extensions Security Group dr user names f Administrator PEDOMAINO Administratar EEI Authenticated Users e Domain Admins PEDO MAINOS Domain Admins 8 Enterprise Admins PEDOMAINOSE nterprise Admins Add Remove Permissions for Authenticated Users Allow Deny Full Control LC O Read O Write QO C Enroll imi O Autoenroall CI CI For special permissions or for advanced settings Advanced click Advanced You have completed creation of the template 11 Copy the CCI Smartcard Logon certificate template into the Certificate Templates folder under the cer tificate server a Expand the Certification Authority object in the MMC you created in step 1 b Expand your CA name c Right click on the Certificate Templates folder under th
18. readers m Computer Management Biles Bl File Action View Window Help lel e ama a j i Compier rere local z m y System Tools fal Event Viewer gJ Shared Folders My Local Users and Groups a Device Manager ig Human Interfaze Devices E IDE ATAJATAPI controllers 3 gt Keyboards TS Mice and other pointing devices Monitors B Network adapters Ports COM amp LPT Processors ag Storage he Services and Applications 72 eo amp amp amp amp Ue AD Sonal cord readers AD HP USB Smartcard Keyboard Sound video end game controllers Ha Storage volumes System devices Universal Seria Bus controllers e Select the installed smart card reader f Under Device status verify the message This device is working properly clicking Start gt All Programs gt Hewlett Packard 4 Click Options Select the Miscellaneous tab and verity the Smart Cards box is selected To begin the enrollment from the blade PC side open the HP PC Session Allocation Client window by O invent 14 6 Connect to the blade PC on which you will set up the smart card and then log in as a domain authenticated user HP SAM Client O PC Session Allocation Client Yy 2006 Hewlett Packard Development Company LP SAM Server Server ye User name Smith Domain Domain Display Audio Miscellaneous Make the Following local devices avail
19. ss warranty statements accompanying such products and services Nothing herein should be construed as constituting an additional warranty HP shall not be liable for technical or editorial errors or omissions contained herein Microsoft MS DOS Windows and Windows NT are trademarks of Microsoft Corporation in the U S and other countries 40953 1 002 4 2006 O invent 24
20. ssages click OK The LED on the card reader indicates when the Web site is accessing the smart card to verify whether the certificate is approved for the site 6 After the secure Web site displays a lock icon in the lower right corner of Internet Explorer confirms that you are connected to a secure Web site 3 4 Local intranet Usage case 4 User authentication using VPN through firewall to blade PC Instructions for installing and configuring a VPN tunnel with a firewall is beyond the scope of this white paper therefore the white paper assumes the VPN tunnel and firewall are already installed and func tional The white paper also assumes that you have a broadband Internet connection and that ActivCard middleware is installed on the client 1 In the Control Panel on the client computer open Network and Internet Connections 2 Select the Create a connection to the network at your workplace task E Network and Internet Connections EIB File Edit View Favorites Tools Help ar Back gt a P Search H Folders 555 S5 Folder Sync Address G Network and Internet Connections ia ao See Al A m Network and Internet Connections ee Also lt My Network Places ee sieve and Other Pick Fs task ardiware GQ Remote Desktop ka Phor avaan Set up or change your Internet connection one and Modem Options gt Create a connection to the network at your workplace Troubleshooters i gt Set up or ch
21. ssion GCA Exchange Fe CCl Smartcard Logon Client Authentication Private Kep Archival CEP Encryption Certificate Request Agent Code Signing Code Signing Cross Certification Authority lt All gt Certificate Request Agent Certificate Request Agent Certificate Request Agent 3A Enrollment Agent Enrollment Agent Computer Exchange Enrollment Agent Offline request Exchange Signature Only RAF uchanne leer Secure Email Secure F mail Smart Card Logon Client Authentication Step 2 Group policy setting Apply the following smart card group policy settings to the computer through a user policy setting or through a computer policy setting e Computer Configuration Windows Settings Security Settings Local Policies Security Options Inter active Logon Require smart card enable or disable The default is disabled e Computer Configuration Windows Settings Security Settings Local Policies Security Options Inter active Logon Smart card removal behavior no action or lock workstation or force logoff The default is no action cciusers Properties mi ajx General Managed By COM Group Policy To improve Group Policy management upgrade to the Group Policy Management Console GPM Si Curent Group Policy Object Links for cciusers Group Policy Object Links Ho Override Disabled F SmartCard login Group Policy Objects higher in the list hawe the highest priority This list obtained from
22. vent This white paper discusses the implementation of ActivCard smart cards on HP Consolidated Client Infrastructure CCI This white paper is not intended as a comprehensive overview of ActivCard smart card technology NOTE The images and instructions in this white paper use Microsoft Windows XPe however HP also tested procedures using Microsoft XP Professional and Microsoft Windows CE NET NOTE The images in this white paper were created using ActivClient For information about ActivCard Gold see the ActivCard Gold user guide Introduction Smart cards can provide additional security to a CCI implementation This paper describes a smart card reference implementation that you can use in a dynamic or a static CCI environment Prerequisites This white paper assumes that the reader is familiar with CCl and has a working knowledge of Microsoft Group Policies Microsoft Certificate Authentication CA and setting up smart card readers and middle ware Reference hardware and software The following list provides the reference hardware and software used to validate the CCI product with a smart card e Load Balancer e HP Server running F5 networks BigIP version 4 6 4 or e HP Server running HP Session Allocation Manager version 1 0 e Primary Domain Controller e HP server running Microsoft Windows Enterprise 2003 Server SP1 Configured as DNS DHCP IIS CA and secure Web site server e VPN Tunnel e Altiris Deploy
23. y 2 In the right pane select the My Certificates icon The system displays the username ID ActivCard ActivGlient HP Modular USB Smartcard Keyboar Sime Ele Edit Wew Tools Help Smart Card Tasks E 4 Change my smart card PIN Smart Card Inf E Show my smart card info G My Certificates Tasks re View my certificates A Import a certificate Help Tasks __ l Get help on using this software ay Troubleshoot a problern L Ready Double click to view the list of certif 3 Select the username ID to view the installed certificate which shows e who it was issued to e who it was issued by e valid dates O invent 18 Usage cases Usage case 1 User authentication trom client device to blade PC using RDP The following steps provides instructions for performing a functional test of the CCI SmartCard Logon cer tificate 1 Log out of the RDP session 2 Open the Remote Desktop Communications window and initiate a connection to the blade 3 Make sure a smart card is installed in the reader The system requests the smart card PIN Loe On to Windows Copright E 2985 2001 Maomsoft Cormoration 4 Type the PIN that you assigned The user is logged into the blade Usage case 2 User authentication from client device to blade PC using HPSAM client The following steps provide instructions for performing a functional test of the CCI SmartCard Logon certif icate 1 Log out of the RDP session
Download Pdf Manuals
Related Search
Related Contents
ONCYTE® Guide to Protein Microarrays - Grace Bio Alpine TEC104 Instructions / Assembly U-Line Refrigerator U-3018WCOL-00 User's Manual AirLive POE-1P Kenroy Home HDP11962 Installation Guide Visonic español Porti 8 user manual Etiquette produit GBD T120 Copyright © All rights reserved.
Failed to retrieve file