Lenovo ThinkVantage Client Security Solution 8.3 Uživatelský manuál Strana 1

Procházejte online nebo si stáhněte Uživatelský manuál pro Software Lenovo ThinkVantage Client Security Solution 8.3. Lenovo ThinkVantage Client Security Solution 8.3 User Manual Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 86
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 0
ClientSecuritySolution8.3
DeploymentGuide
Updated:December,2011
Zobrazit stránku 0
1 2 3 4 5 6 ... 85 86

Shrnutí obsahu

Strany 1 - DeploymentGuide

ClientSecuritySolution8.3DeploymentGuideUpdated:December,2011

Strany 2 - “Notices”onpage75

consistentandsecureenvironment.Thesystemsthathavetheembeddedsecuritychiparemorerobustagainstanattack;however,forthesystemswithouttheembeddedsecuritych

Strany 3 - Contents

Chapter2.InstallationThischaptercontainsinstructionsforinstallingClientSecuritySolution,andFingerprintSoftware.BeforeinstallingClientSecuritySolutiono

Strany 4

Table1.PublicpropertiesPropertyDescriptionEMULATIONMODESpecifytoforcetheinstallationinEmulationmodeevenifaTPMexists.SetEMULATIONMODE=1onthecommandline

Strany 5 - ©CopyrightLenovo2008,2011

SoftwareemulationoftheTrustedPlatformModuleClientSecuritySolutionhastheoptiontorunwithoutaTrustedPlatformModuleonqualiedsystems.Thefunctionalitywillb

Strany 6

ThefollowingparametersanddescriptionsaredocumentedintheInstallShielddeveloperhelpdocumentation.ParametersthatdonotapplytoBasicMSIprojectswereremoved.T

Strany 7 - Chapter1.Overview

Table3.CommandlineparametersParameterDescription/IpackageorproductcodeUsethisformattoinstalltheproduct:Othello:msiexec/i"C:\WindowsFolder\Proles

Strany 8 - ClientSecurityPasswordManager

Table3.Commandlineparameters(continued)ParameterDescriptionYoucanseparatemultipletransformswithasemicolon.Donotusesemicolonsinthenameofyourtransform,a

Strany 9 - Hardwarepasswordreset

Table4.WindowsInstallerproperties(continued)PropertyDescriptionARPSYSTEMCOMPONENTPreventsdisplayofapplicationintheAddorRemoveProgramslist.ARPURLINFOAB

Strany 10 - FingerprintSoftware

InstallingThinkVantageFingerprintSoftwareThesetup.exeleoftheThinkVantageFingerprintSoftwareprogramcanbeinstalledthroughthefollowingmethods:Silentinst

Strany 11 - Chapter2.Installation

Table7.OptionssupportedbytheThinkVantageFingerprintSoftware(continued)ParameterDescriptionPASSPORTSetthedefaultpassporttype.•1=Localpassport•2=Serverp

Strany 12 - TrustedPlatformModulesupport

Note:Beforeusingthisinformationandtheproductitsupports,readthegeneralinformationinAppendixE“Notices”onpage75.FourthEdition(December2011)©CopyrightLeno

Strany 13 - Chapter2.Installation7

Table7.OptionssupportedbytheThinkVantageFingerprintSoftware(continued)ParameterDescriptionLOCKOUT•1=Enabletheanti-hammeringprotection.•0=Disabletheant

Strany 14 - Usingmsiexec.exe

SilentinstallationTosilentlyinstalltheFingerprintSoftware,runthesetup32.exelelocatedintheinstallationdirectoryonyourCD-ROMdrive.Usethefollowingsyntax

Strany 15 - .Installation9

Table8.OptionssupportedbytheLenovoFingerprintSoftware(continued)ParameterDescriptionSWALLOWIMEXPORT•0=Disablethengerprintimport/exportfornon-administ

Strany 16

SystemsManagementServerSystemsmanagementserver(SMS)installationsarealsosupported.OpentheSMSadministratorconsole.Createanewpackageandsetpackageproperti

Strany 17 - Installationlogle

18ClientSecuritySolution8.3DeploymentGuide

Strany 18 - Silentinstallation

Chapter3.WorkingwithClientSecuritySolutionBeforeyouinstallClientSecuritySolution,youshouldunderstandthecustomizationavailableforClientSecuritySolution

Strany 19 - .Installation13

enrolledasanactiveuser.EveryotheruserthatlogsintothesystemwillbeautomaticallyrequestedtoenrollintoClientSecuritySolution.•TakeOwnershipAsingleWindowsa

Strany 20

ThefollowingdiagramprovidesthestructurefortheSystemLevelKey:System Level Key Structure - Take OwnershipTrusted Platform ModuleEncrypted via derived AE

Strany 21

Thefollowingdiagramprovidesthestructurefortheuserlevelkey:User Level Key Structure - Enroll UserTrusted Platform ModuleEncrypted via derived AES KeySt

Strany 22

TheTPMemulationmodecannotbeusedasasecuresubstitutefortheTPM.TheTPMprovidesthefollowingtwokeyprotectionmethodsthataremoresecurethantheTPMemulationmode.

Strany 23 - SystemsManagementServer

ContentsPreface...iiiChapter1.Overview...1ClientSecuritySolution...1ClientSecuritySolutionpassphrase...2ClientSecurity

Strany 24

Thefollowingdiagramprovidesthestructureforthemotherboardswap-takeownership:Motherboard Swap - Take OwnershipTrusted Platform ModuleDecrypted via deriv

Strany 25 - UsingtheTrustedPlatformModule

EFSprotectionutilityClientSecuritySolutionprovidesacommandlineutilitythatenablesTPM-basedprotectionofencryptioncerticatesusedbytheEncryptingFileSyste

Strany 26 - TakeOwnership

Whenruninsilentmode,theoutputoftheprogramwillbeanerrorlevelcorrespondingtotheerrorsnumbersshownabove.UsingtheXMLSchemaThepurposeoftheXMLscriptingistoe

Strany 27 - EnrollUser

<ORDER>0001</ORDER><COMMAND>DISABLE_TPM_FUNCTION</COMMAND><VERSION>1.0</VERSION><SYSTEM_PAP>password</SYS

Strany 28 - Softwareemulation

2.Thiscommandisnotsupportedintheemulationmode.ThefollowingcommandenablesthelogonwithfastuserswitchingsupportanddisablestheClientSecuritySolutionWindow

Strany 29 - Systemboardswap

ENABLE_NONE_GINA_FUNCTIONIftheGINAorCP(CredentialProvider)ofoneoftherelatedThinkVantageTechnologiescomponents,suchasThinkVantageFingerprintSoftware,Cl

Strany 30

Note:Thiscommandisnotsupportedintheemulationmode.INITIALIZE_SYSTEM_FUNCTIONThiscommandinitializestheClientSecuritySolutionsystemfunction.Thesystem-wid

Strany 31 - EFSprotectionutility

Note:Thiscommandisnotsupportedintheemulationmode.ENROLL_USER_FUNCTIONThiscommandenrollsaparticularusertouseClientSecuritySolution.Thisfunctioncreatesa

Strany 32 - Examples

<DOMAIN_NAME_PARAMETER>IBM-2AA92582C79<DOMAIN_NAME_PARAMETER><USER_PW_REC_ANSWER_DATA_PARAMETER>Test1</USER_PW_REC_ANSWER_DATA_PA

Strany 33 - ENABLE_UPEK_GINA_FUNCTION

1.GotothefollowingWebsite:http://www.rsasecurity.com/node.asp?id=11562.Completetheregistrationprocess.3.DownloadandinstalltheRSASecurIDSoftware.Requir

Strany 34

Scenario2...59SwitchingClientSecuritySolutionmodes...61CorporateActiveDirectoryrollout...61StandaloneInstallforCDorscriptles...62Sy

Strany 35 - SET_ADMIN_USER_FUNCTION

Table10.ThinkVantage\ClientSecuritySolution\AuthenticationPolicies\PKCS#11Signature\CustomModeFieldsCSS.ADMModiableeldRequiredFieldDescriptionContro

Strany 36 - INITIALIZE_SYSTEM_FUNCTION

•“CerticateTransfertool”onpage37•“ActivatingordeactivatingtheTPM”onpage38SecurityAdvisorTousetheSecurityAdvisorfunction,launchtheClientSecuritySoluti

Strany 37 - USER_PW_RECOVERY_FUNCTION

Table11.Parameters(continued)ParametersDescriptionEmbeddedSecurityChipSetsvaluethatsecuritychipshouldbeenabled,orsettingwillbeagged.ClientSecuritySol

Strany 38 - UsingRSASecurIDtokens

Table13.ParametersforencryptingordecryptingClientSecurityXMLdeploymentles(continued)ParametersResults/encryptor/decryptSelects/encryptforXMLlesand/d

Strany 39 - ActiveDirectorySupport

Table16.css_cert_transfer_tool.exe<cert_store_type><lter_type>:<name|size>|all_access|usageParameterDescription<cert_store_type&

Strany 40 - Command-linetools

Fordesktopcomputers,dothefollowingtoactivatetheTPM:1.GototheWebsiteathttp://support.lenovo.com/en_US/detail.page?LegacyDocID=MIGR-75407.2.ClickVisualB

Strany 41 - SecurityAdvisor

•Disabled•Activated•Deactivated•Owned•Notowned/setstate:<state>setstheTPMstatustypeyouprefer.0representsdisabledanddeactivated.1representsenable

Strany 42

ThefollowingexamplesaresettingsthatActiveDirectorycanmanageforClientSecuritySolution:•Securitypolicies.•Customsecuritypolicies;suchaswhethertouseaWind

Strany 43 - CerticateTransfertool

HKLM\Software\Lenovo\ClientSecuritySolution\Userpreferences:HKCU\Software\Lenovo\ClientSecuritySolution\Defaultuserpreferences:HKLM\Software\Lenovo\Cl

Strany 44

Table20.ComputerConguration➙Administrativetemplates➙ThinkVantage➙ClientSecuritySolution➙Authenticationpolicies➙Defaultmode(continued)PolicyEnabledset

Strany 45

PrefaceInformationpresentedinthisguideistosupportLenovo®computersinstalledwiththeThinkVantage®ClientSecuritySolutionprogramandtheFingerprintSoftwarepr

Strany 46

Table22.ComputerConguration➙ThinkVantage➙ClientSecuritySolution➙Passwordmanager(continued)PolicysettingDescriptionDisableAuto-llControlswhetherPassw

Strany 47 - Deningmanageablesettings

Table23.ComputerConguration➙ThinkVantage➙ClientSecuritySolution➙Userinterface(continued)PolicysettingDescriptionEnable/disableWindowspasswordrecovery

Strany 48 - GroupPolicysettings

Table24.ComputerConguration➙ThinkVantage➙ClientSecuritySolution➙Workstationsecuritytool(continued)PolicySettingDescriptionClientSecurityEmbeddedSecur

Strany 49 - Passwordmanager

Chapter4.WorkingwithThinkVantageFingerprintSoftwareThengerprintconsolemustberunfromtheThinkVantageFingerprintSoftwareinstallationfolder.Thebasicsynta

Strany 50 - UserInterface

Table25.User-speciccommands(continued)CommandSyntaxDescriptionEnumerateenrolledusersListListstheenrolledusers.ExportenrolledusertoaleSyntax:EXPORTus

Strany 51 - Workstationsecuritytool

SecuremodeandconvenientmodeFingerprintSoftwarecanberunintwosecuritymodes,asecuremodeandaconvenientmode.Thesecuremodeisintendedforsituationswhenyouwant

Strany 52

Table28.Optionsforlimitedusersinthesecuremode(continued)SettingDescriptionDeletePassportLimitedusercandeleteonlytheirownpassport.Power-onSecurityLimit

Strany 53 - User-speciccommands

Table30.Optionsforlimitedusersintheconvenientmode(continued)SettingsDescriptionSecuritymodeLimiteduserscannotmodifysecuritymodes.ProServersLimiteduser

Strany 54 - Globalsettingscommands

Thengerprintsoftwarewillcontinuetovalidatethepasswordatsystemlogon.Note:Whentheaboveregistrykeyissetto1,ifthedomainadministratorchangestheuser's

Strany 55 - Securemode-limiteduser

8.LogontoWindows.9.Reboot.Note:YourauthenticationIDandpasswordforWindowsandNovellmustbeidentical.ThinkVantageFingerprintSoftwareserviceTheupeksvr.exes

Strany 56 - Convenientmode-limiteduser

ivClientSecuritySolution8.3DeploymentGuide

Strany 57 - Congurablesettings

54ClientSecuritySolution8.3DeploymentGuide

Strany 58 - Authenticating

Chapter5.WorkingwithLenovoFingerprintSoftwareThengerprintconsolemustberunfromtheLenovoFingerprintSoftwareinstallationfolder.ThebasicsyntaxisFPRCONSOL

Strany 59

Table31.Policysettings(continued)SettingDescriptionadministratorswillonlybeabletologinusingngerprints.Allowusertoretrievepasswordthroughngerprintaut

Strany 60

Chapter6.BestPracticesThischapterpresentsscenariostoillustratethebestpracticesofClientSecuritySolutionandFingerprintSoftware.Thisscenariostartswiththe

Strany 61

3)TypetheClientSecuritypassphrase(forexample,CSPP4Admin)fortheadministratoraccount,selecttheUsetheClientSecuritypassphrasetoprotectaccesstotheRescuean

Strany 62

*******************************************************Readytotakesysprepbackup.********PLEASERUNSYSPREPNOWANDSHUTDOWN.********Nexttimethemachineboots

Strany 63 - Chapter6.BestPractices

b.Double-clicktheextractedsetup.exeleandfollowtheinstructionsonthescreentoinstalltheThinkVantageFingerprintSoftware.4.InstalltheThinkVantageFingerpri

Strany 64

3.InstalltheThinkVantageFingerprintconsoleonthedeploymentmachinebydoingthefollowing:a.Deploythefprconsole.exelethathasbeenextractedfromthepreparation

Strany 65 - Scenario2

c.ThroughActiveDirectory,enableAntidoteDeliveryManager.Placepackagestoberunandmakesurereportingiscaptured.StandaloneInstallforCDorscriptlesForastanda

Strany 66

3.FromtheFilemenu,clickAdd/RemoveSnap-in,andthenclickAdd.TheAddStandalonesnap-inwindowdisplays.4.Double-clickCerticationAuthorityinthesnap-inlist,and

Strany 67 - Chapter6.BestPractices61

Chapter1.OverviewThischapterprovidesanoverviewofClientSecuritySolutionandFingerprintSoftware.Thetechnologiespresentedinthisdeploymentguidecandirectlya

Strany 68 - CreatingtemplateforTPMuser

ThissectiondescribesthecommonusagescenariosanddeploymentstrategiesforngerprintsoftwarethatisinstalledonthelatestThinkPadnotebookcomputermodels.Note:•

Strany 69 - Chapter6.BestPractices63

Table32.RegistrykeysNameValueDescription0(default)Speciesthattheexternalngerprintsensorispreferredwheneverthengerprintkeyboardisconnected.PreferInt

Strany 70 - Windows7logon

66ClientSecuritySolution8.3DeploymentGuide

Strany 71 - Chapter6.BestPractices65

AppendixA.SpecialconsiderationsforusingtheLenovoFingerprintKeyboardwithsomeThinkPadnotebookmodelsThengerprintdeviceusedinsomeThinkPadnotebookmodelsis

Strany 72

•UsingtheFingerprintSoftwarelogoninterfaceThelogoninterfacesofbothLenovoFingerprintSoftwareandThinkVantageFingerprintSoftwaremustbeenabled.Whenbothng

Strany 73 - Windowslogon

AppendixB.SynchronizingpasswordinClientSecuritySolutionaftertheWindowspasswordisresetAftertheWindowspasswordisreset,ClientSecuritySolutioncontinuallyp

Strany 74

70ClientSecuritySolution8.3DeploymentGuide

Strany 75

AppendixC.UsingClientSecuritySolutiononareinstalledWindowsoperatingsystemIfyourWindowsoperatingsysteminstalledwithClientSecuritySolutionhasbeenreinsta

Strany 76

72ClientSecuritySolution8.3DeploymentGuide

Strany 77 - Windowsoperatingsystem

AppendixD.UsingtheTPMonThinkPadnotebookcomputersThemainusecasefortheTPMistheBitLockerfeaturethatisincludedwithcertainversionsoftheMicrosoftWindowsVist

Strany 78

ClientSecuritySolutionpassphraseTheClientSecuritySolutionpassphraseisanoptionalfeatureofuserauthenticationthatwillprovideenhancedsecuritytoClientSecur

Strany 79 - HowdoesTPMlockoutwork?

•Atmel-ThinkPadT60/R60/X60/X300,ThinkCentreM57•Intel-ThinkPadT500/R500/X200/X301•STMicro-ThinkPadT410/T510/X201/T420/T520/X220,ThinkCentreM90•Winbond-

Strany 80

AppendixE.NoticesLenovomaynotoffertheproducts,services,orfeaturesdiscussedinthisdocumentinallcountries.ConsultyourlocalLenovorepresentativeforinformat

Strany 81 - AppendixE.Notices

TrademarksThefollowingtermsaretrademarksofLenovointheUnitedStates,othercountries,orboth:LenovoThinkCentreThinkPadThinkVantageMicrosoft,InternetExplore

Strany 82 - Trademarks

GlossaryAdministrator(ThinkCentre)/Supervisor(ThinkPad)BIOSPasswordTheadministratororsupervisorpasswordisusedtocontroltheabilitytochangeBIOSsettings.T

Strany 83 - Glossary

Symmetric-keyencryptionSymmetrickeyencryptionciphersusethesamekeyforencryptionanddecryptionofdata.Symmetrickeyciphersaresimplerandfaster,buttheirmaind

Strany 85

PartNumber:PrintedinUSA(1P)P/N:**

Strany 86 - (1P)P/N:

entryrelatedchangescanbedetectedautomaticallybyClientSecurityPasswordManagerandallowstheusertoupdatetheirentrieswithevenlesswork.•Saveyourinformationw

Komentáře k této Příručce

Žádné komentáře