Lenovo ThinkVantage (Client Security Solution 8.21) Manual do Utilizador

Consulte online ou descarregue Manual do Utilizador para Software Lenovo ThinkVantage (Client Security Solution 8.21). Lenovo ThinkVantage (Client Security Solution 8.21) User Manual Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 86
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 0
ClientSecuritySolution8.21
DeploymentGuide
Updated:February,2012
Vista de página 0
1 2 3 4 5 6 ... 85 86

Resumo do Conteúdo

Página 1 - DeploymentGuide

ClientSecuritySolution8.21DeploymentGuideUpdated:February,2012

Página 2 - “Notices”onpage75

youcreate.Createthissecureenvironmentassoonaspossible,beforeapasswordisforgotten.Youcannotresetaforgottenhardwarepassworduntilthissecureenvironmentisc

Página 3 - Contents

Chapter2.InstallationThischaptercontainsinstructionsforinstallingClientSecuritySolution,andFingerprintSoftware.BeforeinstallingClientSecuritySolutiono

Página 4

CustompublicpropertiesTheinstallationpackagefortheClientSecuritySoftwareprogramcontainsasetofcustompublicpropertiesthatcanbesetonthecommandlinewhenrun

Página 5 - ©CopyrightLenovo2008,2012

Afterownershipofthesystemiscongured,eachadditionalWindowsuserthatlogsintothesystemisautomaticallypromptedwiththeClientSecuritysSetupwizardinordertoen

Página 6

customizationsaremade,theusercallsmsiexec.exefromthecommandline,passingthenameoftheunpackedMSIle.Thefollowingparametersanddescriptionsaredocumentedin

Página 7 - Chapter1.Overview

Table3.CommandlineparametersParameterDescription/IpackageorproductcodeUsethisformattoinstalltheproduct:Othello:msiexec/i"C:\WindowsFolder\Proles

Página 8 - ClientSecurityPasswordManager

Table3.Commandlineparameters(continued)ParameterDescriptionYoucanseparatemultipletransformswithasemicolon.Donotusesemicolonsinthenameofyourtransform,a

Página 9 - Hardwarepasswordreset

Table4.WindowsInstallerproperties(continued)PropertyDescriptionARPSYSTEMCOMPONENTPreventsdisplayofapplicationintheAddorRemoveProgramslist.ARPURLINFOAB

Página 10 - FingerprintSoftware

Table6.InstallationexamplesusingClientSecurity-PasswordManager.msiDescriptionExampleInstallationmsiexec/i“C:\CSS82\ClientSecuritySolution-PasswordMana

Página 11 - Chapter2.Installation

Table7.OptionssupportedbytheFingerprintSoftwareParameterDescriptionCTRLONCEDisplaystheControlCenteronlyonce.Thedefaultvalueis0.CTLCNTRRunstheControlCe

Página 12 - TrustedPlatformModulesupport

Note:Beforeusingthisinformationandtheproductitsupports,readthegeneralinformationinAppendixD“Notices”onpage75.ThirdEdition(February2012)©CopyrightLenov

Página 13 - Chapter2.Installation7

Table8.OptionssupportedbytheLenovoFingerprintSoftwareParameterDescriptionSWAUTOSTART•0=willnotstartngerprintsoftwareonWindowsstartup.•1=willstartnge

Página 14 - Usingmsiexec.exe

Table8.OptionssupportedbytheLenovoFingerprintSoftware(continued)ParameterDescriptionSWANTIHAMMERRETRIESSpeciesthemaximumretries.Thedefaultvalueis5.No

Página 15 - .Installation9

16ClientSecuritySolution8.21DeploymentGuide

Página 16

Chapter3.WorkingwithClientSecuritySolutionBeforeyouinstallClientSecuritySolution,youshouldunderstandthecustomizationavailableforClientSecuritySolution

Página 17 - Installationlogles

enrolledasanactiveuser.EveryotheruserthatlogsintothesystemwillbeautomaticallyrequestedtoenrollintoClientSecuritySolution.•TakeOwnershipAsingleWindowsa

Página 18 - Silentinstallation

ThefollowingdiagramprovidesthestructurefortheSystemLevelKey:System Level Key Structure - Take OwnershipTrusted Platform ModuleEncrypted via derived AE

Página 19

Thefollowingdiagramprovidesthestructurefortheuserlevelkey:User Level Key Structure - Enroll UserTrusted Platform ModuleEncrypted via derived AES KeySt

Página 20

TheTPMemulationmodecannotbeusedasasecuresubstitutefortheTPM.TheTPMprovidesthefollowingtwokeyprotectionmethodsthataremoresecurethantheTPMemulationmode.

Página 21 - SystemsManagementServer

Thefollowingdiagramprovidesthestructureforthemotherboardswap-takeownership:Motherboard Swap - Take OwnershipTrusted Platform ModuleDecrypted via deriv

Página 22

EFSprotectionutilityClientSecuritySolutionprovidesacommandlineutilitythatenablesTPM-basedprotectionofencryptioncerticatesusedbytheEncryptingFileSyste

Página 23 - UsingtheTrustedPlatformModule

ContentsPreface...iiiChapter1.Overview...1ClientSecuritySolution...1ClientSecuritySolutionpassphrase...2ClientSecurity

Página 24 - TakeOwnership

UsingtheXMLSchemaThepurposeoftheXMLscriptingistoenableITadministratorstocreatecustomscriptsthatcanbeusedtodeployandcongureClientSecuritySolution.Thes

Página 25 - EnrollUser

<SYSTEM_PAP>password</SYSTEM_PAP></FUNCTION></CSSFile>Note:Thiscommandisnotsupportedintheemulationmode.ENABLE_PWMGR_FUNCTIONTh

Página 26 - Softwareemulation

ThefollowingcommandenablesthelogonwiththefastuserswitchingsupportanddisablestheClientSecuritySolutionWindowslogon.Thefastuserswitchingmightnotbeenable

Página 27 - Systemboardswap

ENABLE_NONE_GINA_FUNCTIONIfoneofGINArelatedTVTcomponentssuchasThinkVantageFingerprintSoftware,ClientSecuritySolution,orAccessConnectionlogonisenabled,

Página 28

Note:Thiscommandisnotsupportedintheemulationmode.INITIALIZE_SYSTEM_FUNCTIONThiscommandinitializestheClientSecuritySolutionsystemfunction.Thesystem-wid

Página 29 - EFSprotectionutility

Note:Thiscommandisnotsupportedintheemulationmode.ENROLL_USER_FUNCTIONThiscommandenrollsaparticularusertouseClientSecuritySolution.Thisfunctioncreatesa

Página 30 - Examples

<DOMAIN_NAME_PARAMETER>IBM-2AA92582C79<DOMAIN_NAME_PARAMETER><USER_PW_REC_ANSWER_DATA_PARAMETER>Test1</USER_PW_REC_ANSWER_DATA_PA

Página 31 - ENABLE_UPEK_GINA_FUNCTION

UsingRSASecurIDtokensLeveringtheencryptionalgorithmmethodofencryptingdata,usingRSASecurIDtokensinadditiontoClientSecuritySolutionwillprovideyourenterp

Página 32

ToleveragethePKCS#11moduleofClientSecuritySolution,thefollowingpoliciesmustbesetforActiveDirectory:1.PKCS#11Signature2.PKCS#11DecryptionThefollowingta

Página 33 - SET_ADMIN_USER_FUNCTION

•“SecurityAdvisor”onpage33•“ClientSecuritySolutionsetupwizard”onpage34•“Deploymentleencryptordecrypttool”onpage34•“Deploymentleprocessingtool”onpage

Página 34 - INITIALIZE_SYSTEM_FUNCTION

DeploymentexamplesforinstallingClientSecuritySolution...55Scenario1...55Scenario2...57SwitchingClientSecuritySolut

Página 35 - USER_PW_RECOVERY_FUNCTION

Table11.Parameters(continued)ParametersDescriptionFileSharingSetsthevalueforthelesharing.1willshowthissection,0willhide.Ifnotpresentthenitisshownbyde

Página 36 - SET_USER_AUTH_FUNCTION

Table13.ParametersforencryptingordecryptingClientSecurityXMLdeploymentlesParametersResults/hor/?DisplaysthehelpmessageFILENAMEDisplayspathnameandlen

Página 37

Table16.css_cert_transfer_tool.exe<cert_store_type><lter_type>:<name|size>|all_access|usageParameterDescription<cert_store_type&

Página 38 - Command-linetools

Table17.ParametersforactivatingordeactivatingtheTPMontheLenovosystem(continued)ParameterDescription/deactivateDeactivatestheTPM.Note:Ifyouruntpm_activ

Página 39 - SecurityAdvisor

•DefaultuserpreferencesAsdescribedpreviously,computeranduserpoliciesaredenedbytheadministrator.ThesesettingscanbeinitializedthroughtheXMLconguration

Página 40

Table19.ComputerConguration➙Administrativetemplates➙ThinkVantage➙ClientSecuritySolution➙Authenticationpolicies➙SecuremodePolicyEnabledsettingsDescrip

Página 41 - CerticateTransfertool

Table21.ComputerConguration➙Administrativetemplates➙ThinkVantage➙ClientSecuritySolution➙AuthenticationpoliciesPolicyEnabledsettingsDescriptionPasswor

Página 42 - TPMactivatetool

Table23.ComputerConguration➙ThinkVantage➙ClientSecuritySolution➙UserinterfacePolicysettingDescriptionFingerprintsoftwareoptionShow,grayorhidetheFinge

Página 43 - ActiveDirectorySupport

Table24.ComputerConguration➙ThinkVantage➙ClientSecuritySolution➙Workstationsecuritytool(continued)PolicySettingDescriptionWindowsUsersPasswordsPasswo

Página 44 - GroupPolicysettings

ActiveUpdateParameterFileTheActiveUpdateparameterlecontainsthesettingstobepassedtoActiveUpdate.TheTargetAppparameterispassedasshowninthisexample:<

Página 45 - AuthenticationPolicies

PrefaceThisguideisintendedforITadministrators,orthoseresponsiblefordeployingThinkVantage®ClientSecuritySolutionandThinkVantageFingerprintSoftwaretocom

Página 46 - UserInterface

44ClientSecuritySolution8.21DeploymentGuide

Página 47 - Workstationsecuritytool

Chapter4.WorkingwithThinkVantageFingerprintSoftwareThengerprintconsolemustberunfromtheFingerprintSoftwareinstallationfolder.ThebasicsyntaxisFPRCONSOL

Página 48 - ActiveUpdate

Table25.User-speciccommands(continued)CommandSyntaxDescriptionExportenrolledusertoaleSyntax:EXPORTusername[|domain\username]leThiscommandwillexport

Página 49 - ActiveUpdateParameterFile

SecuremodeandconvenientmodeFingerprintSoftwarecanberunintwosecuritymodes,asecuremodeandaconvenientmode.Thesecuremodeisintendedforsituationswhenyouwant

Página 50

Table28.Optionsforlimitedusersinthesecuremode(continued)SettingDescriptionDeletePassportLimitedusercandeleteonlytheirownpassport.Power-onSecurityLimit

Página 51 - User-speciccommands

Table30.Optionsforlimitedusersintheconvenientmode(continued)SettingsDescriptionSecuritymodeLimiteduserscannotmodifysecuritymodes.ProServersLimiteduser

Página 52 - Globalsettingscommands

Thengerprintsoftwarewillcontinuetovalidatethepasswordatsystemlogon.Note:Whentheaboveregistrykeyissetto1,ifthedomainadministratorchangestheuser's

Página 53 - Securemode-limiteduser

9.Reboot.Note:YourauthenticationIDandpasswordforWindowsandNovellmustbeidentical.ThinkVantageFingerprintSoftwareserviceTheupeksvr.exeserviceisaddedtoth

Página 54 - Convenientmode-limiteduser

52ClientSecuritySolution8.21DeploymentGuide

Página 55 - Congurablesettings

Chapter5.WorkingwithLenovoFingerprintSoftwareThengerprintconsolemustberunfromtheLenovoFingerprintSoftwareinstallationfolder.ThebasicsyntaxisFPRCONSOL

Página 56 - Authenticating

ivClientSecuritySolution8.21DeploymentGuide

Página 57

Table31.Policysettings(continued)SettingDescriptionAlwaysshowpower-onsecurityoptionsIfyouenablethissetting,userswillbeabletoselectusingtheFingerprintR

Página 58

Chapter6.BestPracticesThischapterpresentsscenariostoillustratethebestpracticesofClientSecuritySolutionandFingerprintSoftware.Thisscenariostartswiththe

Página 59

•TypetheClientSecuritypassphrase(forexample,CSPP4Admin)fortheadministratoraccount,checktheUsetheClientSecuritypassphrasetoprotectaccesstotheRescueandR

Página 60

*******************************************************Readytotakesysprepbackup.********PLEASERUNSYSPREPNOWANDSHUTDOWN.********Nexttimethemachineboots

Página 61 - Chapter6.BestPractices

4.InstallThinkVantageFingerprinttutorialbyrunningthef001zpz7001us00.exetoextractthetutess.exelefromtheWebpackage.Thiswillautomaticallyextractthesetup

Página 62 - “NOCSSWIZARD=1””

5.Afterrebootingthesystem,congurethesystemwiththeXMLscriptlethroughthefollowingprocedure:•CopytheThinkPad.xml.enclepreparedearlytotheC:\directory.•

Página 63 - Scenario2

2.Overinstallallthreedifferentversionsofoldersoftware(RescueandRecovery1.0/2.0/3.0,Fingerprint,ClientSecuritySolution5.4–6,FFE).Settingsshouldbekeptwh

Página 64

1.OpenCerticationAuthority.2.Intheconsoletree,clickCerticateT emplates.3.FromtheActionmenu,clickNew➙CerticatetoIssue.4.ClickTPMandclickOK.Applyingc

Página 65 - SystemUpdate

4.UsetheThinkVantagengerprintsoftwaretoenrollyourngerprintswiththeexternalngerprintsensor.Ifitdoesnotautomaticallystart,clickStart➙Programs➙ThinkVa

Página 66 - Requirements:

11.ClickStart➙Programs➙ThinkVantage➙ThinkVantageFingerprintSoftwaretostarttheenrollment.12.ClickFingerprints➙EnrollorEditFingerprints,andthenclickNext

Página 67 - WindowsVistalogon

Chapter1.OverviewThischapterprovidesanoverviewofClientSecuritySolutionandFingerprintSoftware.Thetechnologiespresentedinthisdeploymentguidecandirectlya

Página 68 - WindowsXPlogon

ClientSecuritySolutionandPasswordManagerDifferentfromWindowslogon,authenticationrequestsfromClientSecuritySolutionandPasswordManageronlyworkontheprefe

Página 69 - Chapter6.BestPractices63

Note:IfthesettingPower-onSecurityisnotavailable,createaregistryentryasfollowstodisplaythissetting:[HKEY_LOCAL_MACHINE\SOFTWARE\ProtectorSuiteQL\1.0]RE

Página 70

66ClientSecuritySolution8.21DeploymentGuide

Página 71 - Chapter6.BestPractices65

AppendixA.ConsiderationswhenusingOmniPassOmniPassfromSoftex©isaprogramthatcanbeusedtosecurelylogintoWebsitesandapplications,aswellasprotectdataonacomp

Página 72

Table33.Omnipassfeatureoverlap(continued)FunctionFeatureoverlapConsiderationsUserauthenticationBothClientSecuritySolutionandOmniPassmaypromptforuserau

Página 73

AppendixB.SpecialconsiderationsforusingtheLenovoFingerprintKeyboardwithsomeThinkPadnotebookmodelsThengerprintdeviceusedinsomeThinkPadnotebookmodelsis

Página 74

WindowsXP-WelcomeScreenTosupportloggingonwitheithertheLenovoFingerprintKeyboardorthebuilt-inThinkPadngerprintsensorwiththeWindowsXPWelcomeScreen,thel

Página 75 - Windowslogon

2.TheWindowsVistalogonscreenmayonlyshowone“tile,orbutton,forngerprintlogon,althougheitherngerprintsensorcanbeusedtologon.Alternatively,tosupportlogo

Página 76 - WindowsVista

72ClientSecuritySolution8.21DeploymentGuide

Página 77

AppendixC.SynchronizingpasswordinCSSaftertheWindowspasswordisresetAftertheWindowspasswordisreset,ClientSecuritySolutioncontinuallypromptsyouforanewWin

Página 78

ClientSecuritySolutionpassphraseTheClientSecuritySolutionpassphraseisanoptionalfeatureofuserauthenticationthatwillprovideenhancedsecuritytoClientSecur

Página 79 - Windowspasswordisreset

74ClientSecuritySolution8.21DeploymentGuide

Página 80

AppendixD.NoticesLenovomaynotoffertheproducts,services,orfeaturesdiscussedinthisdocumentinallcountries.ConsultyourlocalLenovorepresentativeforinformat

Página 81 - AppendixD.Notices

TrademarksThefollowingtermsaretrademarksofLenovointheUnitedStates,othercountries,orboth:LenovoRescueandRecoveryThinkCentreThinkPadThinkVantageMicrosof

Página 82 - Trademarks

GlossaryAdministrator(ThinkCentre)/Supervisor(ThinkPad)BIOSPasswordTheadministratororsupervisorpasswordisusedtocontroltheabilitytochangeBIOSsettings.T

Página 83 - Glossary

Symmetric-keyencryptionSymmetrickeyencryptionciphersusethesamekeyforencryptionanddecryptionofdata.Symmetrickeyciphersaresimplerandfaster,buttheirmaind

Página 86

•AutolluserIDsandpasswords:Automatesyourloginprocesswhenyouaccessanapplicationorwebsite.IfyourlogoninformationhasbeenenteredintoClientSecurityPasswor

Comentários a estes Manuais

Sem comentários