HardwarePasswordManagerDeploymentGuideUpdated:July,2010
2HardwarePasswordManagerDeploymentGuide
Chapter2.InstallingHardwarePasswordManageronThinkManagementConsoleTouseHPMfunctionality,theLenovoThinkManagementConsolemustbeinstalled.Asyoucongureth
PreparingthecoreserverTheHPMcoreserverwillusetheThinkManagementConsole9.0thatisbasedonLANDeskManagementSuite9.0.FormoreinformationaboutLANDeskManageme
WhenusingtheWindowsServer2008R2(64-bit)operatingsystem,theMonitoring/Alerts(SNMP)additionalfeaturemustbeinstalledaswell.1.ClickStart➙ServerManager.2.I
3.RuntheThinkManagementConsoleAutorun.exefromthelocationwheretheinstallationpackagewasextractedto.SelectInstallonthecoreserver.FollowthepromptsintheIn
1.IntheThinkManagementconsole,clickTools➙Conguration➙AgentConguration.2.ClickNewontheAgentCongurationtoolbar,andenteranameforthisagentconguration.
Thenameoftheexecutablelewillbebasedonthenameoftheagentconguration.Theprocesswillruninthebackgroundforaboutaminute.Twoexecutablelesandtwologleswill
Chapter3.ManagingHardwarePasswordManagerdeviceswithThinkManagementConsoleTheavailableHardwarePasswordManagerfunctionsintheconsolearedescribedinthefoll
Enrolledusers:AllusersthatareenrolledtoaccesstheHardwarePasswordManagerdevicearelistedonthistab.TheintranetaccountusernameisthenameusedforLDAPuseracco
YoucanmigratefromoneLDAPservertoanotherwithoutlosingdata.IfyoundthatyouneedtouseadifferentserverforLDAPauthentication,enterthecongurationdataforthen
ThistablistsanyRemoveUseractionsthathavebeenperformedontheuser,includingthenameofthedevicefromwhichtheuserwasremovedandthedateandtimeofthelaststatusch
5.IfyouselectedWithexpiration,selectDuration,andthenselectthebeginningandendtimefortheaccesstoHardwarePasswordManagerdevices;orselectLogincountremaini
•RemoveUser:removesauserfromthelistofusersauthorizedtoaccessaHardwarePasswordManagerdevice.•UpdateClientPolicy:savesanupdatedclientpolicytotheHardware
•Allowmultipleuserstoenrollonasingledevice:morethanoneusercanbeenrolledonadevice.Ifthischeckboxiscleared,onlytherstusertobeenrolledonadevicecanbeanen
1.ClickRemoteActionsandPolicySettingsinthetoolboxorclickT ools➙ThinkVantageHardwarePasswordManager➙RemoteActionsandPolicySettings.2.IntheRemoteActions
ChangingserverpolicysettingsServerpolicysettingsincludevariouswaystomanageuserenrollment,credentials,andclientportalandBIOSsettingsfortheLenovoHardwar
HardwarePasswordManagergroups”onpage12foradescriptionofroles.)So,forexample,ausermightseealloptionsontheHardwarePasswordManagerBIOSmenubutaServiceTech
5.ClickOK.Toassignpermissionstoagroupthatcanbeauthenticatedthroughthenewauthentication,dothefollowing:1.IntheUser'stool,click+onthetoolbarorright
20HardwarePasswordManagerDeploymentGuide
Chapter4.HardwarePasswordManagerClientLenovodevicesthatsupportHardwarePasswordManagerneedtoberegisteredwithamanagementserver(referredtoastheHardwarePa
HardwarePasswordManagerDeploymentGuideUpdated:July,2010
Whentheclientisinstalled,itcommunicateswiththeHardwarePasswordManagerservertoauthenticatethedevice.TheclientcanthenrequestHardwarePasswordManagerpolic
•YoushoulddragthedevicesunderHardwarePasswordManagerDevicestotheActiveDirectoryoreDirectorygrouplistedintheHPMGroupstool.Ifyouradministratorhasenabled
UpdatingcredentialsonaHardwarePasswordManagerdeviceAfterHardwarePasswordManagementisenabledonadevice,youcanaccesstheHardwarePasswordManagerLoginMenuto
Chapter5.DeploymentThischaptercontainsadditionaldeploymentinformationforusingHardwarePasswordManagerdeviceswithHardwarePasswordManager.Itiswrittenfort
–enrolled-returnswhetherthecurrentWindowssystemuserisenrolledintheutility–enabled-returnswhethertheutilityisenabledintheBIOSprogram–show-displaysresul
Thisprocessisinitiatedautomaticallyontheclientsystembasedonpolicy,andadministratorcorporatecredentialsareobtainedfromtheHardwarePasswordManagerservert
28HardwarePasswordManagerDeploymentGuide
Chapter6.ScenariosThischapterdescribesscenariosassociatedwithhardwareandusercongurationchanges.Forthepurposeofthesescenarios,allsystemsareconsideredt
•EnterthehardwareaccountcredentialswithHardwarePasswordManagerAdministratorprivilegestoreleasetheSVP/PAP,suchastheEmergencyAdminaccount.Ifhardwareacco
HardwarePasswordManager,theBIOSwillclearthehardwarepasswordsanddeletethelocalhardwareaccountandSST.Scenario6-ReplacethesystemboardWhenthesystemboardis
Note:Beforeusingthisinformationandtheproductitsupports,readthegeneralinformationinAppendixD“Notices”onpage49.ThirdEdition(July2010)©CopyrightLenovo201
Ifthesystemisstillbootable,itisrecommendedtode-registerthesystemwithHardwarePasswordManager.Thiswillclearallthehardwarepasswordsfromthesystem.Installt
structuresarestoredinash,theashutilitieshavebeenupdatedtonotoverwriteHardwarePasswordManagerrelatedstructures.•ForwardFlashing-Whenashingtoanewerve
Note:TheharddriveshouldnotbeconnectedwhenthesystemisregisteredinHardwarePasswordManagerorelsetheharddiskwillbeassignedanHDP.UserScenariosThissectionde
acompletelydifferentsetofscancodesonanotherkeyboardtype.Forexample,considerthepasswordazw.OnanEnglishkeyboard,thescancoderepresentationis0x1E,0x2C,0x1
36HardwarePasswordManagerDeploymentGuide
AppendixA.SecurityandconvenienceComputersecurityisoftenconsideredmuchmoreimportantmoreconvenience.ThefollowingtableillustrateshowHardwarePasswordManag
Table1.HardwarePasswordManagerpolicysettings(continued)PolicysettingDescriptionMostsecureMostconvenientCommonEmergencyUserNameandPasswordDenestheemer
AppendixB.DisasterrecoveryBackingupthe9.0coreserverBeforeupgradingorotherwisemodifyingthecurrentHardwarePasswordManagercoreserver,itisimportanttobacku
1.CreateafoldercalledLANDeskBackuponashareonaseparateserverthatisnotthecoreserver.2.OpenacommandpromptonthecoreserverbyclickingStart➙Run,andlaunchingC
Ifmigratingtoanewdatabase,manyitemscannotbeexported.Takescreenshotsofsuchcongurationssothattheycanbeappliedtothenewcoreserver.Anexampleoftheseinclude
ContentsPreface...vChapter1.Overview...1Chapter2.InstallingHardwarePasswordManageronThinkManagementConsole...3Prerequisites...
42HardwarePasswordManagerDeploymentGuide
AppendixC.HintsandtipsThefollowingisalistoftipsassociatedwithHardwarePasswordManagerVersion1.0:•Symptom:Bitlockerrecoverymodeistriggeredifyouregistera
Problemdescription:Singlesign-ontoWindowswillnotworkiftheWindowspolicysettingisenabledthatrequirestheusertoPressCtrl+Alt+Deltologin.Thissecuritysettin
•Symptom:YoureceivetheFailedtogenerateencryptionkeyerrormessageduringtheHardwarePasswordManagerregistration.Problemdescription:UserswithaWindowsuserna
Ifyouhavealreadyrestoredyoursystem(forexample,lostyourCAPIkeystore),deregisterandreregisterinHardwarePasswordManager.•Symptom:WhenregisteringinHardwar
Solution:TheusermustuseawirednetworkconnectionwhenperforminganintranetloginfromtheBIOS.•Symptom:Receivetheincorrectusernameorpasswordspeciedmessagewh
48HardwarePasswordManagerDeploymentGuide
AppendixD.NoticesLenovomaynotoffertheproducts,services,orfeaturesdiscussedinthisdocumentinallcountries.ConsultyourlocalLenovorepresentativeforinformat
TrademarksThefollowingtermsaretrademarksofLenovointheUnitedStates,othercountries,orboth:AccessConnectionsLenovoThinkVantageThinkPadThefollowingtermsar
AppendixC.Hintsandtips...43AppendixD.Notices...49Trademarks...50ivHardwarePasswordManagerDeploymentGuide
PrefaceThisguideisintendedforITadministrators,orthosewhoareresponsiblefordeployingtheLenovo®HardwarePasswordManager™programoncomputersintheirorganizat
viHardwarePasswordManagerDeploymentGuide
Chapter1.OverviewTheLenovoHardwarePasswordManager(HPM)givesanadministratortheabilitytomanagehardwarepasswordsforallregisteredPCdevices.Further,itcreat
Komentarze do niniejszej Instrukcji