Lenovo ThinkVantage (Hardware Password Manager Deployment Instrukcja Użytkownika

Przeglądaj online lub pobierz Instrukcja Użytkownika dla Notatniki Lenovo ThinkVantage (Hardware Password Manager Deployment. Lenovo ThinkVantage (Hardware Password Manager Deployment Guide) User Manual Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj

Podsumowanie treści

Strona 1 - DeploymentGuide

HardwarePasswordManagerDeploymentGuideUpdated:July,2010

Strona 2

2HardwarePasswordManagerDeploymentGuide

Strona 3

Chapter2.InstallingHardwarePasswordManageronThinkManagementConsoleTouseHPMfunctionality,theLenovoThinkManagementConsolemustbeinstalled.Asyoucongureth

Strona 4 - “Notices”onpage49

PreparingthecoreserverTheHPMcoreserverwillusetheThinkManagementConsole9.0thatisbasedonLANDeskManagementSuite9.0.FormoreinformationaboutLANDeskManageme

Strona 5 - Contents

WhenusingtheWindowsServer2008R2(64-bit)operatingsystem,theMonitoring/Alerts(SNMP)additionalfeaturemustbeinstalledaswell.1.ClickStart➙ServerManager.2.I

Strona 6 - AppendixD.Notices...49

3.RuntheThinkManagementConsoleAutorun.exefromthelocationwheretheinstallationpackagewasextractedto.SelectInstallonthecoreserver.FollowthepromptsintheIn

Strona 7

1.IntheThinkManagementconsole,clickTools➙Conguration➙AgentConguration.2.ClickNewontheAgentCongurationtoolbar,andenteranameforthisagentconguration.

Strona 8

Thenameoftheexecutablelewillbebasedonthenameoftheagentconguration.Theprocesswillruninthebackgroundforaboutaminute.Twoexecutablelesandtwologleswill

Strona 9 - Chapter1.Overview

Chapter3.ManagingHardwarePasswordManagerdeviceswithThinkManagementConsoleTheavailableHardwarePasswordManagerfunctionsintheconsolearedescribedinthefoll

Strona 10

Enrolledusers:AllusersthatareenrolledtoaccesstheHardwarePasswordManagerdevicearelistedonthistab.TheintranetaccountusernameisthenameusedforLDAPuseracco

Strona 11 - ThinkManagementConsole

YoucanmigratefromoneLDAPservertoanotherwithoutlosingdata.IfyoundthatyouneedtouseadifferentserverforLDAPauthentication,enterthecongurationdataforthen

Strona 13

ThistablistsanyRemoveUseractionsthathavebeenperformedontheuser,includingthenameofthedevicefromwhichtheuserwasremovedandthedateandtimeofthelaststatusch

Strona 14 - MigratingtoanewLDAPserver

5.IfyouselectedWithexpiration,selectDuration,andthenselectthebeginningandendtimefortheaccesstoHardwarePasswordManagerdevices;orselectLogincountremaini

Strona 15

•RemoveUser:removesauserfromthelistofusersauthorizedtoaccessaHardwarePasswordManagerdevice.•UpdateClientPolicy:savesanupdatedclientpolicytotheHardware

Strona 16

•Allowmultipleuserstoenrollonasingledevice:morethanoneusercanbeenrolledonadevice.Ifthischeckboxiscleared,onlytherstusertobeenrolledonadevicecanbeanen

Strona 17 - ©CopyrightLenovo2010

1.ClickRemoteActionsandPolicySettingsinthetoolboxorclickT ools➙ThinkVantageHardwarePasswordManager➙RemoteActionsandPolicySettings.2.IntheRemoteActions

Strona 18

ChangingserverpolicysettingsServerpolicysettingsincludevariouswaystomanageuserenrollment,credentials,andclientportalandBIOSsettingsfortheLenovoHardwar

Strona 19

HardwarePasswordManagergroups”onpage12foradescriptionofroles.)So,forexample,ausermightseealloptionsontheHardwarePasswordManagerBIOSmenubutaServiceTech

Strona 20

5.ClickOK.Toassignpermissionstoagroupthatcanbeauthenticatedthroughthenewauthentication,dothefollowing:1.IntheUser'stool,click+onthetoolbarorright

Strona 21 - Managerdevices

20HardwarePasswordManagerDeploymentGuide

Strona 22

Chapter4.HardwarePasswordManagerClientLenovodevicesthatsupportHardwarePasswordManagerneedtoberegisteredwithamanagementserver(referredtoastheHardwarePa

Strona 23

HardwarePasswordManagerDeploymentGuideUpdated:July,2010

Strona 24 - Updatingtheemergencyaccount

Whentheclientisinstalled,itcommunicateswiththeHardwarePasswordManagerservertoauthenticatethedevice.TheclientcanthenrequestHardwarePasswordManagerpolic

Strona 25 - Changingserverpolicysettings

•YoushoulddragthedevicesunderHardwarePasswordManagerDevicestotheActiveDirectoryoreDirectorygrouplistedintheHPMGroupstool.Ifyouradministratorhasenabled

Strona 26

UpdatingcredentialsonaHardwarePasswordManagerdeviceAfterHardwarePasswordManagementisenabledonadevice,youcanaccesstheHardwarePasswordManagerLoginMenuto

Strona 27

Chapter5.DeploymentThischaptercontainsadditionaldeploymentinformationforusingHardwarePasswordManagerdeviceswithHardwarePasswordManager.Itiswrittenfort

Strona 28

–enrolled-returnswhetherthecurrentWindowssystemuserisenrolledintheutility–enabled-returnswhethertheutilityisenabledintheBIOSprogram–show-displaysresul

Strona 29

Thisprocessisinitiatedautomaticallyontheclientsystembasedonpolicy,andadministratorcorporatecredentialsareobtainedfromtheHardwarePasswordManagerservert

Strona 30

28HardwarePasswordManagerDeploymentGuide

Strona 31

Chapter6.ScenariosThischapterdescribesscenariosassociatedwithhardwareandusercongurationchanges.Forthepurposeofthesescenarios,allsystemsareconsideredt

Strona 32

•EnterthehardwareaccountcredentialswithHardwarePasswordManagerAdministratorprivilegestoreleasetheSVP/PAP,suchastheEmergencyAdminaccount.Ifhardwareacco

Strona 33 - Chapter5.Deployment

HardwarePasswordManager,theBIOSwillclearthehardwarepasswordsanddeletethelocalhardwareaccountandSST.Scenario6-ReplacethesystemboardWhenthesystemboardis

Strona 34 - One-touchregistration

Note:Beforeusingthisinformationandtheproductitsupports,readthegeneralinformationinAppendixD“Notices”onpage49.ThirdEdition(July2010)©CopyrightLenovo201

Strona 35 - Pre-registration

Ifthesystemisstillbootable,itisrecommendedtode-registerthesystemwithHardwarePasswordManager.Thiswillclearallthehardwarepasswordsfromthesystem.Installt

Strona 36

structuresarestoredinash,theashutilitieshavebeenupdatedtonotoverwriteHardwarePasswordManagerrelatedstructures.•ForwardFlashing-Whenashingtoanewerve

Strona 37 - Chapter6.Scenarios

Note:TheharddriveshouldnotbeconnectedwhenthesystemisregisteredinHardwarePasswordManagerorelsetheharddiskwillbeassignedanHDP.UserScenariosThissectionde

Strona 38

acompletelydifferentsetofscancodesonanotherkeyboardtype.Forexample,considerthepasswordazw.OnanEnglishkeyboard,thescancoderepresentationis0x1E,0x2C,0x1

Strona 39 - Scenario7-Addaharddiskdrive

36HardwarePasswordManagerDeploymentGuide

Strona 40 - Scenario11-FlashingtheBIOS

AppendixA.SecurityandconvenienceComputersecurityisoftenconsideredmuchmoreimportantmoreconvenience.ThefollowingtableillustrateshowHardwarePasswordManag

Strona 41 - Scenario13-EntertheBIOSsetup

Table1.HardwarePasswordManagerpolicysettings(continued)PolicysettingDescriptionMostsecureMostconvenientCommonEmergencyUserNameandPasswordDenestheemer

Strona 42

AppendixB.DisasterrecoveryBackingupthe9.0coreserverBeforeupgradingorotherwisemodifyingthecurrentHardwarePasswordManagercoreserver,itisimportanttobacku

Strona 43 - Scenario6-BitLocker

1.CreateafoldercalledLANDeskBackuponashareonaseparateserverthatisnotthecoreserver.2.OpenacommandpromptonthecoreserverbyclickingStart➙Run,andlaunchingC

Strona 44

Ifmigratingtoanewdatabase,manyitemscannotbeexported.Takescreenshotsofsuchcongurationssothattheycanbeappliedtothenewcoreserver.Anexampleoftheseinclude

Strona 45

ContentsPreface...vChapter1.Overview...1Chapter2.InstallingHardwarePasswordManageronThinkManagementConsole...3Prerequisites...

Strona 46

42HardwarePasswordManagerDeploymentGuide

Strona 47 - AppendixB.Disasterrecovery

AppendixC.HintsandtipsThefollowingisalistoftipsassociatedwithHardwarePasswordManagerVersion1.0:•Symptom:Bitlockerrecoverymodeistriggeredifyouregistera

Strona 48

Problemdescription:Singlesign-ontoWindowswillnotworkiftheWindowspolicysettingisenabledthatrequirestheusertoPressCtrl+Alt+Deltologin.Thissecuritysettin

Strona 49 - AppendixB.Disasterrecovery41

•Symptom:YoureceivetheFailedtogenerateencryptionkeyerrormessageduringtheHardwarePasswordManagerregistration.Problemdescription:UserswithaWindowsuserna

Strona 50

Ifyouhavealreadyrestoredyoursystem(forexample,lostyourCAPIkeystore),deregisterandreregisterinHardwarePasswordManager.•Symptom:WhenregisteringinHardwar

Strona 51 - AppendixC.Hintsandtips

Solution:TheusermustuseawirednetworkconnectionwhenperforminganintranetloginfromtheBIOS.•Symptom:Receivetheincorrectusernameorpasswordspeciedmessagewh

Strona 52

48HardwarePasswordManagerDeploymentGuide

Strona 53 - AppendixC.Hintsandtips45

AppendixD.NoticesLenovomaynotoffertheproducts,services,orfeaturesdiscussedinthisdocumentinallcountries.ConsultyourlocalLenovorepresentativeforinformat

Strona 54

TrademarksThefollowingtermsaretrademarksofLenovointheUnitedStates,othercountries,orboth:AccessConnectionsLenovoThinkVantageThinkPadThefollowingtermsar

Strona 56

AppendixC.Hintsandtips...43AppendixD.Notices...49Trademarks...50ivHardwarePasswordManagerDeploymentGuide

Strona 58 - Trademarks

PrefaceThisguideisintendedforITadministrators,orthosewhoareresponsiblefordeployingtheLenovo®HardwarePasswordManager™programoncomputersintheirorganizat

Strona 59

viHardwarePasswordManagerDeploymentGuide

Strona 60

Chapter1.OverviewTheLenovoHardwarePasswordManager(HPM)givesanadministratortheabilitytomanagehardwarepasswordsforallregisteredPCdevices.Further,itcreat

Komentarze do niniejszej Instrukcji

Brak uwag