Lenovo ThinkVantage Client Security Solution 8.3 Instrukcja Użytkownika

Przeglądaj online lub pobierz Instrukcja Użytkownika dla Oprogramowanie Lenovo ThinkVantage Client Security Solution 8.3. Lenovo ThinkVantage Client Security Solution 8.3 User Manual Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 86
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 0
ClientSecuritySolution8.3
DeploymentGuide
Updated:December,2011
Przeglądanie stron 0
1 2 3 4 5 6 ... 85 86

Podsumowanie treści

Strona 1 - DeploymentGuide

ClientSecuritySolution8.3DeploymentGuideUpdated:December,2011

Strona 2 - “Notices”onpage75

consistentandsecureenvironment.Thesystemsthathavetheembeddedsecuritychiparemorerobustagainstanattack;however,forthesystemswithouttheembeddedsecuritych

Strona 3 - Contents

Chapter2.InstallationThischaptercontainsinstructionsforinstallingClientSecuritySolution,andFingerprintSoftware.BeforeinstallingClientSecuritySolutiono

Strona 4

Table1.PublicpropertiesPropertyDescriptionEMULATIONMODESpecifytoforcetheinstallationinEmulationmodeevenifaTPMexists.SetEMULATIONMODE=1onthecommandline

Strona 5 - ©CopyrightLenovo2008,2011

SoftwareemulationoftheTrustedPlatformModuleClientSecuritySolutionhastheoptiontorunwithoutaTrustedPlatformModuleonqualiedsystems.Thefunctionalitywillb

Strona 6

ThefollowingparametersanddescriptionsaredocumentedintheInstallShielddeveloperhelpdocumentation.ParametersthatdonotapplytoBasicMSIprojectswereremoved.T

Strona 7 - Chapter1.Overview

Table3.CommandlineparametersParameterDescription/IpackageorproductcodeUsethisformattoinstalltheproduct:Othello:msiexec/i"C:\WindowsFolder\Proles

Strona 8 - ClientSecurityPasswordManager

Table3.Commandlineparameters(continued)ParameterDescriptionYoucanseparatemultipletransformswithasemicolon.Donotusesemicolonsinthenameofyourtransform,a

Strona 9 - Hardwarepasswordreset

Table4.WindowsInstallerproperties(continued)PropertyDescriptionARPSYSTEMCOMPONENTPreventsdisplayofapplicationintheAddorRemoveProgramslist.ARPURLINFOAB

Strona 10 - FingerprintSoftware

InstallingThinkVantageFingerprintSoftwareThesetup.exeleoftheThinkVantageFingerprintSoftwareprogramcanbeinstalledthroughthefollowingmethods:Silentinst

Strona 11 - Chapter2.Installation

Table7.OptionssupportedbytheThinkVantageFingerprintSoftware(continued)ParameterDescriptionPASSPORTSetthedefaultpassporttype.•1=Localpassport•2=Serverp

Strona 12 - TrustedPlatformModulesupport

Note:Beforeusingthisinformationandtheproductitsupports,readthegeneralinformationinAppendixE“Notices”onpage75.FourthEdition(December2011)©CopyrightLeno

Strona 13 - Chapter2.Installation7

Table7.OptionssupportedbytheThinkVantageFingerprintSoftware(continued)ParameterDescriptionLOCKOUT•1=Enabletheanti-hammeringprotection.•0=Disabletheant

Strona 14 - Usingmsiexec.exe

SilentinstallationTosilentlyinstalltheFingerprintSoftware,runthesetup32.exelelocatedintheinstallationdirectoryonyourCD-ROMdrive.Usethefollowingsyntax

Strona 15 - .Installation9

Table8.OptionssupportedbytheLenovoFingerprintSoftware(continued)ParameterDescriptionSWALLOWIMEXPORT•0=Disablethengerprintimport/exportfornon-administ

Strona 16

SystemsManagementServerSystemsmanagementserver(SMS)installationsarealsosupported.OpentheSMSadministratorconsole.Createanewpackageandsetpackageproperti

Strona 17 - Installationlogle

18ClientSecuritySolution8.3DeploymentGuide

Strona 18 - Silentinstallation

Chapter3.WorkingwithClientSecuritySolutionBeforeyouinstallClientSecuritySolution,youshouldunderstandthecustomizationavailableforClientSecuritySolution

Strona 19 - .Installation13

enrolledasanactiveuser.EveryotheruserthatlogsintothesystemwillbeautomaticallyrequestedtoenrollintoClientSecuritySolution.•TakeOwnershipAsingleWindowsa

Strona 20

ThefollowingdiagramprovidesthestructurefortheSystemLevelKey:System Level Key Structure - Take OwnershipTrusted Platform ModuleEncrypted via derived AE

Strona 21

Thefollowingdiagramprovidesthestructurefortheuserlevelkey:User Level Key Structure - Enroll UserTrusted Platform ModuleEncrypted via derived AES KeySt

Strona 22

TheTPMemulationmodecannotbeusedasasecuresubstitutefortheTPM.TheTPMprovidesthefollowingtwokeyprotectionmethodsthataremoresecurethantheTPMemulationmode.

Strona 23 - SystemsManagementServer

ContentsPreface...iiiChapter1.Overview...1ClientSecuritySolution...1ClientSecuritySolutionpassphrase...2ClientSecurity

Strona 24

Thefollowingdiagramprovidesthestructureforthemotherboardswap-takeownership:Motherboard Swap - Take OwnershipTrusted Platform ModuleDecrypted via deriv

Strona 25 - UsingtheTrustedPlatformModule

EFSprotectionutilityClientSecuritySolutionprovidesacommandlineutilitythatenablesTPM-basedprotectionofencryptioncerticatesusedbytheEncryptingFileSyste

Strona 26 - TakeOwnership

Whenruninsilentmode,theoutputoftheprogramwillbeanerrorlevelcorrespondingtotheerrorsnumbersshownabove.UsingtheXMLSchemaThepurposeoftheXMLscriptingistoe

Strona 27 - EnrollUser

<ORDER>0001</ORDER><COMMAND>DISABLE_TPM_FUNCTION</COMMAND><VERSION>1.0</VERSION><SYSTEM_PAP>password</SYS

Strona 28 - Softwareemulation

2.Thiscommandisnotsupportedintheemulationmode.ThefollowingcommandenablesthelogonwithfastuserswitchingsupportanddisablestheClientSecuritySolutionWindow

Strona 29 - Systemboardswap

ENABLE_NONE_GINA_FUNCTIONIftheGINAorCP(CredentialProvider)ofoneoftherelatedThinkVantageTechnologiescomponents,suchasThinkVantageFingerprintSoftware,Cl

Strona 30

Note:Thiscommandisnotsupportedintheemulationmode.INITIALIZE_SYSTEM_FUNCTIONThiscommandinitializestheClientSecuritySolutionsystemfunction.Thesystem-wid

Strona 31 - EFSprotectionutility

Note:Thiscommandisnotsupportedintheemulationmode.ENROLL_USER_FUNCTIONThiscommandenrollsaparticularusertouseClientSecuritySolution.Thisfunctioncreatesa

Strona 32 - Examples

<DOMAIN_NAME_PARAMETER>IBM-2AA92582C79<DOMAIN_NAME_PARAMETER><USER_PW_REC_ANSWER_DATA_PARAMETER>Test1</USER_PW_REC_ANSWER_DATA_PA

Strona 33 - ENABLE_UPEK_GINA_FUNCTION

1.GotothefollowingWebsite:http://www.rsasecurity.com/node.asp?id=11562.Completetheregistrationprocess.3.DownloadandinstalltheRSASecurIDSoftware.Requir

Strona 34

Scenario2...59SwitchingClientSecuritySolutionmodes...61CorporateActiveDirectoryrollout...61StandaloneInstallforCDorscriptles...62Sy

Strona 35 - SET_ADMIN_USER_FUNCTION

Table10.ThinkVantage\ClientSecuritySolution\AuthenticationPolicies\PKCS#11Signature\CustomModeFieldsCSS.ADMModiableeldRequiredFieldDescriptionContro

Strona 36 - INITIALIZE_SYSTEM_FUNCTION

•“CerticateTransfertool”onpage37•“ActivatingordeactivatingtheTPM”onpage38SecurityAdvisorTousetheSecurityAdvisorfunction,launchtheClientSecuritySoluti

Strona 37 - USER_PW_RECOVERY_FUNCTION

Table11.Parameters(continued)ParametersDescriptionEmbeddedSecurityChipSetsvaluethatsecuritychipshouldbeenabled,orsettingwillbeagged.ClientSecuritySol

Strona 38 - UsingRSASecurIDtokens

Table13.ParametersforencryptingordecryptingClientSecurityXMLdeploymentles(continued)ParametersResults/encryptor/decryptSelects/encryptforXMLlesand/d

Strona 39 - ActiveDirectorySupport

Table16.css_cert_transfer_tool.exe<cert_store_type><lter_type>:<name|size>|all_access|usageParameterDescription<cert_store_type&

Strona 40 - Command-linetools

Fordesktopcomputers,dothefollowingtoactivatetheTPM:1.GototheWebsiteathttp://support.lenovo.com/en_US/detail.page?LegacyDocID=MIGR-75407.2.ClickVisualB

Strona 41 - SecurityAdvisor

•Disabled•Activated•Deactivated•Owned•Notowned/setstate:<state>setstheTPMstatustypeyouprefer.0representsdisabledanddeactivated.1representsenable

Strona 42

ThefollowingexamplesaresettingsthatActiveDirectorycanmanageforClientSecuritySolution:•Securitypolicies.•Customsecuritypolicies;suchaswhethertouseaWind

Strona 43 - CerticateTransfertool

HKLM\Software\Lenovo\ClientSecuritySolution\Userpreferences:HKCU\Software\Lenovo\ClientSecuritySolution\Defaultuserpreferences:HKLM\Software\Lenovo\Cl

Strona 44

Table20.ComputerConguration➙Administrativetemplates➙ThinkVantage➙ClientSecuritySolution➙Authenticationpolicies➙Defaultmode(continued)PolicyEnabledset

Strona 45

PrefaceInformationpresentedinthisguideistosupportLenovo®computersinstalledwiththeThinkVantage®ClientSecuritySolutionprogramandtheFingerprintSoftwarepr

Strona 46

Table22.ComputerConguration➙ThinkVantage➙ClientSecuritySolution➙Passwordmanager(continued)PolicysettingDescriptionDisableAuto-llControlswhetherPassw

Strona 47 - Deningmanageablesettings

Table23.ComputerConguration➙ThinkVantage➙ClientSecuritySolution➙Userinterface(continued)PolicysettingDescriptionEnable/disableWindowspasswordrecovery

Strona 48 - GroupPolicysettings

Table24.ComputerConguration➙ThinkVantage➙ClientSecuritySolution➙Workstationsecuritytool(continued)PolicySettingDescriptionClientSecurityEmbeddedSecur

Strona 49 - Passwordmanager

Chapter4.WorkingwithThinkVantageFingerprintSoftwareThengerprintconsolemustberunfromtheThinkVantageFingerprintSoftwareinstallationfolder.Thebasicsynta

Strona 50 - UserInterface

Table25.User-speciccommands(continued)CommandSyntaxDescriptionEnumerateenrolledusersListListstheenrolledusers.ExportenrolledusertoaleSyntax:EXPORTus

Strona 51 - Workstationsecuritytool

SecuremodeandconvenientmodeFingerprintSoftwarecanberunintwosecuritymodes,asecuremodeandaconvenientmode.Thesecuremodeisintendedforsituationswhenyouwant

Strona 52

Table28.Optionsforlimitedusersinthesecuremode(continued)SettingDescriptionDeletePassportLimitedusercandeleteonlytheirownpassport.Power-onSecurityLimit

Strona 53 - User-speciccommands

Table30.Optionsforlimitedusersintheconvenientmode(continued)SettingsDescriptionSecuritymodeLimiteduserscannotmodifysecuritymodes.ProServersLimiteduser

Strona 54 - Globalsettingscommands

Thengerprintsoftwarewillcontinuetovalidatethepasswordatsystemlogon.Note:Whentheaboveregistrykeyissetto1,ifthedomainadministratorchangestheuser's

Strona 55 - Securemode-limiteduser

8.LogontoWindows.9.Reboot.Note:YourauthenticationIDandpasswordforWindowsandNovellmustbeidentical.ThinkVantageFingerprintSoftwareserviceTheupeksvr.exes

Strona 56 - Convenientmode-limiteduser

ivClientSecuritySolution8.3DeploymentGuide

Strona 57 - Congurablesettings

54ClientSecuritySolution8.3DeploymentGuide

Strona 58 - Authenticating

Chapter5.WorkingwithLenovoFingerprintSoftwareThengerprintconsolemustberunfromtheLenovoFingerprintSoftwareinstallationfolder.ThebasicsyntaxisFPRCONSOL

Strona 59

Table31.Policysettings(continued)SettingDescriptionadministratorswillonlybeabletologinusingngerprints.Allowusertoretrievepasswordthroughngerprintaut

Strona 60

Chapter6.BestPracticesThischapterpresentsscenariostoillustratethebestpracticesofClientSecuritySolutionandFingerprintSoftware.Thisscenariostartswiththe

Strona 61

3)TypetheClientSecuritypassphrase(forexample,CSPP4Admin)fortheadministratoraccount,selecttheUsetheClientSecuritypassphrasetoprotectaccesstotheRescuean

Strona 62

*******************************************************Readytotakesysprepbackup.********PLEASERUNSYSPREPNOWANDSHUTDOWN.********Nexttimethemachineboots

Strona 63 - Chapter6.BestPractices

b.Double-clicktheextractedsetup.exeleandfollowtheinstructionsonthescreentoinstalltheThinkVantageFingerprintSoftware.4.InstalltheThinkVantageFingerpri

Strona 64

3.InstalltheThinkVantageFingerprintconsoleonthedeploymentmachinebydoingthefollowing:a.Deploythefprconsole.exelethathasbeenextractedfromthepreparation

Strona 65 - Scenario2

c.ThroughActiveDirectory,enableAntidoteDeliveryManager.Placepackagestoberunandmakesurereportingiscaptured.StandaloneInstallforCDorscriptlesForastanda

Strona 66

3.FromtheFilemenu,clickAdd/RemoveSnap-in,andthenclickAdd.TheAddStandalonesnap-inwindowdisplays.4.Double-clickCerticationAuthorityinthesnap-inlist,and

Strona 67 - Chapter6.BestPractices61

Chapter1.OverviewThischapterprovidesanoverviewofClientSecuritySolutionandFingerprintSoftware.Thetechnologiespresentedinthisdeploymentguidecandirectlya

Strona 68 - CreatingtemplateforTPMuser

ThissectiondescribesthecommonusagescenariosanddeploymentstrategiesforngerprintsoftwarethatisinstalledonthelatestThinkPadnotebookcomputermodels.Note:•

Strona 69 - Chapter6.BestPractices63

Table32.RegistrykeysNameValueDescription0(default)Speciesthattheexternalngerprintsensorispreferredwheneverthengerprintkeyboardisconnected.PreferInt

Strona 70 - Windows7logon

66ClientSecuritySolution8.3DeploymentGuide

Strona 71 - Chapter6.BestPractices65

AppendixA.SpecialconsiderationsforusingtheLenovoFingerprintKeyboardwithsomeThinkPadnotebookmodelsThengerprintdeviceusedinsomeThinkPadnotebookmodelsis

Strona 72

•UsingtheFingerprintSoftwarelogoninterfaceThelogoninterfacesofbothLenovoFingerprintSoftwareandThinkVantageFingerprintSoftwaremustbeenabled.Whenbothng

Strona 73 - Windowslogon

AppendixB.SynchronizingpasswordinClientSecuritySolutionaftertheWindowspasswordisresetAftertheWindowspasswordisreset,ClientSecuritySolutioncontinuallyp

Strona 74

70ClientSecuritySolution8.3DeploymentGuide

Strona 75

AppendixC.UsingClientSecuritySolutiononareinstalledWindowsoperatingsystemIfyourWindowsoperatingsysteminstalledwithClientSecuritySolutionhasbeenreinsta

Strona 76

72ClientSecuritySolution8.3DeploymentGuide

Strona 77 - Windowsoperatingsystem

AppendixD.UsingtheTPMonThinkPadnotebookcomputersThemainusecasefortheTPMistheBitLockerfeaturethatisincludedwithcertainversionsoftheMicrosoftWindowsVist

Strona 78

ClientSecuritySolutionpassphraseTheClientSecuritySolutionpassphraseisanoptionalfeatureofuserauthenticationthatwillprovideenhancedsecuritytoClientSecur

Strona 79 - HowdoesTPMlockoutwork?

•Atmel-ThinkPadT60/R60/X60/X300,ThinkCentreM57•Intel-ThinkPadT500/R500/X200/X301•STMicro-ThinkPadT410/T510/X201/T420/T520/X220,ThinkCentreM90•Winbond-

Strona 80

AppendixE.NoticesLenovomaynotoffertheproducts,services,orfeaturesdiscussedinthisdocumentinallcountries.ConsultyourlocalLenovorepresentativeforinformat

Strona 81 - AppendixE.Notices

TrademarksThefollowingtermsaretrademarksofLenovointheUnitedStates,othercountries,orboth:LenovoThinkCentreThinkPadThinkVantageMicrosoft,InternetExplore

Strona 82 - Trademarks

GlossaryAdministrator(ThinkCentre)/Supervisor(ThinkPad)BIOSPasswordTheadministratororsupervisorpasswordisusedtocontroltheabilitytochangeBIOSsettings.T

Strona 83 - Glossary

Symmetric-keyencryptionSymmetrickeyencryptionciphersusethesamekeyforencryptionanddecryptionofdata.Symmetrickeyciphersaresimplerandfaster,buttheirmaind

Strona 85

PartNumber:PrintedinUSA(1P)P/N:**

Strona 86 - (1P)P/N:

entryrelatedchangescanbedetectedautomaticallybyClientSecurityPasswordManagerandallowstheusertoupdatetheirentrieswithevenlesswork.•Saveyourinformationw

Komentarze do niniejszej Instrukcji

Brak uwag