Lenovo ThinkVantage (Client Security Solution 8.21) User Manual

Page 3

Advertising
background image

Contents

Preface . . . . . . . . . . . . . . . .

iii

Chapter 1. Overview. . . . . . . . . . . 1

Client Security Solution . . . . . . . . . . . .

1

Client Security Solution passphrase

. . . . .

2

Client Security password recovery . . . . . .

2

Client Security Password Manager . . . . . .

2

Security Advisor . . . . . . . . . . . . .

3

Certificate Transfer wizard . . . . . . . . .

3

Hardware password reset . . . . . . . . .

3

Support for systems without Trusted Platform
Module . . . . . . . . . . . . . . . . .

4

Fingerprint Software . . . . . . . . . . . . .

4

Chapter 2. Installation . . . . . . . . . . 5

Client Security Solution . . . . . . . . . . . .

5

Installation requirements . . . . . . . . . .

5

Custom public properties. . . . . . . . . .

6

Trusted Platform Module support

. . . . . .

6

Installation procedures and command-line
parameters . . . . . . . . . . . . . . .

7

Standard Windows Installer public
properties . . . . . . . . . . . . . . .

10

Installation log files . . . . . . . . . . .

11

Installing Client Security Solution 8.21 with
existing versions . . . . . . . . . . . .

12

Installing ThinkVantage Fingerprint Software . . .

12

Silent installation . . . . . . . . . . . .

12

Options. . . . . . . . . . . . . . . .

12

Installing Lenovo Fingerprint Software . . . . .

13

Silent installation . . . . . . . . . . . .

13

Options. . . . . . . . . . . . . . . .

13

Systems Management Server . . . . . . . . .

15

Chapter 3. Working with Client
Security Solution . . . . . . . . . . .

17

Using the Trusted Platform Module. . . . . . .

17

Using the Trusted Platform Module with
Windows Vista . . . . . . . . . . . . .

17

Managing Client Security Solution with
cryptographic keys . . . . . . . . . . . . .

17

Take Ownership . . . . . . . . . . . .

18

Enroll User . . . . . . . . . . . . . .

19

Software emulation . . . . . . . . . . .

20

System board swap . . . . . . . . . . .

21

EFS protection utility . . . . . . . . . .

23

Using the XML Schema . . . . . . . . . . .

24

Examples . . . . . . . . . . . . . . .

24

Using RSA SecurID tokens . . . . . . . . . .

31

Installing the RSA SecurID Software Token . .

31

Requirements . . . . . . . . . . . . .

31

Setting the Smart Card Access Options . . .

31

Installing the RSA SecurID Software Token
manually . . . . . . . . . . . . . . .

31

Active Directory Support . . . . . . . . .

31

Settings and policies for the fingerprint reader
authentication . . . . . . . . . . . . . . .

32

Enforced fingerprint bypass option . . . . .

32

Fingerprint swipe result . . . . . . . . .

32

Command-line tools . . . . . . . . . . . .

32

Security Advisor . . . . . . . . . . . .

33

Client Security Solution setup wizard . . . .

34

Deployment file encrypt or decrypt tool . . .

34

Deployment file processing tool . . . . . .

35

TPMENABLE.EXE

. . . . . . . . . . .

35

Certificate Transfer tool . . . . . . . . .

35

TPM activate tool . . . . . . . . . . . .

36

Active Directory Support . . . . . . . . . . .

37

Administrative (ADM) template files . . . . .

37

Group Policy settings . . . . . . . . . .

38

Active Update . . . . . . . . . . . . .

42

Chapter 4. Working with
ThinkVantage Fingerprint Software .

45

Management console tool . . . . . . . . . .

45

User-specific commands . . . . . . . . .

45

Global settings commands . . . . . . . .

46

Secure mode and convenient mode . . . . . .

47

Secure mode - administrator . . . . . . .

47

Secure mode - limited user . . . . . . . .

47

Convenient mode - administrator

. . . . .

48

Convenient mode - limited user . . . . . .

48

Configurable settings . . . . . . . . . .

49

Fingerprint Software and Novell Netware Client . .

50

Authenticating . . . . . . . . . . . . .

50

ThinkVantage Fingerprint Software service. . . .

51

Chapter 5. Working with Lenovo
Fingerprint Software . . . . . . . . .

53

Management console tool . . . . . . . . . .

53

Lenovo Fingerprint Software service . . . . . .

53

Active Directory support for Lenovo Fingerprint
Software . . . . . . . . . . . . . . . . .

53

Chapter 6. Best Practices . . . . . . .

55

© Copyright Lenovo 2008, 2012

i

Advertising