Manuel d'utilisation / d'entretien du produit t5720 du fabricant HP (Hewlett-Packard)
Aller à la page of 41
Impleme nting A cti vIdentity Smar t Car ds f or U se w ith HP C ompaq t5 7 20 Thin C li ents and HP Blade P Cs Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 Prerequisites .
2 Intr oduction Smart cards can str engthen user authen tication in a cor por ate networ k b y offe ring str ong, 2 -factor a uthen- ticati on to offse t weak pas s w or ds or cumbe rsome a uthenticati on polic ies r equir ing fr equent pas s wo rd changes .
3 • Citr ix Pr esent ation Serv er 4 w ith Hotfi x Rollup P ac k PSE4 00W2KR01 f or Citr ix Pr esent ation Server 4. 0 for Windo ws 2000 Server . •F a t c l i e n t s : - Client (W indo w s 2000/XP): MetaFr ame Pr esenta ti on Server C lient P ac k ager 8.
4 • Smart Card R eaders • HP standar d USB Smart Car d K ey boar d . Go to http://w ww .hp.com fo r dri ver support avail- able w ith sp3113 7 .e xe (dr i v er 4. 30. 0.1) or greater . Dri ver : HPKBCC ID .s ys , v ersi on 4. 30. 0.1. • USB CA C appr ov ed smar t card r eader (SCM Mi cr osy stems SCR3 31 Reader ).
5 Cli ent So ft w ar e Conf igur ation Installing A cti vClient PK I Only The S etup Deplo yment c h apter o f the Res our ce K it pr o vi ded b y Acti vI dentity disc usse s ho w to deploy Acti vClient u sing standar d methods . The A cti vCli ent PKI Onl y 6 .
6 As mentioned a bov e, the f irst ins tallati on step is to mo dify the thin cli ent’s RAMDisk si z e fr om defa ult set- tings to 64 MB . Mak e note o f the defa ult setting so th at it can be r estor ed af te r installati on is complete . T o change RAMDisk si z e, c lic k Start > Control P anel > HP RAMDisk M anager .
7 Once the env ironmental v ari ables hav e been changed, r ight-clic k on the EWF i con on the taskbar and select Commi t . NO TE : T he env ironmental v ar iables should be c hanged bac k to de fault se ttings after installation pac k age has been installed , and then the wr ite filter change s mus t again be committed.
8 Initiali zing the smart card Use the f ollo w ing procedur e on blank smart cards or car ds whic h contain a standalone pr of ile that need to be r e -initiali z ed. T o initiali z e your P IN using the P IN Initiali z ation T ool: 1. Go to Start > Programs > ActivIdentity > Ac tivClient and select PIN Initialization Tool .
9 Ser ver Soft war e Conf iguration Installing M ic ro soft C ertifi cate Serv ice s R ole based administr ati v e featur es included in Wind ow s Ser v er 2003 can be u sed to manage and main- tain digital certif icates v ia the Certificati on A uthor ity (CA).
10 4. Click Cert ific ate S ervic es , and then clic k Ne xt . 5. Select Enterpris e Root CA , and then c lic k Ne xt ..
11 6. Click Ye s to accept the w arning . 7. Ty p e a Common name for this CA , and then clic k Ne xt ..
12 8. Select Ne x t to accept Certif icate Databas e Settings . The ins tallation w ill configur e components , as sho wn in the f ollo wing sc r een .
13 9. Click Ye s w hen pr ompted to temporar ily stop IS S. 10. Click Fini sh to complete the installatio n. Conf igur ing a Ce rtifi cate A uthor it y (CA ) serv ice Conf igur e a CA service . This white pa per uses Mi c r os oft Cer ti ficat e Se r vices t o c onfig ure c er ti ficat es.
14 3. Cr eate a duplicat e template b y ri ght-clic king on the Smartcard L ogon certifi cate template , and then select ing Duplicate T emplate . 4. T ype a name fo r the new te mplate in the Te m p l a t e D i s p l a y n a m e box . F or this ex ample we w ill use the temp late nam e of CCI Sma rtcard User .
15 5. Click t he Request Hand ling tab. 6. Select 10 2 4 in the Minimum ke y size box . 7. Click t he CSP s button. 8. Select Requests can use any CSP available on t he subjec t ’s compu ter .
16 10. In the P ermis sions for Authentica ted Users ar ea , in the Allo w column, selec t both Rea d and Enroll. Y ou hav e cr eated the cr eati on of the templat e. 11. Copy t he CCI SmartCar d User certifi cate template into the Cert ific ate s T emplates folder under the certific ate server .
17 d. S el e ct Ne w > Certificate Template to Is sue. 12. Selec t the template , and then clic k OK to import the template..
18 Conf igur ing Mi cr oso ft Certifi cate A uthor ity to Issue Smart Car d User C ertifi- cate Acti vClient 6 . 0 PKI Serv ices support Digital certif i cate- based logon t o Windo ws 2000, Windo ws XP Pr o- fes sional , and W indo w s Server 200 3 .
19 2. Expand the def ined CA. 3. Rig h t - cl ic k Certifi cate T emplat es , and then select Ne w . a. S el e ct Certifica te T emp late to I ssue . b . Selec t Enrollment Agent. c. S el ect OK to add. 4. Launc h Internet Explor er and bro w se to http://localhost/certsr v .
20 5. Under Select a task , select Request a cer tifica te . 6. Select advanced certificate request..
21 7. Select Create and submit req uest to th is CA . 8. In the Cert ifi cate T emplat es bo x, s elect Enr ollment Ag ent..
22 9. V erify Enr ollment A gent Settings in the Key O pt i on s section as follo ws: • Create new k e y is selected • Mic roso ft Enhanced Cryptogr aphic Pr ov ider v1. 0 •C l i c k Submit . 10. Accept def ault se ttings under Additional O ptions .
23 12. Install the Enr ollment certificate r eques ted. 13. Select Ye s to P o tent ial Scrip tion Violat ion. Y ou hav e succes sfull y gener ated and inst alled r equ ir ed Enr ollment Certif icate , as show n belo w .
24 Manuall y issue Smart Car d User C ertifi cate 1. Launc h Internet Explor er and bro w se to http://localhost/certsr v . 2. Select Reque st a ce rtificate .
25 4. Select Request a cer tificate for a smar t card on behalf of anoth er user b y using t he smart card cer tificate enrollment s tation. 5. Select Smartcard User under Enrollment O ptions .
26 6. Def ine the user to enr oll by c lic king Select User . NO TE : Ac tivC lient L ibr ar ies ma y r eport a container err or message w hen used f or sec ur e logon purpo ses.
27 7. Inser t Smar t Card into Reader , and then select Enr oll . Smart Car d V alidati on T esting the Smart Car d T o ver if y that the CCI SmartCar d L ogon certific ate fo r the user is ins talled on the smart car d: 1. Cli ck t he ActivCard icon in t he sy stem tray to open the Ac tivClient user consol e .
28 3. Select the u sername ID to v ie w the installed certificate , whic h sho w s: • who it w as issued to • who is w as issued by • vali d dates T roubleshoot A cti vClient The T rouble shooting Wi z ar d helps y ou sol ve an y problems w ith Acti vClient .
29 The f ollo wing table lis ts what ac tions t o tak e ne xt if y ou do not type y our PIN or the T r oubleshooting Wi z ard is displa y ed: 5. When the Anal ysis in Pr ogr ess page is displa y ed , cli ck Ne xt . 6. If pr oblems ar e detected , then the Problems f ound page is displa y ed .
30 • Manage the smart cards and certifi cates us ed w ith Acti vClient PKI Onl y 6 . 0 L ibr ari es • Use A cti vCli ent PK I Only 6 .0 L ibr ar ies to log o n/o ff and lock/unloc k y our W indo w s 2000, XP wo rk- stati on , Windo ws 2000 and 2003 S ervers .
31 Usage cases Usage cas e 1: User a uthenti cation f r om HP blade PC to A cti ve Dir ector y Domain The f ollo wing step s pr ov ide instruc tions f or perf orming a f unctional te st of the SmartCar d Logo n certifi cate (assumes A cti vClient PKI Onl y 6 .
32 Usage ca se 2 : User authen ticati on f r om c lie nt de v ice to blade P C or Ac ti v e Dir ect ory Server using RDP The f ollo wing steps pr ov ides instr ucti ons fo r performing a f uncti onal test of the SmartCar d L ogon certifi- cate: 1. Log out o f the RDP session .
33 The f ollo w ing steps pro vide ins truc tions f or perfor ming a func tional te st of the C CI SmartCard L ogon cer tif- icat e: 1. Log out o f the MS RDP sessi on . 2. Open the HP S AM c lient w indo w and initiat e a co nnectio n to the HP blade P C or Acti ve Dir ectory Server .
34 Usage cas e 4: Acce ssing sec ur e W eb site Sec ur e W eb access means access to an y W eb se rver w ith SSL v3 and a digit al certificate . The f ollo wing steps pr ov ide instru ctions f or accessing a secur e W eb site using an A cti vI dentity smar t car d thr ough an HP blade P C or Acti ve Dir ectory Server .
35 Usage ca se 5: Us er authenti c ati on using VPN thr ough fir ew all to HP blade PC o r A ct ive D i rec to r y S er ver Instruc tions f or installing and conf igur ing a VPN tunnel w ith a fir ew .
36 8. Select Add a shortc ut for this conn ection to my desktop , and then cli ck Fini sh . Depending upon the conf igur ation o f the VPN tunnel, y ou may hav e to change the confi gur ation of the VPN connectio n. T o change the conf igur ation o f the VPN w indo w: 1.
37 2. Rig h t - cl ic k on t h e VPN connection icon and select Pr operties . Y ou can initiate the VPN connecti on after se tting it up , as fo llo ws: 1.
38 After the connecti on is est ablished , the networ k connectio n icon displa y s in the s y stem tr a y . Usage cas e 6: User a uthenticati on f r om c lient de vi ce using C itri x server A single cli ent can access m ultiple Ci tri x servers in the same ses sion , with Ac tivC lient r unning on each C it- ri x server .
39 3. Select pr operties for the ICA connec tion , c lic k the Logon Information tab, select Smar t card , and then cli ck OK . 4. Double -cli c k the shortcut t o connect to the C itri x server . 5. During logon t o the server , the smar t car d login pr ompt appear s fo r author iz ation .
40 Acr o ny ms ACM —Adapti v e Cr edential Manager . CA —Certifi cate Au thority . CAC —E ither Common Acce ss Car d (for U . S. go vernment) or C orpor ate Access Car d (for enterprise s ystems) . CSP — Cry pto g r aph i c S erv ice P r ov i de r .
41 Serv i ce and Support If y ou wo uld lik e additional inf or mation about A cti vCli ent or other Acti vI dentity pr oducts, plea se r ef er to http://w ww .ac tiv identity .com . F or support issue s, y ou ma y contact y our local Acti vIdentity res eller , or Acti vI dentity cu stomer support b y email at support @actividentity .
Un point important après l'achat de l'appareil (ou même avant l'achat) est de lire le manuel d'utilisation. Nous devons le faire pour quelques raisons simples:
Si vous n'avez pas encore acheté HP (Hewlett-Packard) t5720 c'est un bon moment pour vous familiariser avec les données de base sur le produit. Consulter d'abord les pages initiales du manuel d'utilisation, que vous trouverez ci-dessus. Vous devriez y trouver les données techniques les plus importants du HP (Hewlett-Packard) t5720 - de cette manière, vous pouvez vérifier si l'équipement répond à vos besoins. Explorant les pages suivantes du manuel d'utilisation HP (Hewlett-Packard) t5720, vous apprendrez toutes les caractéristiques du produit et des informations sur son fonctionnement. Les informations sur le HP (Hewlett-Packard) t5720 va certainement vous aider à prendre une décision concernant l'achat.
Dans une situation où vous avez déjà le HP (Hewlett-Packard) t5720, mais vous avez pas encore lu le manuel d'utilisation, vous devez le faire pour les raisons décrites ci-dessus,. Vous saurez alors si vous avez correctement utilisé les fonctions disponibles, et si vous avez commis des erreurs qui peuvent réduire la durée de vie du HP (Hewlett-Packard) t5720.
Cependant, l'un des rôles les plus importants pour l'utilisateur joués par les manuels d'utilisateur est d'aider à résoudre les problèmes concernant le HP (Hewlett-Packard) t5720. Presque toujours, vous y trouverez Troubleshooting, soit les pannes et les défaillances les plus fréquentes de l'apparei HP (Hewlett-Packard) t5720 ainsi que les instructions sur la façon de les résoudre. Même si vous ne parvenez pas à résoudre le problème, le manuel d‘utilisation va vous montrer le chemin d'une nouvelle procédure – le contact avec le centre de service à la clientèle ou le service le plus proche.