Novell SecureLogin 7.0 SP3 Administration Guide

  • Hello! I am an AI chatbot trained to assist you with the Novell SecureLogin 7.0 SP3 Administration Guide. I’ve already reviewed the document and can help you find the information you need or explain it in simple terms. Just ask your questions, and providing more details will help me assist you more effectively!
www.novell.com/documentation
pcProx Guide
SecureLogin 7.0 SP3
April, 2012
Legal Notices
Novell,Inc.,makesnorepresentationsorwarrantieswithrespecttothecontentsoruseofthisdocumentation,andspecifically
disclaimsanyexpressorimpliedwarrantiesofmerchantabilityorfitnessforanyparticularpurpose.Further,Novell,Inc.,
reservestherighttorevisethispublicationandtomakechangestoitscontent,at
anytime,withoutobligationtonotifyany
personorentityofsuchrevisionsorchanges.
Further,Novell,Inc.,makesnorepresentationsorwarrantieswithrespecttoanysoftware,andspecificallydisclaimsany
expressorimpliedwarrantiesofmerchantabilityorfitnessforanyparticularpurpose.Further,Novell,Inc.,reservestheright
to
makechangestoanyandallpartsofNovellsoftware,atanytime,withoutanyobligationtonotifyanypersonorentityof
suchchanges.
AnyproductsortechnicalinformationprovidedunderthisAgreementmaybesubjecttoU.S.exportcontrolsandthetrade
lawsofothercountries.Youagreeto
complywithallexportcontrolregulationsandtoobtainanyrequiredlicensesor
classificationtoexport,reexportorimportdeliverables.YouagreenottoexportorreexporttoentitiesonthecurrentU.S.
exportexclusionlistsortoanyembargoedorterroristcountriesasspecifiedintheU.S.
exportlaws.Youagreetonotuse
deliverablesforprohibitednuclear,missile,orchemicalbiologicalweaponryenduses.SeetheNovellInternationalTrade
ServicesWebpage(http://www.novell.com/info/exports/)formoreinformationonexportingNovellsoftware.Novellassumes
noresponsibilityforyourfailuretoobtainanynecessaryexportapprovals.
Copyright©20092012
Novell,Inc.Allrightsreserved.Nopartofthispublicationmaybereproduced,photocopied,storedon
aretrievalsystem,ortransmittedwithouttheexpresswrittenconsentofthepublisher.
Novell,Inc.,hasintellectualpropertyrightsrelatingtotechnologyembodiedintheproductthatisdescribedinthis
document.Inparticular,and
withoutlimitation,theseintellectualpropertyrightsmayincludeoneormoreoftheU.S.patents
listedontheNovellLegalPatentsWebpage(http://www.novell.com/company/legal/patents/)andoneormoreadditional
patentsorpendingpatentapplicationsintheU.S.andinothercountries.
Novell, Inc.
1800 South Novell Place
Provo, UT 84606
U.S.A.
www.novell.com
OnlineDocumentation:Toaccessthelatestonlinedocumentation
forthisandotherNovellproducts,seetheNovell
DocumentationWebpage(http://www.novell.com/documentation).
Novell Trademarks
ForNovelltrademarks,seetheNovellTrademarkandServiceMarklist(http://www.novell.com/company/legal/trademarks/
tmlist.html).
Third-Party Materials
Allthirdpartytrademarksarethepropertyoftheirrespectiveowners.
Contents 3
Contents
About This Guide 5
1 Installing and Using pcProx 7
1.1 Software Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .7
1.1.1 Client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
1.1.2 Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
1.1.3 Novell iManager. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
1.2 Installing PcProx NMAS Login Server Method. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
1.3 Installing the iManager Plug-In for pcProx. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
2 Configuring pcProx for Identification (Login ID) 11
2.1 Setting Up the Hardware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11
2.2 Configuring the Workstation to Scan the pcProx Card Through Plug-In . . . . . . . . . . . . . . . . . . . . . . 11
2.3 Adding a pcProx Card as a Login ID . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11
2.3.1 Adding by Scanning the Card . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .12
2.3.2 Adding Manually . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
2.4 Preventing the Login ID Plug-In from Executing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .12
2.5 Deleting a pcProx Card Used as a Login ID . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .12
3 Configuring pcProx for Authentication 15
3.1 Setting Up the Hardware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .15
3.2 Installing the Login Server Method for pcProx in eDirectory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .15
3.3 Creating and Authorizing Login Sequences. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .15
3.4 Configuring the Workstation to Scan the pcProx Card Through Plug-In . . . . . . . . . . . . . . . . . . . . . . 16
3.5 Configuring the Login Method . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
3.5.1 Adding a Certificate . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
3.5.2 Manually Setting a pcProx Card for User . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
3.5.3 Removing a pcProx Card from a User. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .17
3.5.4 Allowing a User to Self-Enroll the Card ID. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .18
4 Registry Keys and Values for the pcProx Method 19
4.1 Registry Keys and Values for the pcProx Plug-In . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .19
4 pcProx Guide
About This Guide 5
About This Guide
Thisguidecontainsthefollowingsection:
Chapter 1,“InstallingandUsingpcProx,”onpage 7
Chapter 2,“ConfiguringpcProxforIdentification(LoginID),”onpage 11
Chapter 3,“ConfiguringpcProxforAuthentication,”onpage 15
Chapter 4,“RegistryKeysandValuesfor thepcProxMethod,”onpage 19
Audience
Thisguideisintendedforadministrators.
Feedback
Wewanttohearyourcommentsandsuggestionsaboutthismanualand theotherdocumentation
includedwiththisproduct.PleaseusetheUserCommentsfeatureatthebottomofeachpageofthe
onlinedocumentation,orgotowww.novell.com/documentation/feedback.htmlandenteryour
commentsthere.
Documentation Updates
ForthemostrecentversionofthepcProxGuide,visittheNovellSecureLoginDocumentat ionWebsite
(http://www.novell.com/documentation/securelogin70).
Additional Documentation
FordocumentationonotherNovellSecureLogindocumentation,seetheNovellSecureLogin
DocumentationWebsite(http:// www.novell.com/documentation/securelogin70).
TheotherdocumentsavailablewiththisreleaseofNovellSecureLoginare:
GettingStarted
NovellSecureLoginReadme7.0.2
NovellSecureLoginQuickStartGuide
NovellSecureLoginOverviewGuide
Installation
NovellSecureLoginInstallationGuide
Administration
NovellSecureLoginAdministration
Guide
NovellSecureLoginApplicationDefinitionWizardAdministrationGuide
NovellSecureLoginCitrixandTerminalServicesGuide
6 pcProx Guide
EndUser
NovellSecureLoginUserGuide
Reference
NovellSecureLoginApplicationDefinitionGuide
1
Installing and Using pcProx 7
1
Installing and Using pcProx
TheNMASLoginMethodandLoginIDpluginforpcProxprovidestoyoutwowaystoemploya
proximitycardasameansofauthenticationtothenetwork.ItenablesyoutosetupapcProxcardID
toactlikeaconventionalpasswordtoauthenticatetheusertothe
network.Thismethodissimilarto
theloginmethodsprovidedforusewithNMAS.
IMPORTANT:pcProxshouldnotbetheonlyfactor usedforauthentica tion,becausethismightpose
securityissues.Itshouldbeusedwithasecondfactor,suchasabiometricdevice,asmartcard,ora
password.
TheNMASloginIDpluginenablestheorganizationstoutilizetheirproximitycardstoquicklyand
easilyidentifyusers.Forexample,insteadofrequiringusertospecifytheiruserIDswhenthey
authenticate,youcanrequireuserstopresenttheirproximitycardsforidentificationalongwith
anotherformof
authentication,suchasapasswordorabiometricdevicetoauthenticatetheusers.
Thisloginmethodsupportstwotypesofproximitycards:
HIDCards
AIRCards
1.1 Software Requirements
EnsurethatyouhavemetthefollowingrequirementsbeforeinstallingthepcProx:
1.1.1 Client
MicrosoftWindowsVistaSP1,32bitand64bit.
MicrosoftVistaUltimate
MicrosoftVistaEnterprise
MicrosoftVistaBusiness
MicrosoftWindowsServer2003,32bit.
MicrosoftWindowsServer2008,32bitand64bit.
MicrosoftWindowsXPProfessionalSP2andSP3,32bit
NMASClient3.4orlaterforMicrosoftWindows
XP
NMASClient3.4forMicrosoftWindowsVista
TheUSBreadersmusthavefirmware3.20oraboveforstandardcards(26bit)and6.30orabove
forcardswiththeIDoflengthgreaterthan26bits.
8 pcProx Guide
1.1.2 Server
HavethefollowingserverontheworkstationsthatusespcProx:
NovelleDirectory8.8.5,8.8.4,or8.8.3.
NMASServer‐theversionbundledwiththeeDirectoryversionyouareusing.
1.1.3 Novell iManager
NovelliManager2.7.2and2.7.1
1.2 Installing PcProx NMAS Login Server Method
NOTE:InstallingtheNMASLoginServerMethodforpcProxbyusingtheiManagerpluginfor
NMASwithiManager2.6failstoextendtheschemadefinitionoftheUserobjectclasswiththe
sasPcProxIDattribute.ThismeansthatyouareunabletoassociatethepcProxcardIDwiththeUser
objectforidentification.
Toresolvetheissue,youmustmanuallyaddthesasPcProxIDattrib utetotheuserobjectclassby
usingtheiManagerschemaplugin.
1 LaunchandaccessiManager.
FordetailedinformationonaccessingiManager,seetheNovellDocumentationWebsite.(http://
www.novell.com/documentation/imanager20/imanager20/data/agrxfn3.html)
2 Specifytheusername,password,andtheeDirectorytreename,thenlogintoeDirectory.
Youcan substitutetheIPaddressofaneDirectoryserverforthetreename.
TohavefullaccesstoallNovelliManagerfeatures,youmustloginasauserwithadmin
equivalentrightstothetree.
3 SelectNMAS>NMASLoginMethods>New. TheNewLoginMethodpageopens.
4 Browseandlocatethe
pcprox.zip
foundin
\Nmas\NmasMethods\Novell\pcProx\pcProx.zip
ontheNovellSecureLogininstallerpackage.
NOTE:TheinstallationofNMASLoginServerMethodforpcProx:
CreatesaloginsequencecalledNMASProximityCard.
InstallstheiManagerpluginforpcProx.
1.3 Installing the iManager Plug-In for pcProx
1 LaunchandaccessiManager.
FordetailedinformationonaccessingiManager,seetheNovellDocumentationWebsite.(http://
www.novell.com/documentation/imanager27/imanager_admin_27/index.ht m l?page=/
documentation/imanager27/imanager_admin_27/da ta/bsxrjzp.html)
2 Specifytheusername,password,andtheeDirectorytreename,thenlogintoeDirectory.
Youcan substitutetheIPaddressofaneDirectoryserverforthetreename.
Installing and Using pcProx 9
TohavefullaccesstoallNovelliManagerfeatures,youmustloginasauserwithadmin
equivalentrightstothetree.
3 ClicktheConfiguretab.
4 ClickPluginInstallation,thenselectAvailableNovellPluginModules.
5 ClickAdd.TheCopyPluginFilepageisdisplayed.
6 ClickBrowseandlocatethepcprox.npmfile,whichisavailableiniManager\2.7folderofthe
NovellSecureLogin7.0SP1installerpackage.
7 SelectthepcproxpluginyouwanttoinstallandclickInstall.Yousee aconfirmationmessage
afterthepluginissuccessfullyinstalled.
8 ClickClose.
9 RestartTomcataftertheinstallationiscomplete.Thismighttakeseveralminutes.
ForinformationoninstallationandRoleBasedServices(RBS)configuration,visittheNovell
DocumentationWebpage(http://www.novell.com/documentation/imanager27/index.html)
NOTE:ScanningthepcPRoxcardIDandassociatingitwiththeusersforeitheridentificationor
authenticationworksonlywiththeiManagerserverrunningonWindows.
ForenrollingthepcProxIDfortheusers,youcanalsousemobileiM anager2.7
10 pcProx Guide
2
Configuring pcProx for Identification (Login ID) 11
2
Configuring pcProx for Identification
(Login ID)
AfteryouhaveinstalledNMASandtheloginmethodsoftware,configurepcProxforidentification,
thatis,configureasaloginID.
Section 2.1,“SettingUptheHardware,”onpage 11
Section 2.2,“ConfiguringtheWorkstationtoScanthepcProxCardThroughPlugIn,”on
page 11
Section 2.3,AddingapcProxCardasaLoginID,”
onpage 11
Section 2.4,“PreventingtheLoginIDPlugInfromExecuting,”onpage 12
Section 2.5,“DeletingapcProxCardUsedasaLoginID,”onpage 12
2.1 Setting Up the Hardware
TheworkstationthatusesthepcProxloginmethodmusthaveapcProxcardreader.
NOTE:SpecifytheCOMportnumberorUSBduringthemethodinstallation.
2.2 Configuring the Workstation to Scan the pcProx Card
Through Plug-In
1 Run
pcprox.reg
availableinthe
iManager
folderintheNovellSecureLogin7.0SP1installer
package.
2.3 Adding a pcProx Card as a Login ID
YoucanaddapcProxcardtobeusedasaloginIDintwoways:
Section 2.3.1,AddingbyScanningthe Card,”onpage 12
Section 2.3.2,AddingManually,”onpage 12
NOTE
pcProxidentificationfailsinLDAPCredentialProvidermodebecausepcProxcachesthe
certificateintheregistrytoidentifythecardontheserver(thatis,eDirectory)itisregistered.If
youchangetheserver,pcProxdoesnothavethelogictoverifyifthecertificateisvalidornot.
pcProx
treatsthecertificatefromthenewserverasinvalid.Ittriestoidentifywiththiscertificate
andso,theidentificationfails.
12 pcProx Guide
Toresolvethisissue,youmustdeletethe certificateregistryvaluewheneveryouchangethe
identificationserver(eDirectory).
Youmust deletetheTrustedCertificate0,whichislocatedinthe
HKEY_LOCAL_MACHINE\SOFTWARE\Novell\NMAS\MethodData\pcProx\ID\LDAPServers
Identificationmightalsofailifthecertificateiscorrupted.Insuchascenario,deletetheold
cachedcertificatefromtheregistryandaddnewcertificate.
2.3.1 Adding by Scanning the Card
1 LogintoiManager.
2 Fromtheleftpane,selectNMAS>NMASUsers.
3 IntheUsernamefieldspecifytheobjectname,thenclickOK.
4 SelectthePcProxtab,thenselectPcProxId entification.
5 PlacethecardonthecardreaderandclickScan&AddID.Afterthecardisscanned,thecardʹsID
appearsintheCardIDfield.
6 ClickApplytosavethechanges.
7 ClickOKtoexit.
2.3.2 Adding Manually
1 LogintoiManager.
2 Fromtheleftpane,selectNMAS>NMASUsers.
3 IntheUsernamefieldspecifytheobjectname,thenclickOK.
4 SelectthePcProxtab,thenselectPcProxId entification.
5 IntheCardIDfield,specifythepcProxcardIDinhexadecimalformat.
6 ClickAddIDtoaddtheID.
7 ClickApplytosave.
8 ClickOKtoexit.
2.4 Preventing the Login ID Plug-In from Executing
AusercanpreventtheIDpluginfromexecutingbyholdingtheCtrlkeywhenthelogindialogbox
isdisplayed.Thisisausefulfeatureforuserswhoneedtooccasionallychangetheirlogin
information,forexample,ifauserneedstologintoadifferenttreeor
server,oruseadifferent
NMASsequence.
2.5 Deleting a pcProx Card Used as a Login ID
1 LogintoiManager.
2 Fromtheleftpane,selectNMAS>NMASUsers.
3 IntheUsernamefieldspecifytheobjectname,thenclickOK.
4 SelectthePcProxtab,thenselectPcProxId entification.
Configuring pcProx for Identification (Login ID) 13
5 SelecttheIDtoberemovedfromthepcProxIDlist.
6 SelectDelete.
7 ClickOKorApplytosavethechanges.
14 pcProx Guide
3
Configuring pcProx for Authentication 15
3
Configuring pcProx for Authentication
Section 3.1,“SettingUptheHardware,”onpage 15
Section 3.2,“InstallingtheLoginServerMethodforpcProxineDirectory,”onpage 15
Section 3.3,“CreatingandAuthorizingLoginSequences,”onpage 15
Section 3.4,“ConfiguringtheWorkstationtoScanthepcProxCardThroughPlugIn,”on
page 16
Section 3.5,“ConfiguringtheLoginMethod,”onpage 16
3.1 Setting Up the Hardware
Theworkstationtha tusesthepcProxloginmethodmusthaveapcProxcardreader.
3.2 Installing the Login Server Method for pcProx in eDirectory
SeeSection 1.2,“InstallingPcProxNMASLoginServerMethod,”onpage 8
3.3 Creating and Authorizing Login Sequences
Forinformationonhowtocreateandauthorizeloginsequences,seetheNMASAdministration
GuideattheNovellDocumentationWebsite.(http://www.novell.com/documentation/lg/nmas20/
index.html)
NOTE:ThistaskisnotnecessaryfortheIDplugin
16 pcProx Guide
3.4 Configuring the Workstation to Scan the pcProx Card
Through Plug-In
1 Run
pcprox.reg
availableinthe
iManager
folderintheNovellSecureLogin7.0SP1installer
package.
3.5 Configuring the Login Method
AfteryouhavesuccessfullyinstalledtheloginmethodforpcProx,youcanmanageitthrough
iManager.
ReferthefollowingsectionstomanagetheloginmethodforpcProxthroughiManager:
Section 3.5.1,AddingaCertificate,”onpage 16
Section 3.5.2,“ManuallySetti ngapcProxCardforUser,”onpage 17
Section 3.5.3,“RemovingapcProxCardfrom
aUser,”onpage 17
Section 3.5.4,“A l l o w i n g aUsertoSelfEnrolltheCardID,”onpage 18
3.5.1 Adding a Certificate
AfteryouhaveinstalledthepcProxpluginontheserversunningiManager,youmustimport
certificatestotheworkstationrunningiManager.Importingthecertificateassociatestheproximity
cardtotheuserforauthentication.
1 ExportthecertificatefromeDirectoryusingiManager
1a LogintoiManager.
1b InRolesandTasks,clickDirectoryAdministration>ModifyObject.
1c UsetheObjectSelectortoselecttheSSLCertificateDNScertificate.
1d ClickOK.
1e VerifyifNovellCertificateServerPluginsforiManagerisinstalledornot.Ifitisnotinstalled
it,installit.
1f InRolesandTasks,clickNovellCertificateAccess>ServerCertificates.
1g SelectSSLCertificateDNS>Export.
1h FromtheCertificatedropdownlist,selectSSLCertificateDNS.
1i IfExportprivatekeyisselected,deselectitandselecttheexportformatas
.DER
1j ClickNextandspecifythepathtosavethefile.
2 ImportingthecertificatetoJREkeystoreusedbyiManager
2a Runthecom mandpromptandchangethedirectorytoJREpath thatisusedby iMa nager.
2b NavigatetobindirectoryunderJREdirectory.
TheJREpathforworkstationiManagerrunningon,
Windows:
<iManager extracted directory>\bin\windows\java\jre
Linux:
<iManager extracted directory>/bin/linux/java/jre
ThedefaultpathforiManagerserverinstallationis,
Windows:
C:\Program Files\novell\jre
Configuring pcProx for Authentication 17
Linux:
opt\novell\jdk\jre
2c Runfollowingcommand.
<Prompt>keytool -import -file <imported certificate file path> -alias
<alias to identify the server> -keystore..\lib\security\cacerts -storepass
changeit
NOTE:aliasisoptional.
Example
Usethefollowingcommandtoimportthecertificate(cert.der)fromC:\,underthe
NSL611TREEtree,
C:\Program Files\novell\jre\bin>keytool -import -file c:\cert.der -alias
NSL611TREECERT -keystore ..\lib\security\cacerts-storepass changeit
2d Iftheimportiscorrect,pressY.
2e RestartiManager
3.5.2 Manually Setting a pcProx Card for User
1 LaunchandaccessiManager.
FordetailedinformationonaccessingiManager,seetheNovellDocumentationWebsite.(http://
www.novell.com/documentation/imanager20/imanager20/data/agrxfn3.html).
2 Specifytheusername,password,andtheeDirectorytreename,thenlogintoeDirectory.
3 YoucansubstitutetheIPaddressofaneDirectoryserverforthetreename.
TohavefullaccesstoallNovelliManagerfeatures,youmustloginasauserwithadmin
equivalentrightstothetree.
4 Fromtheleftpane,selectNMAS>NMASUsers.
5 IntheUsernamefield,specifytheobjectname,thenclickOK.
6 SelectthePcProxtab,thenselectPcProxAuthentication.
7 Fromthetaskoptions,selectSetCardID.
IfyouwanttoscanthepcProxcardID,placethecardonthecardreader,thenclickScanID.
Afterthescanningiscomplete,thecard’sIDappearsintheScanIDfield.
Youcan alsomanuallyspecifythecardIDnumber
intheCardIDfield.
8 ClickOKorApplytosaveyourset tings.
3.5.3 Removing a pcProx Card from a User
1 LogintoiManager.
2 Fromtheleftpane,selectNMAS>NMASUsers.
3 IntheUsernamefieldspecifytheobjectname,thenclickOK.
4 SelectthePcProxtab,thenselectPcProxAuthentication.
5 Fromthetaskoptions,selectRemoveCardID.
18 pcProx Guide
6 ClickOKorApplytosavethechanges.
TheselectedcardIDisremoved.
3.5.4 Allowing a User to Self-Enroll the Card ID
1 LogintoiManager.
2 Ontheleftpane,selectDirectoryAdministration>ModifyObject.
3 ClicktheiconadjacenttotheObjectnamefield.
4 UndertheContents,selectSecurity>AuthorizedLoginMethods>NMASProximityCard.
5 ClickOK.
6 ClickPcProxtab,thenselectEnableSelfEnrollment.
7 ClickOKorApplytosavethechanges.
4
Registry Keys and Values for the pcProx Method 19
4
Registry Keys and Values for the pcProx
Method
Key:
HKLM\SOFTWARE\Novell\NMAS\MethodData\pcProx
Value:
comid
Type:
DWORD
Data:Thecomportthatthereaderisattachedto.Avalueof‐1(0xffffffff)signifiesUSB.
Value:
retries
Type:
DWORD
Data:SpecifiesthenumberofconsecutivefailuresthatthereadermustgetbeforereportingaDevice
RemovalEventtoSecureWorkstation.ThisismostusefulwhentheAIRIDreadersareusedinareas
withconsiderableinterference.
4.1 Registry Keys and Values for the pcProx Plug-In
Key:
HKLM\SOFTWARE\Novell\NMAS\pcProx\ID
Value:
Sequence
Type:
String
Data:ThenameofthesequencetobeusedwhenauserIDisobtainedfromthedevice.Ifthisvalue
existsbuthasnodata,thentheuserʹsdefaultsequenceisused.
Value:
Tree
Type:
String
Data:ThetreenametobeusedwhenauserIDisobtainedfromthedevice.
Value:
Server
Type:
String
Data:TheservertobeusedforloginwhenauserIDisobtainedfromthedevice.
Key:
HKLM\SOFTWARE\Novell\NMAS\<<Method Name>>\ID\LDAPServers
ThiskeycontainsanorderedlistofLDAPserversthatisqueriedfortheusernamewhendataisread
fromthedevice.
20 pcProx Guide
CorrespondingtoeachoftheLDAPserversinthelist,theadministratorscanspecifythefullpathof
thetrustedrootcertificatefileasthedataforthevaluewiththeprefix
TrustedCertificateFile
and
theservernumberasthesuffix.Forexample,avalue
TrustedCertificateFile0
canhave
C:\Certificates\TrustedRoot-acme.com.der
asthedata.
Ifthesevaluesarenotpresent,pcProxLCMautomaticallyimportsandwritescontentsofthetrusted
rootcertificateunderthiskeywithaprefixof
TrustedCertificate
andasuffixofthe
correspondingservernumber.Forexample,thecontentsofthetrustedrootcertificateoftheserver
withthenumber
0
hasthevalueas
TrustedCertificate0
.
/