Red Hat SYSTEM 8.0 - MANAGING SMART CARDS WITH THE ENTERPRISE SECURITY CLIENT Informacje Techniczne

Przeglądaj online lub pobierz Informacje Techniczne dla Podręczniki do oprogramowania Red Hat SYSTEM 8.0 - MANAGING SMART CARDS WITH THE ENTERPRISE SECURITY CLIENT. Red Hat SYSTEM 8.0 - MANAGING SMART CARDS WITH THE ENTERPRISE SECURITY CLIENT System information Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj

Podsumowanie treści

Strona 1 - Security Client

Red Hat Certificate System 7.3Managing Smart Cardswith the EnterpriseSecurity Client7.3ISBN: N/APublication date: Updated August 5, 2008

Strona 2

• Give a clear title for the bug. For example, "Incorrect command example for setupscript options" is better than "Bad example".We

Strona 3

Overview of the Enterprise SecurityClientThe Enterprise Security Client is a tool for Red Hat Certificate System which simplifiesmanaging smart cards.

Strona 4

such as the Certificate Authority to generate certificates or the Data Recovery Manager toarchive and recover keys.• The Token Key Service (TKS) gener

Strona 5

• The Enterprise Security Client user interface incorporates Mozilla XULRunner technology.XULRunner is a runtime package which hosts standalone applic

Strona 6

• Windows. When right-clicked, the tray icon shows a simple menu with options to ManageSmart Card, which opens the Enterprise Security Client interfac

Strona 7 - 2. Additional Reading

Installing the Enterprise SecurityClientThe Enterprise Security Client is packaged as a set of installation executables or RPMs andother files that ar

Strona 8 - 3. Examples and Formatting

The preferred method of obtaining RPMs is using the up2date command-line utility, as follows:# up2date escIf the up2date command completes successfull

Strona 9 - 4. Giving Feedback

1. Unplug all USB tokens.2. Stop the Enterprise Security Client.3. Log in as root, and use rpm -ev to remove the Enterprise Security Client RPMs in th

Strona 10 - 5. Revision History

Figure 2.1. Launching the Installation Wizard3. The wizard displays the list of packages that will be installed.Chapter 2. Installing the Enterprise S

Strona 11

Figure 2.2. Launching the Installation Wizard on Windows4. The wizard prompts for the installation directory for the Enterprise Security Client. Thede

Strona 12 - 2. Features

This guide is for regular users of Certificate System subsystems. It explains how to managepersonal certificates and keys using the Enterprise Securit

Strona 13

Figure 2.3. Specifying the Installation Directory5. The wizard prompts for the Start Menu directory for the Enterprise Security Client. Thedefault dir

Strona 14

Figure 2.4. Specifying the Start Menu Directory6. Proceed through the Enterprise Security Client installation wizard. Click Install to begininstalling

Strona 15 - 2. Supported Smart Cards

Figure 2.5. Ready to Start the Installation7. When the installation has completed, the Enterprise Security Client will prompt the user toinsert a toke

Strona 16

Figure 2.6. Launching the Smart Card Manager8. Click Finish to complete the installation.Installing the Client13

Strona 17 - 4.1. Installing the Client

Figure 2.7. Completing the Installation4.2. Uninstalling the Client1. Unplug all USB tokens.2. Stop the Enterprise Security Client.3. Open the Control

Strona 18

The Mac Enterprise Security Client packages are available in the Downloads area of RedHat Network. There are two channels for the packages; Mac client

Strona 19 - Installing the Client

b. Read the Software License Agreement, and click Continue if you accept the terms.c. Select the installation destination.Figure 2.9. Specifying the i

Strona 20 - Red Hat

Figure 2.10. Launch Installatione. Enter the administrator password, and click OK to start the installation.Figure 2.11. Entering the Administrator Pa

Strona 21

f. When the installation is complete, click Close.Figure 2.12. Coolkey Software Package installation in progressWhen the process is complete, the e-ga

Strona 22

Using the Enterprise Security ClientThe following sections contain basic instructions on using the Enterprise Security Client fortoken enrollment, for

Strona 23

Red Hat Certificate System 7.3: Managing Smart Cards withthe Enterprise Security ClientCopyright © 2008 Red Hat, Inc.Copyright © 2008 Red Hat. This ma

Strona 24 - Client on Mac OS X

op.format.tokenKey.issuerinfo.enable=trueop.format.tokenKey.issuerinfo.value=http://server.example.com2.1. About Phone Home ProfilesThe Enterprise Sec

Strona 25

/Applications/ESC.app/Contents/Resources/defaults/preferences.3. Add the global Phone Home parameter line. For example:pref("esc.global.phone.hom

Strona 26

• The preferred method is that the information is burned onto the token at the factory. When thetokens are ordered from the manufacturer, the company

Strona 27

<ServiceInfo><IssuerName>Example Corp</IssuerName><Services><Operation>http://tps.example.com:12443/nk_service ## TPS se

Strona 28 - 5.2. Uninstalling the Client

controls the cryptographic keys belonging to the certificates.Certificate System CSP.The Certificate System CSP is designed to provide cryptographic f

Strona 29 - 2. Phone Home

1. Ensure that the Enterprise Security Client is running.2. Insert an uninitialized smart card, pre-formatted with the Phone Home information for theT

Strona 30

Figure 3.2. Smart Card Enrollment PageThe above illustration shows the default enrollment UI included with the TPS server. This UIis a standard HTML f

Strona 31

LDAP PasswordThis is the password corresponding to the user ID entered; this can be a simple passwordor a customer number.NOTEThe LDAP user ID and pas

Strona 32

Figure 3.3. Smart Card Enrollment Success Message5. Customizing the Smart Card Enrollment UserInterfaceRed Hat Certificate System (specifically the TP

Strona 33 - CAPI Store

The following is an extract from the default UI HTML file, and it includes comments on how youmight customize it to suit your requirements.<html>

Strona 34 - 4. Smart Card Auto Enrollment

Red Hat Certificate System 7.3

Strona 35

<td> </td><td><input type="text" id="snametf"value=""></td><td> </td><td>

Strona 36

Figure 3.4. Manage Smart Cards Page6.1. Formatting the Smart CardWhen you format a smart card, it is reset to the uninitialized state. This removes al

Strona 37

status as UNINITIALIZED.6.2. Resetting a Smart Card PasswordIf a user forgets the password for a smart card after the card is enrolled, it is possible

Strona 38 - Interface

1. Insert a supported smart card into the computer. Ensure that the card is listed in the ActiveSmart Cards table.2. Select the card from the list, an

Strona 39

2. Click Enroll to display the Password dialog.NOTEThis button is active only if the inserted card is unenrolled.3. Enter a new key password in the En

Strona 40 - 6. Managing Smart Cards

The Smart Card Manager, in conjunction with the latest TPS Server software, now supports aspecial "security officer" mode of operation. This

Strona 41

1. Open the Smart Card Manager installation directory.On Microsoft Windows, this is C:/Program Files/Red Hat/ESC/esc.exe.On Red Hat Enterprise Linux,

Strona 42 - 6.3. Viewing Certificates

./esc -secmode http://test.host.com:7888/cgi-bin/so/enroll.cgiThis opens the security officer enrollment page.2. In the Security Officer Enrollment wi

Strona 43 - 6.4. Enrolling Smart Cards

1. Click Format SO Card. Because the security officer card is already inserted, the followingscreen displays:2. Click Format to begin the operation.Wh

Strona 44 - 7. Security Officer Mode

new or temporary cards, formatting cards, and setting the Phone Home URL.• Section 7.3.1, “Opening the User's Smart Card Interface”• Section 7.3.

Strona 45

About This Guide ... vii1. What Is in This Guide ..

Strona 46

This opens the security officer welcome page.NOTEEnsure that there is a valid and enrolled security officer card plugged into thecomputer. A security

Strona 47

1. Click the Enroll New Card link to display the Security Officer Select User page.2. Enter the LDAP name of the user who is to receive a new smart ca

Strona 48 - 7.3. Managing Regular Users

3. Click Format. The result will be a card with the new phone home information stored on thecard.8. Diagnosing ProblemsThe Enterprise Security Client

Strona 49

Figure 3.6. The Smart Card Manager Diagnostics Information ScreenInformation Displayed on the Diagnostics Information Screen.The Diagnostics Informati

Strona 50 - 7.3.2. Enrolling a New User

For each card detected, the following information is displayed:• The version of the applet running on the smart card.• The alpha-numeric ID of the sma

Strona 51

Using Enterprise Security ClientKeys for SSL Client Authenticationand S/MIMEAfter a token is enrolled, the token can be used for SSL client authentica

Strona 52 - 8. Diagnosing Problems

3. If the CA is not yet trusted, download and import the CA certificate.a. Open the SSL End Entity page on the CA. For example:https://example.com:944

Strona 53

The certificates can be used for SSL.2. S/MIME ApplicationsTo enable S/MIME on mail applications such as Mozilla Thunderbird:1. In Mozilla Thunderbird

Strona 54 - Example Corp

6. In the Encryption of the Security panel, click Select to choose the certificate to encrypt anddecrypt messages.Chapter 4. Using Enterprise Security

Strona 55 - Support/CoolKey/PKCS11

Appendix A. Enterprise SecurityClient ConfigurationPreviously, Enterprise Security Client relied on an application-specific configuration file.Enterpr

Strona 56

1. Configuration ...492. Enterprise Security Client Mac T

Strona 57 - 2. S/MIME Applications

Platform LocationRed Hat Enterprise Linux ~/.redhat/escMacintosh ~/Library/ApplicationSupport/ESC/ProfilesTable A.2. Location of Enterprise Security C

Strona 58

Example A.1. Example Configuration File2. Enterprise Security Client Mac TokenDThe TokenD software installed on a Macintosh computer provides a link b

Strona 59 - Client Configuration

Filename Purposeconfig.xul Contains the code for the configuration UI.esc_browser.xul Contains the code for hosting the externalHTML Smart Card Manage

Strona 60

function EnrollCoolKey(keyType, keyID, enrollmentType, screenname,pin,screennamepwd,tokencode){try {netkey.EnrollCoolKey(keyType, keyID, enrollmentTyp

Strona 61 - Functionality

File or Directory Purposeesc.exe The executable which launches EnterpriseSecurity Client in XULRunner.xulrunner\ Privately-deployed XULRunner bundle.T

Strona 62 - 4. Quick Javascript UI Guide

File or Directory Purposeapplication.ini Enterprise Security Client XULRunnerapplication configuration file.components/ Enterprise Security Client XPC

Strona 66

About This GuideThe Enterprise Security Client is a simple user interface which formats and manages smartcards. This guide is intended for everyday us

Strona 67

• Certificate System Administration Guide explains how to install, configure, and use Red HatCertificate System.Additional Certificate System informat

Strona 68

NOTEA note provides additional information that can help illustrate the behavior of thesystem or provide more detail for a specific issue.TIPA tip is

Komentarze do niniejszej Instrukcji

Karolin 31 Jan 2024 | 07:19:26

Hey, Are you tired of missing out on potential profits in the volatile world of cryptocurrency trading? Look no further! I've got something special for you. Introducing the "GOD Trading Strategies" e-book, your ultimate guide to mastering successful crypto trading. For a limited time, you can get this comprehensive guide for just $19.95 instead of the regular $49. That's a whopping 60% discount! Here's what you get with "GOD Trading Strategies": In-depth insights into successf