Lenovo ThinkVantage (Hardware Password Manager Deployment Bedienungsanleitung

Stöbern Sie online oder laden Sie Bedienungsanleitung nach Notebooks Lenovo ThinkVantage (Hardware Password Manager Deployment herunter. Lenovo ThinkVantage (Hardware Password Manager Deployment Guide) User Manual Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken

Inhaltsverzeichnis

Seite 1 - DeploymentGuide

HardwarePasswordManagerDeploymentGuideUpdated:July,2010

Seite 2

2HardwarePasswordManagerDeploymentGuide

Seite 3

Chapter2.InstallingHardwarePasswordManageronThinkManagementConsoleTouseHPMfunctionality,theLenovoThinkManagementConsolemustbeinstalled.Asyoucongureth

Seite 4 - “Notices”onpage49

PreparingthecoreserverTheHPMcoreserverwillusetheThinkManagementConsole9.0thatisbasedonLANDeskManagementSuite9.0.FormoreinformationaboutLANDeskManageme

Seite 5 - Contents

WhenusingtheWindowsServer2008R2(64-bit)operatingsystem,theMonitoring/Alerts(SNMP)additionalfeaturemustbeinstalledaswell.1.ClickStart➙ServerManager.2.I

Seite 6 - AppendixD.Notices...49

3.RuntheThinkManagementConsoleAutorun.exefromthelocationwheretheinstallationpackagewasextractedto.SelectInstallonthecoreserver.FollowthepromptsintheIn

Seite 7

1.IntheThinkManagementconsole,clickTools➙Conguration➙AgentConguration.2.ClickNewontheAgentCongurationtoolbar,andenteranameforthisagentconguration.

Seite 8

Thenameoftheexecutablelewillbebasedonthenameoftheagentconguration.Theprocesswillruninthebackgroundforaboutaminute.Twoexecutablelesandtwologleswill

Seite 9 - Chapter1.Overview

Chapter3.ManagingHardwarePasswordManagerdeviceswithThinkManagementConsoleTheavailableHardwarePasswordManagerfunctionsintheconsolearedescribedinthefoll

Seite 10

Enrolledusers:AllusersthatareenrolledtoaccesstheHardwarePasswordManagerdevicearelistedonthistab.TheintranetaccountusernameisthenameusedforLDAPuseracco

Seite 11 - ThinkManagementConsole

YoucanmigratefromoneLDAPservertoanotherwithoutlosingdata.IfyoundthatyouneedtouseadifferentserverforLDAPauthentication,enterthecongurationdataforthen

Seite 13

ThistablistsanyRemoveUseractionsthathavebeenperformedontheuser,includingthenameofthedevicefromwhichtheuserwasremovedandthedateandtimeofthelaststatusch

Seite 14 - MigratingtoanewLDAPserver

5.IfyouselectedWithexpiration,selectDuration,andthenselectthebeginningandendtimefortheaccesstoHardwarePasswordManagerdevices;orselectLogincountremaini

Seite 15

•RemoveUser:removesauserfromthelistofusersauthorizedtoaccessaHardwarePasswordManagerdevice.•UpdateClientPolicy:savesanupdatedclientpolicytotheHardware

Seite 16

•Allowmultipleuserstoenrollonasingledevice:morethanoneusercanbeenrolledonadevice.Ifthischeckboxiscleared,onlytherstusertobeenrolledonadevicecanbeanen

Seite 17 - ©CopyrightLenovo2010

1.ClickRemoteActionsandPolicySettingsinthetoolboxorclickT ools➙ThinkVantageHardwarePasswordManager➙RemoteActionsandPolicySettings.2.IntheRemoteActions

Seite 18

ChangingserverpolicysettingsServerpolicysettingsincludevariouswaystomanageuserenrollment,credentials,andclientportalandBIOSsettingsfortheLenovoHardwar

Seite 19

HardwarePasswordManagergroups”onpage12foradescriptionofroles.)So,forexample,ausermightseealloptionsontheHardwarePasswordManagerBIOSmenubutaServiceTech

Seite 20

5.ClickOK.Toassignpermissionstoagroupthatcanbeauthenticatedthroughthenewauthentication,dothefollowing:1.IntheUser'stool,click+onthetoolbarorright

Seite 21 - Managerdevices

20HardwarePasswordManagerDeploymentGuide

Seite 22

Chapter4.HardwarePasswordManagerClientLenovodevicesthatsupportHardwarePasswordManagerneedtoberegisteredwithamanagementserver(referredtoastheHardwarePa

Seite 23

HardwarePasswordManagerDeploymentGuideUpdated:July,2010

Seite 24 - Updatingtheemergencyaccount

Whentheclientisinstalled,itcommunicateswiththeHardwarePasswordManagerservertoauthenticatethedevice.TheclientcanthenrequestHardwarePasswordManagerpolic

Seite 25 - Changingserverpolicysettings

•YoushoulddragthedevicesunderHardwarePasswordManagerDevicestotheActiveDirectoryoreDirectorygrouplistedintheHPMGroupstool.Ifyouradministratorhasenabled

Seite 26

UpdatingcredentialsonaHardwarePasswordManagerdeviceAfterHardwarePasswordManagementisenabledonadevice,youcanaccesstheHardwarePasswordManagerLoginMenuto

Seite 27

Chapter5.DeploymentThischaptercontainsadditionaldeploymentinformationforusingHardwarePasswordManagerdeviceswithHardwarePasswordManager.Itiswrittenfort

Seite 28

–enrolled-returnswhetherthecurrentWindowssystemuserisenrolledintheutility–enabled-returnswhethertheutilityisenabledintheBIOSprogram–show-displaysresul

Seite 29

Thisprocessisinitiatedautomaticallyontheclientsystembasedonpolicy,andadministratorcorporatecredentialsareobtainedfromtheHardwarePasswordManagerservert

Seite 30

28HardwarePasswordManagerDeploymentGuide

Seite 31

Chapter6.ScenariosThischapterdescribesscenariosassociatedwithhardwareandusercongurationchanges.Forthepurposeofthesescenarios,allsystemsareconsideredt

Seite 32

•EnterthehardwareaccountcredentialswithHardwarePasswordManagerAdministratorprivilegestoreleasetheSVP/PAP,suchastheEmergencyAdminaccount.Ifhardwareacco

Seite 33 - Chapter5.Deployment

HardwarePasswordManager,theBIOSwillclearthehardwarepasswordsanddeletethelocalhardwareaccountandSST.Scenario6-ReplacethesystemboardWhenthesystemboardis

Seite 34 - One-touchregistration

Note:Beforeusingthisinformationandtheproductitsupports,readthegeneralinformationinAppendixD“Notices”onpage49.ThirdEdition(July2010)©CopyrightLenovo201

Seite 35 - Pre-registration

Ifthesystemisstillbootable,itisrecommendedtode-registerthesystemwithHardwarePasswordManager.Thiswillclearallthehardwarepasswordsfromthesystem.Installt

Seite 36

structuresarestoredinash,theashutilitieshavebeenupdatedtonotoverwriteHardwarePasswordManagerrelatedstructures.•ForwardFlashing-Whenashingtoanewerve

Seite 37 - Chapter6.Scenarios

Note:TheharddriveshouldnotbeconnectedwhenthesystemisregisteredinHardwarePasswordManagerorelsetheharddiskwillbeassignedanHDP.UserScenariosThissectionde

Seite 38

acompletelydifferentsetofscancodesonanotherkeyboardtype.Forexample,considerthepasswordazw.OnanEnglishkeyboard,thescancoderepresentationis0x1E,0x2C,0x1

Seite 39 - Scenario7-Addaharddiskdrive

36HardwarePasswordManagerDeploymentGuide

Seite 40 - Scenario11-FlashingtheBIOS

AppendixA.SecurityandconvenienceComputersecurityisoftenconsideredmuchmoreimportantmoreconvenience.ThefollowingtableillustrateshowHardwarePasswordManag

Seite 41 - Scenario13-EntertheBIOSsetup

Table1.HardwarePasswordManagerpolicysettings(continued)PolicysettingDescriptionMostsecureMostconvenientCommonEmergencyUserNameandPasswordDenestheemer

Seite 42

AppendixB.DisasterrecoveryBackingupthe9.0coreserverBeforeupgradingorotherwisemodifyingthecurrentHardwarePasswordManagercoreserver,itisimportanttobacku

Seite 43 - Scenario6-BitLocker

1.CreateafoldercalledLANDeskBackuponashareonaseparateserverthatisnotthecoreserver.2.OpenacommandpromptonthecoreserverbyclickingStart➙Run,andlaunchingC

Seite 44

Ifmigratingtoanewdatabase,manyitemscannotbeexported.Takescreenshotsofsuchcongurationssothattheycanbeappliedtothenewcoreserver.Anexampleoftheseinclude

Seite 45

ContentsPreface...vChapter1.Overview...1Chapter2.InstallingHardwarePasswordManageronThinkManagementConsole...3Prerequisites...

Seite 46

42HardwarePasswordManagerDeploymentGuide

Seite 47 - AppendixB.Disasterrecovery

AppendixC.HintsandtipsThefollowingisalistoftipsassociatedwithHardwarePasswordManagerVersion1.0:•Symptom:Bitlockerrecoverymodeistriggeredifyouregistera

Seite 48

Problemdescription:Singlesign-ontoWindowswillnotworkiftheWindowspolicysettingisenabledthatrequirestheusertoPressCtrl+Alt+Deltologin.Thissecuritysettin

Seite 49 - AppendixB.Disasterrecovery41

•Symptom:YoureceivetheFailedtogenerateencryptionkeyerrormessageduringtheHardwarePasswordManagerregistration.Problemdescription:UserswithaWindowsuserna

Seite 50

Ifyouhavealreadyrestoredyoursystem(forexample,lostyourCAPIkeystore),deregisterandreregisterinHardwarePasswordManager.•Symptom:WhenregisteringinHardwar

Seite 51 - AppendixC.Hintsandtips

Solution:TheusermustuseawirednetworkconnectionwhenperforminganintranetloginfromtheBIOS.•Symptom:Receivetheincorrectusernameorpasswordspeciedmessagewh

Seite 52

48HardwarePasswordManagerDeploymentGuide

Seite 53 - AppendixC.Hintsandtips45

AppendixD.NoticesLenovomaynotoffertheproducts,services,orfeaturesdiscussedinthisdocumentinallcountries.ConsultyourlocalLenovorepresentativeforinformat

Seite 54

TrademarksThefollowingtermsaretrademarksofLenovointheUnitedStates,othercountries,orboth:AccessConnectionsLenovoThinkVantageThinkPadThefollowingtermsar

Seite 56

AppendixC.Hintsandtips...43AppendixD.Notices...49Trademarks...50ivHardwarePasswordManagerDeploymentGuide

Seite 58 - Trademarks

PrefaceThisguideisintendedforITadministrators,orthosewhoareresponsiblefordeployingtheLenovo®HardwarePasswordManager™programoncomputersintheirorganizat

Seite 59

viHardwarePasswordManagerDeploymentGuide

Seite 60

Chapter1.OverviewTheLenovoHardwarePasswordManager(HPM)givesanadministratortheabilitytomanagehardwarepasswordsforallregisteredPCdevices.Further,itcreat

Kommentare zu diesen Handbüchern

Keine Kommentare