
Chapter5.Deployment
ThischaptercontainsadditionaldeploymentinformationforusingHardwarePasswordManagerdeviceswith
HardwarePasswordManager.ItiswrittenfortheadministratorwhowillmanagedeviceswiththeHardware
PasswordManagerserverandcongurethesedeviceswithother.Thisguideincludesthefollowingsections:
•“Fingerprintintegration”onpage25
•“SafeGuardEasy/SafeGuardEnterprisecompatibility”onpage26
•“One-touchregistration”onpage26
Fingerprintintegration
HardwarePasswordManagerisfullycompatiblewiththeLenovopreferredngerprintsoftware(Authentec
andUPEK).ForWindowsXP
®
clients,itisrecommendedthattheHardwarePasswordManagerclientis
installedwithouttheHardwarePasswordManagerGINA.Doingsowillallowtheusertoperformsingle
sign-onintoWindowsusingtheirngerprints.ToinstalltheHardwarePasswordManagerclientapplication
withouttheGINA,usethefollowinginstallcommand:
HPMClientInstall.exe/vNOGINA=1
Furthermore,theorderofenrollmentisimportantwhenusingHardwarePasswordManagerwiththe
ngerprintsoftware.FirstregisterinHardwarePasswordManagertosethardwarepasswords.Thenenroll
yourngerprintsforpre-bootaccessusingthengerprintsoftware.Whenyourngerprintsareenrolled
forthersttime,shutdownandrestartthecomputer.Whenyouswipeyourngerprint,theuserloginwill
promptyoutoenteryourcredentialsandlogintothedesktop.Afterrestartingthecomputerforthesecond
time,swipeyourngerprint,andtheBIOSwillreleasetheactualhardwarepasswords.Fromthispointon
youwillbeabletosingle-sign-ontoWindowswithjustaswipeofthengeratpre-boot.
IfyouseethengerprintenrollmentwizardandtheHardwarePasswordManagerregistrationwizard
displayedatthesametimeafteryoulogintoWindows,proceedrsttotheHardwarePasswordManager
registrationwizard.However,ifyouenrollyourngerprintsrstandhavenotalreadysethardware
passwords,youcanstillsynchronizeyourngerprintswiththeHardwarePasswordManageraccount.
Launchthengerprintsoftwareandenablepre-bootauthenticationandsinglesign-on.Thenfollowthe
instructionsbelow:
Ifyouarecreatinganimage,youcanusethefollowingstepsinyourimagetosuppressthengerprint
enrollmentwizarduntilthesystemisregisteredwiththeHardwarePasswordManager:
1.DisabletheFingerprintEnrollmentwizardonstartupbysettingthefollowingvaluesto0.Authentec:
HKEY_CURRENT_USER\Software\AuthenticBiometricSuite\bFingerprintSoftwareStartUp
UPEK:
HKEY_CURRENT_USER\Software\ProtectorSuite\ControlCenter\1.0\ShowOnStartup
2.CreateascriptthatenablestheFingerprintEnrollmentwizardifthesystemisregisteredinHardware
PasswordManagerandthecurrentuserisenrolledinHardwarePasswordManager.Autilityisprovided
intheHardwarePasswordManagerprogramfolderthatITadministratorscanusetoobtainregistration
andenrollmentstatuswithinascript.Thescriptinterfaceisdenedasfollows:
•UtilityName:cmp_util.exe
•Prerequisite:psadd.sysdevicedriver,cmp_server_dll.dll
•Usage:cmp_util.exe<command>where<command>isoneofthefollowing:
–supported*-returnswhethertheutilityissupportedonthecurrentsystem
–registered-returnswhetherthecurrentsystemisregisteredintheutility
©CopyrightLenovo2010
25
Comentarios a estos manuales