
Chapter1.Overview
TheLenovoHardwarePasswordManager(HPM)givesanadministratortheabilitytomanagehardware
passwordsforallregisteredPCdevices.Further,itcreatesthenotionofaBIOS-leveluserIDandpassword
fortheendusertouseasasinglesign-onproxy.ThisuserIDandpasswordcanbesynchronizedwiththe
WindowsIDandpasswordfortheuser.TheuseralsohastheoptiontoauthenticatehimselftoBIOSusing
hisngerprint.Whenthedevicepowerson,theuserisaskedforthesecredentials.Ifprovided,thedevice
willlogintheusertohisdesktop.Thismechanismpreservestheuser'sprivacyandmakesitpossibleforhim
tousethedevice,eventhoughhedoesnotknowwhattheactualhardwarepasswordsare.
WhenHPMisinstalled,theLenovoThinkManagementConsolecoreserveractsastheHPMserver—it
managesandauthenticatesHPMdevices.Inaddition,anActiveDirectoryoreDirectoryLDAPserver
functionsastheauthenticationserverforHardwarePasswordManager—theHPMserverchecksuser
credentialsagainstdataontheLDAPserver.
OnLenovoclientdeviceswhichsupportHPM,theadministratorinstallsanagentthatcontainsaHardware
PasswordManagerapplication.Whentheclientdevicepowerson,itcommunicatesthroughUDPport
50001withtheHPMserver.
Aftertheclienthasbootedtotheoperatingsystem,itusestheHardwarePasswordManagerclientapplication
tocommunicatewithaWebserviceontheserver.ThiscommunicationisthroughanHTTPSchannel.
TheadministratorusestheHPMfeaturesintheThinkManagementConsoletomanageHPMdevicesand
createanddeploypoliciestothesedevices.ThesepoliciesdeterminehowHardwarePasswordManager
isimplementedforthedevices;forexample,theadministratorselectswhichuseroptionsareavailable
onHPMdevicesaspartofthepolicydenition.
©CopyrightLenovo2010
1
Comentarios a estos manuales