Lenovo ThinkVantage (Hardware Password Manager Deployment Manuel d'utilisateur

Naviguer en ligne ou télécharger Manuel d'utilisateur pour Carnets de notes Lenovo ThinkVantage (Hardware Password Manager Deployment. Lenovo ThinkVantage (Hardware Password Manager Deployment Guide) User Manual Manuel d'utilisatio

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer

Résumé du contenu

Page 1 - DeploymentGuide

HardwarePasswordManagerDeploymentGuideUpdated:July,2010

Page 2

2HardwarePasswordManagerDeploymentGuide

Page 3

Chapter2.InstallingHardwarePasswordManageronThinkManagementConsoleTouseHPMfunctionality,theLenovoThinkManagementConsolemustbeinstalled.Asyoucongureth

Page 4 - “Notices”onpage49

PreparingthecoreserverTheHPMcoreserverwillusetheThinkManagementConsole9.0thatisbasedonLANDeskManagementSuite9.0.FormoreinformationaboutLANDeskManageme

Page 5 - Contents

WhenusingtheWindowsServer2008R2(64-bit)operatingsystem,theMonitoring/Alerts(SNMP)additionalfeaturemustbeinstalledaswell.1.ClickStart➙ServerManager.2.I

Page 6 - AppendixD.Notices...49

3.RuntheThinkManagementConsoleAutorun.exefromthelocationwheretheinstallationpackagewasextractedto.SelectInstallonthecoreserver.FollowthepromptsintheIn

Page 7

1.IntheThinkManagementconsole,clickTools➙Conguration➙AgentConguration.2.ClickNewontheAgentCongurationtoolbar,andenteranameforthisagentconguration.

Page 8

Thenameoftheexecutablelewillbebasedonthenameoftheagentconguration.Theprocesswillruninthebackgroundforaboutaminute.Twoexecutablelesandtwologleswill

Page 9 - Chapter1.Overview

Chapter3.ManagingHardwarePasswordManagerdeviceswithThinkManagementConsoleTheavailableHardwarePasswordManagerfunctionsintheconsolearedescribedinthefoll

Page 10

Enrolledusers:AllusersthatareenrolledtoaccesstheHardwarePasswordManagerdevicearelistedonthistab.TheintranetaccountusernameisthenameusedforLDAPuseracco

Page 11 - ThinkManagementConsole

YoucanmigratefromoneLDAPservertoanotherwithoutlosingdata.IfyoundthatyouneedtouseadifferentserverforLDAPauthentication,enterthecongurationdataforthen

Page 13

ThistablistsanyRemoveUseractionsthathavebeenperformedontheuser,includingthenameofthedevicefromwhichtheuserwasremovedandthedateandtimeofthelaststatusch

Page 14 - MigratingtoanewLDAPserver

5.IfyouselectedWithexpiration,selectDuration,andthenselectthebeginningandendtimefortheaccesstoHardwarePasswordManagerdevices;orselectLogincountremaini

Page 15

•RemoveUser:removesauserfromthelistofusersauthorizedtoaccessaHardwarePasswordManagerdevice.•UpdateClientPolicy:savesanupdatedclientpolicytotheHardware

Page 16

•Allowmultipleuserstoenrollonasingledevice:morethanoneusercanbeenrolledonadevice.Ifthischeckboxiscleared,onlytherstusertobeenrolledonadevicecanbeanen

Page 17 - ©CopyrightLenovo2010

1.ClickRemoteActionsandPolicySettingsinthetoolboxorclickT ools➙ThinkVantageHardwarePasswordManager➙RemoteActionsandPolicySettings.2.IntheRemoteActions

Page 18

ChangingserverpolicysettingsServerpolicysettingsincludevariouswaystomanageuserenrollment,credentials,andclientportalandBIOSsettingsfortheLenovoHardwar

Page 19

HardwarePasswordManagergroups”onpage12foradescriptionofroles.)So,forexample,ausermightseealloptionsontheHardwarePasswordManagerBIOSmenubutaServiceTech

Page 20

5.ClickOK.Toassignpermissionstoagroupthatcanbeauthenticatedthroughthenewauthentication,dothefollowing:1.IntheUser'stool,click+onthetoolbarorright

Page 21 - Managerdevices

20HardwarePasswordManagerDeploymentGuide

Page 22

Chapter4.HardwarePasswordManagerClientLenovodevicesthatsupportHardwarePasswordManagerneedtoberegisteredwithamanagementserver(referredtoastheHardwarePa

Page 23

HardwarePasswordManagerDeploymentGuideUpdated:July,2010

Page 24 - Updatingtheemergencyaccount

Whentheclientisinstalled,itcommunicateswiththeHardwarePasswordManagerservertoauthenticatethedevice.TheclientcanthenrequestHardwarePasswordManagerpolic

Page 25 - Changingserverpolicysettings

•YoushoulddragthedevicesunderHardwarePasswordManagerDevicestotheActiveDirectoryoreDirectorygrouplistedintheHPMGroupstool.Ifyouradministratorhasenabled

Page 26

UpdatingcredentialsonaHardwarePasswordManagerdeviceAfterHardwarePasswordManagementisenabledonadevice,youcanaccesstheHardwarePasswordManagerLoginMenuto

Page 27

Chapter5.DeploymentThischaptercontainsadditionaldeploymentinformationforusingHardwarePasswordManagerdeviceswithHardwarePasswordManager.Itiswrittenfort

Page 28

–enrolled-returnswhetherthecurrentWindowssystemuserisenrolledintheutility–enabled-returnswhethertheutilityisenabledintheBIOSprogram–show-displaysresul

Page 29

Thisprocessisinitiatedautomaticallyontheclientsystembasedonpolicy,andadministratorcorporatecredentialsareobtainedfromtheHardwarePasswordManagerservert

Page 30

28HardwarePasswordManagerDeploymentGuide

Page 31

Chapter6.ScenariosThischapterdescribesscenariosassociatedwithhardwareandusercongurationchanges.Forthepurposeofthesescenarios,allsystemsareconsideredt

Page 32

•EnterthehardwareaccountcredentialswithHardwarePasswordManagerAdministratorprivilegestoreleasetheSVP/PAP,suchastheEmergencyAdminaccount.Ifhardwareacco

Page 33 - Chapter5.Deployment

HardwarePasswordManager,theBIOSwillclearthehardwarepasswordsanddeletethelocalhardwareaccountandSST.Scenario6-ReplacethesystemboardWhenthesystemboardis

Page 34 - One-touchregistration

Note:Beforeusingthisinformationandtheproductitsupports,readthegeneralinformationinAppendixD“Notices”onpage49.ThirdEdition(July2010)©CopyrightLenovo201

Page 35 - Pre-registration

Ifthesystemisstillbootable,itisrecommendedtode-registerthesystemwithHardwarePasswordManager.Thiswillclearallthehardwarepasswordsfromthesystem.Installt

Page 36

structuresarestoredinash,theashutilitieshavebeenupdatedtonotoverwriteHardwarePasswordManagerrelatedstructures.•ForwardFlashing-Whenashingtoanewerve

Page 37 - Chapter6.Scenarios

Note:TheharddriveshouldnotbeconnectedwhenthesystemisregisteredinHardwarePasswordManagerorelsetheharddiskwillbeassignedanHDP.UserScenariosThissectionde

Page 38

acompletelydifferentsetofscancodesonanotherkeyboardtype.Forexample,considerthepasswordazw.OnanEnglishkeyboard,thescancoderepresentationis0x1E,0x2C,0x1

Page 39 - Scenario7-Addaharddiskdrive

36HardwarePasswordManagerDeploymentGuide

Page 40 - Scenario11-FlashingtheBIOS

AppendixA.SecurityandconvenienceComputersecurityisoftenconsideredmuchmoreimportantmoreconvenience.ThefollowingtableillustrateshowHardwarePasswordManag

Page 41 - Scenario13-EntertheBIOSsetup

Table1.HardwarePasswordManagerpolicysettings(continued)PolicysettingDescriptionMostsecureMostconvenientCommonEmergencyUserNameandPasswordDenestheemer

Page 42

AppendixB.DisasterrecoveryBackingupthe9.0coreserverBeforeupgradingorotherwisemodifyingthecurrentHardwarePasswordManagercoreserver,itisimportanttobacku

Page 43 - Scenario6-BitLocker

1.CreateafoldercalledLANDeskBackuponashareonaseparateserverthatisnotthecoreserver.2.OpenacommandpromptonthecoreserverbyclickingStart➙Run,andlaunchingC

Page 44

Ifmigratingtoanewdatabase,manyitemscannotbeexported.Takescreenshotsofsuchcongurationssothattheycanbeappliedtothenewcoreserver.Anexampleoftheseinclude

Page 45

ContentsPreface...vChapter1.Overview...1Chapter2.InstallingHardwarePasswordManageronThinkManagementConsole...3Prerequisites...

Page 46

42HardwarePasswordManagerDeploymentGuide

Page 47 - AppendixB.Disasterrecovery

AppendixC.HintsandtipsThefollowingisalistoftipsassociatedwithHardwarePasswordManagerVersion1.0:•Symptom:Bitlockerrecoverymodeistriggeredifyouregistera

Page 48

Problemdescription:Singlesign-ontoWindowswillnotworkiftheWindowspolicysettingisenabledthatrequirestheusertoPressCtrl+Alt+Deltologin.Thissecuritysettin

Page 49 - AppendixB.Disasterrecovery41

•Symptom:YoureceivetheFailedtogenerateencryptionkeyerrormessageduringtheHardwarePasswordManagerregistration.Problemdescription:UserswithaWindowsuserna

Page 50

Ifyouhavealreadyrestoredyoursystem(forexample,lostyourCAPIkeystore),deregisterandreregisterinHardwarePasswordManager.•Symptom:WhenregisteringinHardwar

Page 51 - AppendixC.Hintsandtips

Solution:TheusermustuseawirednetworkconnectionwhenperforminganintranetloginfromtheBIOS.•Symptom:Receivetheincorrectusernameorpasswordspeciedmessagewh

Page 52

48HardwarePasswordManagerDeploymentGuide

Page 53 - AppendixC.Hintsandtips45

AppendixD.NoticesLenovomaynotoffertheproducts,services,orfeaturesdiscussedinthisdocumentinallcountries.ConsultyourlocalLenovorepresentativeforinformat

Page 54

TrademarksThefollowingtermsaretrademarksofLenovointheUnitedStates,othercountries,orboth:AccessConnectionsLenovoThinkVantageThinkPadThefollowingtermsar

Page 56

AppendixC.Hintsandtips...43AppendixD.Notices...49Trademarks...50ivHardwarePasswordManagerDeploymentGuide

Page 58 - Trademarks

PrefaceThisguideisintendedforITadministrators,orthosewhoareresponsiblefordeployingtheLenovo®HardwarePasswordManager™programoncomputersintheirorganizat

Page 59

viHardwarePasswordManagerDeploymentGuide

Page 60

Chapter1.OverviewTheLenovoHardwarePasswordManager(HPM)givesanadministratortheabilitytomanagehardwarepasswordsforallregisteredPCdevices.Further,itcreat

Commentaires sur ces manuels

Pas de commentaire