ActivClient User Guide
ActivClient User Guide
Table of Contents
Chapter 1: Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .5
About ActivClient . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Getting Started . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
Your First Steps with ActivClient . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .6
Working with the User Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
What can you do with the User Console? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
Access the User Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9
Export a Certificate . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
Delete a Certificate . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34
Select Certificates for Windows PKI Logon . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. 34
Deselect a Logon Certificate . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35
Make Certificates Available to Windows . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. 36
Manage Certificates in Microsoft Outlook . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. 36
Automatically Configure your Microsoft Outlook Security Profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36
Automatically Publish your Certificates to the Global Address List . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37
Automatically Add Certificates to Microsoft Outlook Contacts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38
Chapter 1: Introduction
In This Chapter This guide presents how to use ActivClient for authentication using your smart
card. It also explains how to manage your smart card credentials and ActivClient
5 About ActivClient itself.
• ActivClient 32-bit
• ActivClient 64-bit
• ActivClient CAC 32-bit
• ActivClient CAC 64-bit
About ActivClient
ActivClient is the latest smart card and USB token middleware from ActivIdentity
that allows enterprise and government customers to easily use smart cards and
USB tokens for a wide variety of desktop, network security and productivity
applications.
ActivClient enables the use of PKI certificates and keys, one-time password and
static password credentials on a smart card or USB token to secure:
• Desktop applications
• Network logon
• Remote access
• Web logon
• E-mail
• Electronic transactions
For a complete overview of the capabilities and functions of ActivClient, see the
ActivClient for Windows Overview.
This document is for:
• End users
Getting Started
This section explains the first steps you need to take with ActivClient and introduces
the User Console.
• Smart card status (whether your administrator has prepared the card for you and
it is ready to use, or not)
• ActivClient configuration (defined during ActivClient setup)
Table 1.1 lists the actions to take according to your smart card status:
You have a blank Your administrator has given you a blank smart card. You need to
smart card (no initialize the card before you can use it.
PIN)
1. Log on to your workstation using the same user name and
password that you used before installing ActivClient.
2. Initialize your new smart card and create your PIN, see "Initialize
a Smart Card with the PIN Initialization Tool" on page 11".
3. Load credentials on to your smart card as described in
"Managing Digital Certificates" on page 25".
4. Use your card to log on to your workstation (if your administrator
instructs you to do so), sign emails, access secure Web sites,
etc.
5. At any time, you can access the ActivClient User Console to
configure ActivClient, your smart card, or your credentials. For
more information, see "Working with the User Console" on
page 8.
Your smart card is Your administrator has given you a smart card and a PIN, and the
personalized with a smart card has already been personalized with your credentials (for
PIN but is not example, with digital certificates - but not configured for Windows
configured for logon). Your card is ready to use.
Windows PKI logon
1. Log on to your workstation using the same user name and
password you used before installing ActivClient.
2. Use your card to sign emails, access secure Web sites, etc.
3. At any time, you can access the ActivClient User Console to
configure ActivClient, your smart card, or your credentials. For
more information, see "Working with the User Console" on
page 8.
Your smart card is Your administrator has given you a smart card and a PIN, and the
personalized with a smart card has already been personalized with your credentials
PIN and a (including a digital certificate configured for Windows logon). Your
Windows PKI logon card is ready to use.
digital certificate
1. Log on to your workstation using your smart card and your PIN.
For more information, see "Log on to Windows with a Certificate"
on page 39".
2. Use your card to sign emails, access secure Web sites, etc.
3. At any time, you can access the ActivClient User Console to
configure ActivClient, your smart card, or your credentials. For
more information, see "Working with the User Console" on
page 8.
Manage your smart card • Change your PIN code, see "Change your Smart Card
PIN" on page 15
• View your smart card information, see "View Smart Card
Information" on page 23
• Unlock your smart card, see "Unlock your Smart Card"
on page 16
• Initialize your new smart card, see "Initialize a Smart
Card with the PIN Initialization Tool" on page 11
• Reset your smart card, see "Reset a Smart Card" on
page 13
• Update your smart card with ActivID CMS, see "Update
your Smart Card" on page 20
• View your unlock code, see "View your Unlock Code" on
page 16
• Select a smart card reader, from the Reader List icon on
the Standard toolbar
Use ActivClient Tools to: • Run the Troubleshooting Wizard, see "Troubleshoot
ActivClient" on page 62
• Troubleshoot • Run the Advanced Diagnostics Tool, see "Perform
• Diagnose Advanced Diagnostics" on page 64
• Configure advanced • Run the Advanced Configuration Manager, see
settings "Configure ActivClient" on page 68
• From the ActivClient Agent icon located in the Windows notification area:
– Double-click the ActivClient Agent icon .
– Left or right-click on the ActivClient Agent icon and select Open.
For more information on the ActivClient User Console, see the ActivClient for
Windows Overview.
This chapter explains how to manage your smart card and your PIN code.
13 Reset a Smart Card The PIN Initialization Tool allows you to:
15 Change your Smart • Initialize your smart card by setting a PIN code.
Card PIN
• Reset a PIN code while erasing the content of the smart card.
16 Unlock your Smart Card
Before initializing, you need to verify that your smart card is supported by the tool.
20 Update your Smart Card
22 Smart Card or
Certificate Expiration
Supported Smart Cards
23 View Smart Card PIN Initialization Tool supports blank and standalone smart cards.
Information
No unlock mechanism is available. If the smart card is locked due to too many
wrong PIN entries or if you forget the PIN code, the smart card can be run
through the PIN Initialization Tool again. You will be able to choose a new PIN
code, but the previous content of the smart card will be completely erased.
For the list of supported blank (ActivClient Standalone / Mini configuration) and
standalone (ActivClient Standalone configuration) smart cards, see the ActivClient for Important
Windows Overview. Repeated attempts to initialize a
smart card that is not in a supported
configuration can render the smart
card permanently unusable.
Access the PIN Initialization Tool
Your options to access the PIN Initialization Tool depend on whether you have
installed the User Console and ActivClient Agent.
• On the ActivClient Agent icon in the Windows notification area, left or right-
click and select PIN Initialization Tool.
• From ActivClient User Console, insert your smart card and then, from the Tools
menu, select New Card.
Use the following procedure to initialize your smart card using the PIN Initialization
Tool.
1. Start the PIN Initialization Tool (see "Access the PIN Initialization Tool" on
page 12).
Warning
• Entering too many wrong PIN
codes will lock your smart card!
Make sure you view your unlock
3. Enter your new PIN code, confirm it, and click Next.
code and write it down in a secure
place before you inadvertently
4. If you have a standalone smart card that is already initialized (with an unlock lock your smart card.
code), you must enter a PIN or unlock code. • If the smart card is already
initialized, the PIN Initialization
When the initialization is complete, the Finish window is displayed. Tool will reformat the card: all
content present on the card
5. If an unlock code is displayed, write it down in a secure location. (including private keys) will be
permanently deleted.
In order to reset the smart card, you need to know either the smart card’s PIN or the
unlock code.
2. Insert your smart card (chip-side up and chip first) into the smart card reader.
Note
You can also “Reset” and “Re-
initialize” your smart card using the
PIN Initialization tool. The tool also
allows you to reset your PIN in the
same process.
If... Action
You know the smart card PIN Make sure the PIN option is selected, enter
your PIN in the field, and click OK.
You do not know the smart card PIN 1. Select Unlock Code.
and the smart card was initialized 2. Enter the unlock code that you saved
with ActivClient in standalone mode at initialization, and click OK.
You do not know the smart card PIN, 1. Select Unlock Code.
and the smart card was initialized by 2. Call your help desk. You may be
your administrator asked to give the challenge displayed
in the Challenge Code field.
3. In the Unlock Code field, enter the
unlock code that the help desk
operator gives you, and click OK.
• On the ActivClient Agent icon , left or right-click and select PIN Change Tool.
• From the User Console, either:
– Select Change PIN from the Tools menu.
– Select the Change PIN icon from the Standard toolbar.
• From the Windows Start menu, go to Programs, ActivIdentity, ActivClient, and
select PIN Change Tool.
All conditions must be met (indicated by a green check ) before you can
proceed to the Next step.
The unlock procedure depends on the method used to initialize your smart card as
explained in Table 2.1.
Note
Some smart card models (such as
Table 2.1: Smart Card Unlock Actions
DoD CAC and US Government PIV
cards) cannot be unlocked with
Initialization method Unlock procedure
ActivClient. Instead, you should
contact your help desk to unlock
If you initialized your You are also responsible for the unlock code. You should
your card.
smart card directly with view your unlock code and save it in a secure location. This
ActivClient in unlock code helps you unlock the smart card if you lock it by
standalone mode entering multiple incorrect PINs.
See:
If your smart card was There is no code as the smart card cannot be unlocked.
initialized with However, you can re-initialize your smart card with the PIN
ActivClient in a Initialization Tool.
Standalone / Mini mode
See "Initialize a Smart Card with the PIN Initialization Tool"
on page 11.
Important
ActivClient detects the method used to initialize the smart card and displays the
You cannot view your unlock code if
relevant unlock dialog box. your smart card is locked.
2. Enter your PIN code when prompted. • Your smart card has been
initialized with ActivClient in
standalone mode.
3. Write down your unlock code and save it in a secure location. You need this
unlock code in case you lock your smart card in the future.
Important
If you select the Never display the
Unlock Code again option, the
Display Smart Card Unlock Code
dialog box will never display again.
When ActivClient detects that the locked smart card was initialized with ActivClient,
the Unlock Smart Card PIN dialog box asking for your Unlock Code and a New PIN
is displayed.
Note
• ActivClient can be configured to
display the unlock screen as soon
as a locked smart card is inserted
in the system.
1. Retrieve the unlock code that you saved when you initialized your smart card. • All conditions must be met
(indicated by a green check ).
2. In the Unlock Code field, enter the unlock code.
4. In the Verify field, re-enter the new PIN, and click OK.
When ActivClient detects that the locked smart card was initialized by the
administrator, the Unlock Smart Card PIN dialog box is displayed with a Challenge
Code.
1. Call your help desk and give them the code displayed in the Challenge Code
field.
2. In the Unlock Code field, enter the unlock code that the help desk operator gives
Note
you.
All conditions must be met
(indicated by a green check ).
3. In the New PIN field, enter a new PIN.
4. In the Verify field, re-enter the new PIN, and click OK.
If the unlock dialog box does not automatically display, you can manually initiate the
unlock process.
1. From the ActivClient User Console Tools menu, select Unlock Card.
2. Re-insert the locked smart card into your smart card reader.
Note
You can either: If you do not select an option or you
remove the card from the reader,
• Proceed with the update: the alert will disappear.
A window opens with the configured ActivID CMS My Digital ID Card portal.
c. To apply your new credentials, remove and then re-insert your smart card
when prompted.
If necessary, you can also manually check for smart card updates (for example, for
troubleshooting purposes).
1. In the User Console, make sure the correct smart card reader is selected.
2. From the Tools menu, select Advanced and then Check for card update.
• If a card update is available, you are prompted to perform the card update:
1. Insert your smart card (chip-side up and chip first) into the smart card reader.
If ActivClient detects that your card or certificates has expired or is about to expire,
it displays the following message:
Prerequisites
At least one of the following
ActivClient policies is enabled:
Notes
• The card expiration option is only
available for CAC and PIV cards.
• The certificate expiration option is
available for all card models.
2. If you want to be reminded of this expiration, select the number of days before
expiration and click OK.
• User name
• Smart card manufacturer name (when known)
• Smart card type (when known)
• Serial number
• From the User Console tasks pane, insert your smart card and click Smart Card
Info.
• From the User Console right pane, insert your smart card and either:
– Double-click the Smart Card Info icon . Note
– Right-click the Smart Card Info icon and select View smart card info. Your user name is supplied by
ActivClient from either:
In This Chapter This chapter explains how to download and configure your digital certificates for
authentication.
25 Download a Certificate
with Microsoft Internet The availability of the operations described in this chapter (such as importing/
Explorer deleting a certificate from your smart card) vary according to your smart card
policy.
26 Download a Certificate
with Firefox
36 Make Certificates
Available to Windows Prerequisites
36 Manage Certificates in
Microsoft Outlook • Microsoft CAPI Support (sub-component of the Digital Certificate Services
component) was installed during setup.
31 Manage User and CA
Certificates • Your administrator provided you with a Web site URL to access your
organization's Certificate Authority. To download a smart card logon
certificate, your organization's Certificate Authority must be either one of the
following:
– Windows 2000, Windows Server 2003 and Windows Server 2008
Certificate Authority
– A Certificate Authority trusted by your Active Directory
1. Insert your smart card (chip-side up and chip first) into the smart card reader.
3. Navigate to the page where you can generate or download a certificate (the
steps to reach this page vary depending on the CA that you are using).
4. When you are asked for the Cryptographic Service Provider (CSP), select
ActivClient Cryptographic Service Provider from the list of providers.
When your smart card is full (that is, if there is not enough space for the
certificate that you are downloading), the ActivClient CSP overwrites the
default certificate with the new certificate. In this case, a message is displayed Note
that you are about to replace the existing credentials on the card. Select Yes to Once your certificate is
overwrite the default certificate. downloaded, Microsoft
applications, such as Internet
6. Enter your PIN when prompted. Explorer and Outlook, display the
certificate name and information.
7. Verify that the key pair and associated certificate have been loaded on your smart However, the private key
card using the ActivClient User Console (optional). associated with the certificate is not
stored on the personal computer.
Therefore, you still need the smart
Download a Certificate with Firefox card in order to use the certificate
information.
You can use a PKI key pair (unique to you, generated directly on your smart card) and
an associated digital certificate (proving your identity inside your organization) in order Prerequisites
to use a variety of security services. • A supported version of Firefox is
installed on your computer.
1. Insert your smart card (chip-side up and chip first) into the smart card reader. • If you use ActivClient 32-bit,
Firefox support was installed
2. Launch Firefox and go to your Certificate Authority’s Web site. during setup.
• If you use ActivClient 64-bit, the
3. Follow the instructions to request a certificate. ActivClient PKCS#11 library was
installed during setup and then
installed in Firefox. For details,
4. Enter your PIN when prompted.
see the ActivClient for Windows
Installation Guide.
5. Verify that the key pair and associated certificate have been loaded on your smart
• Your administrator provided you
card using the ActivClient User Console (optional). with a Web site URL to access
your organization's Certificate
Authority.
Download an Entrust Profile
If you plan to use Entrust Entelligence™ Desktop Solution with ActivClient, you must Prerequisite
store your Entrust profile on your ActivClient smart card. This profile includes The Entrust Entelligence Desktop
signature and encryption keys and certificates, along with certificates for key history. Solution support was installed
during setup.
1. Insert your smart card (chip-side up and chip first) into the smart card reader.
2. In the Windows notification area, right-click the Entrust icon and then click Notes
• This feature is only available with
Create Entrust Profile.
ActivClient 32-bit.
• As an alternative, you can
download an Entrust Profile to
your smart card using the Entrust
Self-Administration Server.
• This section only applies to
Entrust Entelligence Desktop
Solution. It does not apply to
Entrust Entelligence Security
Provider.
4. In the Reference number and Authorization code fields, enter the information
supplied by your Entrust administrator, and click Next.
Note
Although the Entrust profile is stored
on the smart card, all the supporting
Entrust files are stored in the
specified folder. If necessary, enter
a different folder location.
5. Use the following table to determine how to store your profile and then click Next.
If... Then...
The correct reader does not appear Select the correct reader from the list.
in the drop-down list
6. Enter a name for the Entrust profile (usually your username) in the Profile name
box, and click Next.
7. When a window displays a message that Entrust is now ready to create your
profile, click Next.
Note
If your card is already initialized, you
are prompted to enter your current
PIN instead.
8. In the New Password field, enter a password for the Entrust profile. You can use the ActivClient User
Console to change your PIN later.
This password is the initial PIN for the smart card.
9. In the Confirm Password field, re-enter your password, and click Next.
10. When the window is displayed with the message that your Entrust profile has
been successfully created, click Finish.
You can view details of your certificates on your smart card using the ActivClient User
Console.
2. Either:
Note
In the Advanced tab, you can copy
a value to another application, use
the Copy command (CTRL + C) to
move the selected text to the
clipboard, and then use the Paste
command (CTRL + V) to add the
value.
Prerequisites
Import a User Certificate
• ActivClient User Console is
installed.
If you are already using your personal PKI key pair and certificates, you can import
• A certificate is available as a
them to your smart card as .pfx or .p12 file formats. This guarantees that your PKCS#12 file on your workstation.
private credentials are portable and more secure inside your smart card. To obtain this file, export your
certificate by using, for example,
1. Open the ActivClient User Console. the Microsoft Internet Explorer
Export function.
2. From the File menu, select Import and then click Certificate.
Note
3. Select or browse to the certificate that you want to import, and click Open.
Make sure that Personal
Information Exchange
If the certificate is password-protected, the Password Request dialog box is
(*.pfx;*.p12) is selected as the file
displayed prompting you to enter your password. type.
4. In the Password field, type the certificate password, and click OK.
4. In the Password field, type the certificate password, and click OK.
Export a Certificate
You can send your user certificate or CA certificate to someone by exporting it from
your smart card into a file. Prerequisites
• ActivClient User Console is
1. Open the ActivClient User Console. installed on your workstation.
• A certificate is available on your
2. Either: smart card.
4. Select the location and the file name for the exported certificate, and click Save.
5. Click OK.
Important
Do not delete a certificate if you may
Delete a Certificate need it to decrypt old documents or
messages
If a certificate is obsolete (expired or revoked), you can delete it from your smart card
before you download a new certificate. Deleting a certificate applies both to user
certificates (in My Certificates folder) and to CA certificates (in CA Certificates folder). Prerequisites
• ActivClient User Console is
1. Open the ActivClient User Console. installed.
• A certificate is available on your
2. Either: smart card.
With Windows Vista, Windows 7 and Windows Server 2008, the Windows logon
process allows you to select a logon certificate when you log on (among certificates
3. Select the certificate you want to use for Windows PKI logon.
Prerequisite
Deselect a Logon Certificate
One of your certificates is set as
default.
When you do not need to set your logon certificate as default, follow these steps:
).
The certificate icon is updated and the green check mark disappears .
You need to make the certificates available to Windows manually when your
administrator has configured ActivClient so that certificates are not automatically
registered at card insertion. For information on configuration, see the ActivClient for
Windows Administration Guide.
This operation is needed only once, the first time you use a new smart card on a new
workstation.
2. Either:
To sign and encrypt/decrypt emails with Microsoft Outlook, a security profile must be • Your smart card contains
certificates for email signature and
created in Outlook for your email Exchange account. This profile identifies the
encryption.
signature and encryption certificates.
Note
ActivClient can automatically create your security profile. For further information about this
ActivClient feature, see the
ActivClient for Windows
1. Start Microsoft Outlook configured with a Microsoft Exchange account. Administration Guide.
2. Insert your smart card (chip-side up and chip first) into the smart card reader.
ActivClient also makes sure that the most current certificates are used and that
the email address in the certificate matches that of the Outlook account.
This chapter explains how to use your smart card-based certificates for
authentication, digital signature and encryption.
41 Use Windows Dial-Up/ • Your smart card is configured with a certificate for Windows PKI logon.
VPN for Remote Access • Your workstation is configured for PKI logon: the workstation must be
attached to a domain, a root certificate must be available and a CRL server
42 Use a Non-Microsoft
accessible.
VPN for Remote Access
• Microsoft CAPI Support (sub-component of the Digital Certificate Services
42 Access a Secure Web component) was installed during setup.
Site
44 Log on to Entrust
Entelligence
1. Start your workstation.
45 Send/Read Signed and
Encrypted Email 2. Insert your smart card (chip-side up and chip first) into the smart card reader.
Messages with Microsoft
Outlook A Log On window relevant to your operating system is displayed.
48 Send/Read Signed and
Encrypted Mails with
Thunderbird
50 Encrypt/Decrypt Files
with EFS
- Or -
After a few moments, you are logged on and your desktop is displayed. For further information on
ActivClient customization, see to the
ActivClient for Windows
Administration Guide.
Lock your Workstation on Smart Card Removal
Prerequisites
To increase the security of your computer and its contents, lock your computer when • ActivClient is configured to lock
you are away from it and keep your smart card safely in a separate place or on your the workstation on smart card
person. removal (default setting).
• You used your smart card to log
To lock your workstation, simply remove your smart card from the smart card reader. on to your workstation.
Notes
• On Windows Vista, Windows 7,
Windows Server 2008, there is no
visual notification. Instead, there is
an audio notification (a beep).
• For further information about this
ActivClient feature, see the
ActivClient for Windows
Administration Guide.
Prerequisites
• You can access a VPN product
supported by ActivClient. For the
complete list, see the ActivClient
for Windows Overview
• Your smart card contains a
4. Enter your PIN in the Smart card PIN field and click OK. certificate configured for VPN
logon
Once authentication is successful, the Dial-Up or VPN session is established. • You have configured your VPN to
use an ActivClient-based digital
certificate. Depending on the VPN
Use a Non-Microsoft VPN for Remote Access products, you may need to select
the cryptographic library.
- Select the "ActivClient
You can use your smart card-based digital certificate for authentication with several Cryptographic Service Provider"
VPN products. for Microsoft CAPI compatible
applications
OR
1. Insert your smart card (chip-side up and chip first) into the smart card reader.
- Select the ActivClient PKCS#11
library (acpkcs211.dll in the
2. Start your VPN connection. ActivClient installation directory)
for PKCS#11 compatible
3. When prompted, enter your smart card PIN, and click OK. applications and the certificate for
the VPN authentication
When you are authenticated, the VPN session is established.
You can use your smart card-based digital certificate to access a Web site protected
by SSL v3 or TLS for strong user authentication.
1. Insert your smart card (chip-side up and chip first) into the smart card reader.
2. Access the secure Web site or page using Microsoft Internet Explorer.
Prerequisites
• Your smart card contains a
certificate configured for
authentication to this Web site
• Microsoft CAPI Support (sub-
component of the Digital
Certificate Services component)
was installed during setup
3. From the certificate list, select the appropriate ActivClient certificate, and click OK.
4. Enter your PIN in the Smart card PIN field and click OK.
The browser sends your certificate and a digital signature to the web server. The
server verifies your signature and grants access to the secured site or page. Prerequisites
• Firefox is installed on you
computer.
Access a Secure Web Site with Firefox
• Your smart card contains a
certificate configured for
You can use your smart card-based digital certificate to access a Web site protected authentication to this Web site.
by SSL v3 for strong user authentication.
• If you use ActivClient 32-bit,
Firefox support was installed
1. Insert your smart card (chip-side up and chip first) into the smart card reader. during setup.
• If you use ActivClient 64-bit, the
2. Start your browser from your desktop. ActivClient PKCS#11 library was
installed during setup and then
3. Access the secure Web site or page. installed in Firefox.
For details, see the ActivClient for
4. When Firefox prompts you to enter a Master Password, enter your PIN. Windows Installation Guide.
Your browser sends your certificate and a digital signature to the web server. The
server verifies your signature and grants access to the secured site or page.
2. Right-click the Entrust icon located in the Windows notification area and
select Log In to Entrust. Prerequisite
An Entrust profile is downloaded on
to your smart card. For more
The Entrust Login dialog box is displayed. Entrust automatically retrieves the
information, see "Download an
profile name from the smart card. Entrust Profile" on page 26.
When you are logged on, the red X is no longer displayed above the Entrust icon
Click the signed message that you want to read. If the sender is successfully
authenticated, the message appears with a secure message icon.
Encrypting an email message guarantees that only the proper recipient can open and
read the message and its attachments. Email encryption is based on the public key
infrastructure.
Decrypting an encrypted email message is performed directly on your smart card for
increased security.
The email message and attachments are displayed. In addition, the secure
message icon is no longer displayed, indicating that the message is not
encrypted.
3. In your Inbox, click on the signed message you want to read. If the sender is
successfully authenticated, the message appears with a secure message icon.
Encrypting an email message guarantees that only the proper recipient can open and
read the message and its attachments. Email encryption is based on the public key
infrastructure.
Decrypting an encrypted email message is performed directly on your smart card for
increased security. Prerequisites
• Thunderbird is installed on your
workstation.
Send Encrypted Email Messages
• A certificate with email signature
capabilities is available on your
1. Insert your smart card (chip-side up and chip first) into the smart card reader. smart card.
• If you use ActivClient 32-bit,
2. Start your email client.
Thunderbird support was installed
during setup.
3. Click Write.
• If you use ActivClient 64-bit, the
ActivClient PKCS#11 library was
4. Compose your mail and go to Security (on top of the email toolbar) and select installed during setup and then
Encrypt this message. installed in Thunderbird.
For further information about the
5. Encrypt your mail. setup, see the ActivClient for
Windows Installation Guide.
6. Click Send.
8. Look in your Sent Items for the sent email and verify it is encrypted.
In order to encrypt and decrypt files on your workstation, you may need to configure
EFS during your first file encryption (depending on your platform configuration).
4. Update your file or folder properties to enable encryption (via the Advanced
button and then the Encrypt contents to secure data option).
– Select your existing smart card EFS certificate in the certificate list.
– Choose to create either a smart card self-signed certificate or a certificate
issued by your domain‘s certification authority.
6. Enter your smart card PIN and click OK.
The selected or new certificate will be used for all file encryption and decryption
operations. The selected file or folder is encrypted and appears in green in
Microsoft Explorer.
EFS Encryption/Decryption
Prerequisites
Encrypt a File or Folder with EFS • Your operating system is either
Windows Vista, Windows 7 or
1. Start Microsoft Explorer. Windows Server 2008.
• Your platform is configured for
2. Insert your smart card. EFS.
• Your platform is configured to
3. Select the file or the folder to encrypt. require the use of a smart card for
EFS.
4. Update your file or folder properties to enable encryption (via the Advanced • Your smart card contains a
button and then the Encrypt contents to secure data option). certificate configured for EFS.
The file or the folder is then encrypted and appears in green in Microsoft Explorer.
A window is displayed at the lower right corner of your desktop prompting you to
enter your smart card PIN.
3. When prompted to select an existing encryption certificate or create a new one on Note
your smart card, either:
The old EFS certificate and the new
one will co-exist on the same card.
• Choose to create either a new smart card self-signed certificate or a certificate
issued by your domain‘s certification authority:
a. Insert your smart card.
b. Click Next.
• Choose to select an existing smart card EFS certificate from the certificate list.
A tree representing your file system is displayed.
4. Select the folders to re-encrypt. Make sure all folders containing your encrypted
files are selected.
5. Enter your smart card PIN when prompted and click OK.
Note
Depending on your configuration, a
recovery agent may be configured
to help you recover your data. For
more information on file/folder
recovery, see the Microsoft
Windows Help on your Windows
platform.
This chapter explains how to synchronize your smart card and configure remote
access.
Prerequisites
– From the Tasks pane, under One-Time Password Tasks, click View
one-time password.
– From the right pane, double-click the One-Time Password icon .
An icon for each authentication server is displayed (usually only one server is
available, hence only one icon is displayed) in the right pane.
– From the right-pane, right-click the One-Time Password icon and select
Synchronize one-time password.
– From the Tasks pane, under One-Time Password Tasks, click
Synchronize one-time password.
The Synchronize One-Time Password dialog box is displayed.
2. Either:
– From the Tasks pane, under One-Time Password Tasks, click View one-
time password.
– From the right pane, double-click the One-Time Password icon .
An icon for each authentication server is displayed (usually only one server is
available, hence only one icon is displayed) in the right pane.
5. Enter your name in the User Name field and click OK.
This chapter explains how to generate and log on with a one-time password
(OTP).
58 Manually Generate a
ActivClient generates one-time passwords and sends them to the VPN client
One-Time Password
transparently each time you perform a secure connection.
Prerequisites
If you do not have a smart card, you need an emergency password. Contact
your help desk.
2. Place your cursor in the password field of the application to which you want to
authenticate.
a. Locate the challenge on the application you are authenticating to. (For
challenge/response applications, the challenge is displayed in the dialog box
used when logging in).
c. Click Generate.
This chapter explains how to display the personal information stored on your
smart card.
59 View “My Personal Info” The personal information displayed may vary according to your type of card and
on CAC and PIV Cards
profile. It includes:
• From the User Console left pane, click on View my personal info under My
Personal Info Task.
• From the User Console right pane, either:
– Double-click My Personal Info icon .
– Right-click on the My Personal Info icon and select Open.
The Personal Information dialog box is displayed on the right pane.
For PIV smart cards, the User Console displays the digital signature’s validity for:
62 Troubleshoot ActivClient The About ActivClient window displays information such as:
64 Perform Advanced
Diagnostics • ActivClient edition and version number
• Build Number
66 Use the Forget state for
all cards Option • Copyright information
67 Activate Log Files from • Information about your system, such as Windows version and web browser
the ActivClient User version
Console
• Credits information (click the Credits button)
68 Configure ActivClient
69 Auto-Update Service
1. To view the ActivClient system information, either:
– From ActivClient User Console, select About ActivClient from the Help
menu.
– On ActivClient Agent icon in the Windows notification area, left or
right-click and select About.
The About ActivClient window is displayed.
Troubleshoot ActivClient
The Troubleshooting Wizard:
• Helps you to resolve issues you may encounter while using a smart card with
ActivClient
• Analyzes your system
• Diagnoses problems
• Displays the results in the Diagnosis And Resolutions window
• Provides instructions on how to correct problems
2. Click Next on the Welcome screen and follow the instructions to proceed.
If you do not enter your PIN, the Diagnosis and Resolutions report will not
proceed with PIN related operations such as:
4. Click Next.
5. Follow the instructions displayed in the Diagnosis and Resolutions page and
click Finish.
3. Click Diagnose.
A single report is generated and stored in a log file which you can send to your
help desk.
The generated report is displayed in eight categories which you can access by
clicking on the corresponding nodes:
– Applications
– PC/SC
– Readers
– Drivers
– Smart Card
– ActivClient Configuration
– ActivClient Installation
– ActivClient Health Check
– ActivID CMS Connectivity
– Platform
5. To copy part of your report, select the required view, and select File and click
Copy.
The content of the option you selected is copied to the clipboard and can be
pasted into a file and location of your choice.
Warning!
All the information is saved in a single log file.
The diagnostic report may consist of
hundreds of pages. If you only want
7. To print the report, select File and click Print.
to print part of the report, either save
it as a log file first or copy the
The entire report is sent to your default printer. relevant option(s) to a file, and then
print only the relevant sections.
8. If your administrator has enabled the option, you can email the report to your help
desk by selecting File and then clicking Email.
Note
The report is saved as a log file and your default email application (for example,
The destination email address may
Outlook) opens with a new message. be pre-defined by your
administrator.
The log file is then attached to the new mail message.
9. Add any additional information and send the message to your help desk.
In most environments, ActivClient will refresh this information as needed when your
smart card content is updated. In some cases, in order to solve potential problems,
your technical support may suggest to "tell" ActivClient to "forget" any smart card
information it may have saved.
The ActivClient Log File Options dialog box is displayed. Log Activity Recommendations
• Turn off logging system activity in
normal use cases.
• Turn on logging system activity
only when required by your
system administrator or help desk.
• After log file creation, ActivIdentity
recommends disabling log system
activity!
4. Enter a name for the log file in the Log File Name field.
5. Type a size for the log file in the Max Log File Size (in MB) field.
6. Click OK.
You are prompted to reboot in order to enable logging for all ActivClient
components.
7. Save and close all your applications and select Reboot Now (or Reboot Later if
you prefer to enable logging later).
Configure ActivClient
Only local administrators can configure ActivClient. Administrators can select specific
security policies, such as “smart card removal behavior”. For example, when users
remove their smart card from the smart card reader, the workstation behaves either
way depending of pre-set configuration:
Prerequisite
• Lock workstation The Advanced Configuration
Manager was installed during the
• Log off session
ActivClient setup.
• No action
For information on the settings and their values, read the description displayed at
the bottom of the window each time you select an option.
Prerequisite
Auto-Update Service This feature is enabled only if the
Auto-Update component is
ActivClient can be configured so that software updates are automatically downloaded installed and if your organization
and installed on your workstation. has set up an auto-update server.
For further information, see the
ActivClient for Windows
Administration Guide.
This chapter explains how to use ActivClient in Citrix and Remote Desktop
environments.
72 Use your Smart Card It is not necessary to install ActivClient on the Citrix client unless you intend to log
Inside a Citrix Session
on to the client workstation with a smart card.
72 Log on to a Remote
Desktop Session
Prerequisites
73 Use your Smart Card in
a Remote Desktop
Session • ActivClient is installed on the Citrix XenApp Server. For more information on
supported versions of Citrix server, see the ActivClient for Windows
73 Lock a Remote Desktop Overview.
Session
• Your workstation is configured with Citrix client (Program Neighborhood,
Program Neighborhood Agent, or Web Interface).
• You have a smart card and a smart card reader up and running and
connected to your workstation.
How you log on to a Citrix session depends on your configuration. There are
three cases you might encounter:
• You log on to your workstation with a smart card and digital certificate and
your Citrix authentication mode is “Smart Card with Pass-through”.
– You are logged in automatically as soon as you start a Citrix session
• You log on to your workstation with a user name and password (standard
Windows authentication) and your Citrix authentication mode is “Local User
with Pass-through”.
– You are logged in automatically as soon as you start a Citrix session.
• You log on to a workstation or thin terminal that is not part of the domain, and
that does not have ActivClient installed.
– You are prompted to authenticate with your smart card and PIN code
(see "Log on to Windows with a Certificate" on page 39).
You are automatically authenticated and you access your Citrix Web Interface
web page.
4. Double-click your Citrix server desktop icon in your Citrix Web Interface web
page.
The Windows logon interface of your Citrix server desktop displays within your
browser window.
that is connected locally to your computer. • You have a smart card and a
smart card reader up and running
and connected to your
workstation.
Log on to a Remote Desktop Session
• You are logged on to a Citrix
session.
Microsoft Remote Desktop allows you:
• To remotely control your computer from another office, home, or while traveling in
order to use the data, applications, and network resources that are on your office
computer.
• To connect to a Windows server with Windows Terminal Services enabled, to
access applications not available on your local workstation.
3. Select the server or workstation you want to access and click Connect.
1. Start the application that is using your smart card, for example, Microsoft Outlook.
Prerequisites
2. Use one of the smart card-based services (for example, prepare to send a signed • ActivClient is installed on the
email message). remote Windows workstation or
server.
3. When you are prompted for the PIN, enter your smart card PIN, and click OK. • Remote Desktop Connection is
installed on your local Windows
workstation.
The application running on the Remote Desktop (remote computer)
communicates with your smart card that is connected locally to your computer. • You have a smart card and a
smart card reader up and running
After a few moments, the operation is completed (for example, the signed email is connected to your workstation.
sent).
In This Appendix This appendix lists terms and acronyms used throughout the full set of
ActivIdentity ActivClient for Windows technical publications. Not all terms and
Terms acronyms appear in all documents.
74
75 Acronyms
Terms
Certificate Authority (CA) - The CA issues and manages security credentials
and public keys for message encryption in a networked environment. As part of a
Public Key Infrastructure (PKI), a CA checks with a registration authority (RA) to
verify information provided by the requestor of a digital certificate. If the RA
verifies the requestor's information, the CA issues a certificate.
Federal Information Processing Standard 201 (FIPS 201) - FIPS 201 is the
standard for Personal Identity Verification (PIV) cards defined for US Government
employees and contractors.
My Digital ID Card (MDIDC) - This CMS component allows end users to access
the self-service CMS functions, which includes card and credential management.
Public Key Infrastructure (PKI) - PKI describes the laws, policies, standards, and
software that regulate or manipulate certificates and public and private keys.
Symmetric Key Infrastructure (SKI) - SKI keys are used to perform strong
authentication on remote applications. SKI keys encrypt passwords in:
- Synchronous mode (generates 1 password without any challenge. The server uses
the same method to create a password than the smart card)
- Asynchronous: encrypts a challenge
Standalone smart card - Smart card with pre-loaded applets issued by the
manufacturer.
Acronyms
Acronym
What does it stand for
CA
Certificate Authority
CAC
Common Access Card (for the United States Department of Defense)
CSP
Cryptographic Service Provider
FIPS
Federal Information Processing Standard
GAL
Global Address List
GP
GlobalPlatform
OTP
One-Time Password
PKI
Public Key Infrastructure
PIV
Personal Identity Verification
Smart card issued by the United States government to federal employees and contractors.
RA
Registration Authority
SKI
Symmetric Key Infrastructure
Document Information
ActivIdentity, Inc. welcomes your comments and suggestions.
Your input is an important factor in future revisions of this publication. Please let us know
your opinion.
Please send your feedback via email to: [email protected]. If you find errors or have
general suggestions for improvement, please indicate the chapter, section and page
number. If you would like a reply, please include your name, company, email address, and
telephone number.
Americas +1 510.574.0100 ActivIdentity Intellectual Property: This document or deliverable(s) contain proprietary
US Federal +1 571.522.1000 information of ActivIdentity Corporation and/or its subsidiaries and affiliates (collectively,
Europe +33 (0) 1.42.04.84.00 “ActivIdentity”) embodying confidential information, ideas, and expressions, no part of which may
Asia Pacific +61 (0) 2.6208.4888 be reproduced or transmitted in any form or by any means, electronic, mechanical, or otherwise,
without prior written permission from ActivIdentity. This document may not be modified, copied,
Email [email protected]
distributed, transmitted, displayed, performed, reproduced, published, licensed, used to create
Web www.actividentity.com
derivative works therefrom, transferred, or sold unless expressly agreed by ActivIdentity. The
furnishing of this document does not imply or expressly provide a license to any of the ActivIdentity
intellectual property.