This User Manual will help you install the Citadel SSD and activate it for use. It also includes instructions for using the PBA's Settings Console, including managing users and user roles and configuring the PBA for smart card or password access.
Remove the screw from the SSD slot you intend to use if there is one present. Insert the Citadel SSD into an open M.2 slot in your computer. Be sure to align the notch(es) on the gold contacts of the SSD module with the notch(es) on the empty slot.
Attach a SATA power connector from your computer to the SATA power port on the rear of the Citadel SSD. Attach a SATA data cable to the SATA port on the rear end of the Citadel SSD and the other end to the computer's motherboard.
"Disk Management" which is built into Windows 8.1 and Windows 10. Open the ZIP file you downloaded and extract the "USB Digistor Activator V11 - Foxtrot" folder to your computer.
If you have a discrete video card, ensure your primary display detection is set to Auto. Disable "Secure Boot". NOTE The Citadel SSD does support Secure Boot, but only once activated. You may reena- ble Secure Boot after you finish reactivating the Citadel SSD. 3.3.2. FOR DELL COMPUTERS Follow these steps to ensure your Dell computer's UEFI settings are configured correctly.
3.4. INSTALL AN OPERATING SYSTEM OR VIRTUAL ENVI- RONMENT Your Citadel SSD has been shipped to you deactivated and unlocked. Install any operating system (OS) or virtual machine (VM) at this time. If you need to turn on a Trusted Platform Module (TPM), Virtualization Support, or Trusted...
3.5. HOW TO BOOT INTO THE THUMB DRIVE Insert the bootable USB drive with the Citadel SSD software into the computer and turn it on. Continually press the key for accessing your motherboard's boot menu while the computer starts up.
Page 12
Citadel SSD User Manual The software will activate the pre-boot authentication and will automatically shut down the computer when finished. Remove the USB thumb drive and reboot the system. The Citadel SSD has been activated!
Citadel SSD User Manual 4. FIRST TIME LOGIN IMPORTANT Before attempting to log in, make sure you have first activated your Citadel SSD. See Sec- tion 3: Activate the Citadel SSD, page If you haven't already, turn on the computer. The Citadel SSD software will load.
5.1. LOGGING IN 5.1.1. LOGGING IN WITH A USERNAME AND PASSWORD Power the computer on. The computer will boot into the Citadel SSD's pre-boot authorization screen. Make sure the Password button is selected. Type the default username and password into the "Username" and "Password" fields, respectively.
Citadel SSD User Manual 5.1.2. LOGGING IN WITH A SMART CARD Power the computer on. The computer will boot into the Citadel SSD's pre-boot authorization screen. Insert the smart card into the card reader. Make sure the Smart Card button is selected.
When two-factor authentication is enabled, the user is required to use both the password and smart card login methods. Power the computer on. The computer will boot into the Citadel SSD's pre-boot authorization screen. Type the default username and password into the "Username" and "Password" fields, respectively.
Citadel SSD User Manual WARNING If you've enabled this setting without having an account set up with both a password and smart card, you will be unable to log in or access the Settings Console. You will need to use the Administrator Backdoor method to log in or access Settings Console. See Sec- tion 6.2: Administrator Backdoor, page...
Citadel SSD User Manual 5.4. USER The "User" screen allows you to add a new user account, delete an account, or modify an existing account. 5.4.1. USER ROLES Here are the available user roles (user account types) and what each is allowed to do:...
Citadel SSD User Manual ADD A USER WITH A PASSWORD On the "User" screen, click the Add button. Make sure the Password tab is selected. Enter a unique username for the user account in the Username field. IMPORTANT The username must be less than 40 characters. Uppercase, lowercase, numbers, and special characters are allowed.
Citadel SSD User Manual ADD A USER WITH A SMART CARD NOTE A single-factor SmartCard user will only be able to configure Login and viewing options such as Logs. Only users with a password will be able to access the full suite of manage- ment features.
Citadel SSD User Manual 11. A new window will pop up. Enter your password in the appropriate field and click Continue to verify that you have registered the credentials correctly. The user account is now ready for use. BULK IMPORT USERS The "Import"...
Citadel SSD User Manual 5.4.3. EDIT A USER EDIT A USER WITH A PASSWORD On the "User" screen, locate the user account you wish to edit and then click the Edit button next to it. The "Edit User" window will open. Ensure the Password tab is selected.
Citadel SSD User Manual EDIT A USER WITH A SMART CARD On the "User" screen, locate the user account you wish to edit and then click the Edit button next to it. If you are a Login User you can only edit your own account.
The "Configuration" page allows you to view and customize the following settings that determine how the Citadel SSD PBA behaves. When you are finished, click the Save button to save your changes. • Failed Logins Before Lockout: When a user reaches this number of consecutive failed login attempts, further login is disabled until the system is rebooted.
Citadel SSD User Manual NOTE This setting does not remember passwords. • Show Legal Notice Before Login: Select Yes to set the disclaimer screen to appear prior to the login screen. Select No to set the disclaimer screen to show after the login screen.
Citadel SSD User Manual 5.6.1. BACKUP DATABASE The "Backup Database" screen is used to export configuration and log data. This feature is planned to be fully implemented in a future version of the PBA software. 5.6.2. ERASE DISK The "Erase Disk" screen lets a Security Officer erase everything on the SSD and resets it to the factory default state.
Citadel SSD User Manual The SSD will be erased. 5.6.3. CHANGE DEK The "Change DEK" screen lets a Security Officer change the SSD's data encryption key (DEK). This is the actual key used to encrypt the data on the SSD. This screen is only visible to users with the "Security Offi- cer"...
AK. 5.6.5. LICENSE UPGRADE Each Citadel SSD comes with a full license so generally you will not need to upgrade or change your li- cense. Licensing consists of two operations. First, you will need to generate a license request that is unique to the computer where the PBA will be used.
Citadel SSD User Manual GENERATE A LICENSE REQUEST Insert a thumb drive formatted to FAT-32 into your computer. On the "Maintenance" > "License Upgrade" screen, select the Generate License tab. From the Device Name drop-down box, choose the thumb drive you inserted to the computer in Step 1.
The license will be updated. For changes to take effect, log out and log back in again. 5.6.6. UPGRADING THE PBA SOFTWARE There are two methods to upgrade the Citadel SSD's PBA software: through the Settings Console or through a USB boot disk while using a command line utility.
Click the Upgrade PBA button. 10. A dialog box will pop up. Enter an Administrator password and click Continue. The Citadel SSD will now be upgraded. After the upgrade is complete, the computer will power off. VIA COMMAND LINE CREATE A BOOTABLE THUMB DRIVE Insert a USB thumb drive into your computer.
Page 32
Otherwise, continue onto the next step. HOW TO BOOT INTO THE THUMB DRIVE Insert the bootable USB drive with the Citadel SSD software into the computer and turn it on. Continually press the key for accessing your motherboard's boot menu while the computer starts up.
Citadel SSD User Manual 5.6.7. TEMPORARILY DEACTIVATE THE PBA The Citadel SSD PBA software can be temporarily disabled by an authorized administrator to allow mainte- nance of the computer's OS. This may be necessary for OS updates that require multiple reboots, or when you need uninterrupted booting and reading from a USB thumb drive or CD.
Citadel SSD User Manual 5.6.8. UNINSTALL THE PBA SOFTWARE You can completely uninstall the Citadel SSD PBA software, which will completely remove all settings, users, and files from the SSD. WARNING DIGISTOR recommends against performing this action unless a Technical Support agent directs you to do so.
Citadel SSD User Manual 5.6.9. EXPORT CONFIGURATION The "Export Configuration" feature is used to deploy a large number of devices with the same configuration on all of them. The configuration includes both users and settings and will be named "CDExportDB".
5.7. LOGS 5.7.1. ACTIVITY LOG The "Activity Log" screen includes every log that exists in the Citadel SSD PBA software's database. To ac- cess the "Activity Log" screen, click on Logs on the left-hand menu and then click on Activity Log.
• Incorrect JSON data for import users 5.7.2. LOGIN LOG The "Login Log" screen includes successful and unsuccessful login and logout events of the Citadel SSD. To access the "Login Log" screen, click on Logs on the left-hand menu and then click on Login Log.
Citadel SSD User Manual 5.7.3. EXCEPTION LOG The "Exception Log" screen includes all failed actions. To access the "Exception Log" screen, click on Logs on the left-hand menu and then click on Exception Log. You can search for specific log messages by using the Search text box in the top right of the screen and you can filter log messages by date range and username by clicking on the Filter button in the top right.
Citadel SSD User Manual 5.7.4. ADMIN LOG The "Admin Log" screen includes all administator actions carried out by the administrator on their account. To access the "Admin Log" screen, click on Logs on the left-hand menu and then click on Admin Log.
Citadel SSD User Manual 5.7.5. LATEST LOG The "Latest Log" screen includes all logs generated for the current day. To access the "Admin Log" screen, click on Logs on the left-hand menu and then click on Latest Log. You can search for specific log messages by using the Search text box in the top right of the screen and you can filter log messages by date range and username by clicking on the Filter button in the top right.
Citadel SSD User Manual Maintenance Messages • Incorrect JSON data for import users 5.7.6. PURGE LOG The "Purge Log" screen allows Security Officer users to delete logs by date range and/or username. Click on the Start Date text box. You'll be shown a pop-up calendar. Click on your desired start date for the date range you want to search within.
Citadel SSD User Manual 5.7.7. LOG FILTER You can sort and filter the display of logs by date and/or username with the log filter. This feature is availa- ble on all log screens except the "Purge Log" screen. Click on the Filter button in the top right.
Citadel SSD User Manual 5.8. DISK INFORMATION The "Disk Information" screen shows a list of available disks installed on the computer and displays each one's device name, serial number, and protection status.
DANGER Because the Administrator account can be accessed in this way, DIGISTOR recommends that you do not use this account for everyday access or share its credentials with anyone.
Page 45
Citadel SSD User Manual Skip selecting a username or entering your PIN. Instead, click the Login button. You will now be logged into the Settings Console on the Administrator account. Now you can disable two- factor authentication if necessary by going to Settings > Configuration. See Section 5.5.1: Configuration,...
Need help?
Do you have a question about the CItadel and is the answer not in the manual?
Questions and answers