Smart cards can provide additional security to a thin client network. This paper provides instructions for configuring a smart card with your HP Compaq t5000 thin client. Prerequisites The following items are required to use a smart card with HP Compaq t5000 thin clients: • Reflex USB V2 Smart Card Reader from Schlumberger.
Page 3
From the CA Identifying Information box, enter a name for your CA and click Next. From the Certificate Database Settings dialog box, leave the default settings (unless you know that you want to change them) and click Next. You'll need the CD-ROM or installation files. If Internal Information Services is currently running, you will be prompted to stop the service tempo- rarily.
Creating a Smart Card Logon Certificate Template You will need to create a smart card logon certificate template. To create the certificate template, perform the following steps: Create an MMC with the following snap-ins: • Active Directory Users and Computers •...
Page 5
A Properties of New Template dialog box will appear. Give the new template a name. Be sure to select Publish Certificate in Active Directory if the box isn't already checked.
Page 6
Click the Request Handling tab and then select Signature and Smartcard Logon in the Purpose drop- down list. If you want the user to be prompted to insert a smart card during logon, select the option Prompt the User During Enrollment. From the Properties of New Templates dialog box, click the CSPs button near the bottom to open the CSP Selection dialog box, where you can select the appropriate cryptographic service provider (CSP).
Page 7
NOTE: You cannot randomly select a CSP. What you select affects what the user sees on the other end. For example, if selecting the Schlumberger Cryptographic Service Provider, the user is prompted to insert a Schlumberger smart card on the client side. Select only the applicable CSP(s) for your smart cards.
Issuing the Certificate Now that you have the smart card logon template duplicated, you need to issue it from the CA. To issue the certificate perform the following steps: Expand the Certification Authority object in your MMC. Expand your CA name. Right-click Certificate Templates.
Forcing a Smart Card Logon Administrators can modify users’ account properties to require smart cards for interactive logons. With this feature, users cannot log onto a thin client in your network without a smart card. To configure this option, perform the following steps: From the Group Policy Editor window, select Group Policy Editor >...
HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein.
Need help?
Do you have a question about the Compaq t5135 and is the answer not in the manual?
Questions and answers