Using The Enterprise Security Client; Launching Enterprise Security Client; Phone Home - Red Hat CERTIFICATE SYSTEM ENTERPRISE - SECURITY GUIDE Manual

Table of Contents

Advertisement

Chapter 4.

Using the Enterprise Security Client

The following section contains basic instructions on using the Enterprise Security Client for
token enrollment, formating, and password reset operations.

1. Launching Enterprise Security Client

• On Red Hat Enterprise Linux 4, launch Enterprise Security Client by typing
command prompt; this brings up the Enterprise Security Client daemon process, which
silently watches for inserted smart cards. The client can also be launched by selecting
System Settings, then Smart Card Manager, from the system menu.
• On Windows, Enterprise Security Client is launched from the desktop or the start menu;
Enterprise Security Client is also configured to launch on reboot.
• On Mac OS X, Enterprise Security Client is launched by double-clicking the Enterprise
Security Client icon wherever the client is installed.

2. Phone Home

The Enterprise Security Client offers a feature called Phone Home that associates information
within each smart card with information which points to distinct TPS servers and Enterprise
Security Client UI pages. Whenever the Enterprise Security Client accesses a new smart card, it
connects to the TPS server and retrieves the Phone Home information.
Phone Home quickly retrieves and then caches this information; because the information is
cached locally, the TPS subsystem does not have to be contacted each time a formatted smart
card is inserted.
The information can be different for every key or token, which means different TPS servers and
enrollment URLs can be configured for different corporate or customer groups. Phone Home
makes it possible to configure different TPS servers for different issuers or company units,
without having to configure the Enterprise Security Client manually to find the proper server and
URL.
NOTE
In order for the TPS subsystem to utilize the Phone Home feature, Phone Home
must be enabled in the TPS configuration file:
op.format.tokenKey.issuerinfo.enable=true
op.format.tokenKey.issuerinfo.value=http://server.example.com
at the
esc
21

Advertisement

Table of Contents
loading

Table of Contents