Buy online or Call 800-BUY-MYHP

HP ProtectTools Security Manager: enable Smart Card security

Free, online classes, available 24/7: www.hp.com/go/learningcenter

Overview

HP ProtectTools Security Manager: enable Smart Card security
» HP ProtectTools Security Manager: enable Smart Card security  (10:36) Video
Get an overview of HP ProtectTools Security Manager and learn how to set up and use Smart Card (Java Card) functionality, step by step.
2 Ratings
 

Related topics

» HP ProtectTools Security Manager: using BIOS Configuration
» HP ProtectTools Security Manager: using single sign-on
» Streamline your organization through shared services (quick lesson)
» Transition your old IT assets (quick lesson)
» eBooks: a different way to read (quick lesson)

Transcript

HP ProtectTools Security Manager: enabling smart card security

Welcome to this demonstration on HP ProtectTools Security Manager and smart cards. In this demo, you'll learn how to set up and use a smart card reader with HP ProtectTools Java Card for user authentication.

You might be wondering why you should use a smart card. A smart card adds another layer of security to your notebook computer by adding a power-on password, in addition to a password for Microsoft Windows. An unauthorized user who learns your password can access your system if that's your only security measure in place. With a smart card configured for pre-boot authentication, before the operating system loads, a user must have the smart card in addition to the power-on password to use your computer.

All HP business notebook PCs include either an embedded smart card reader or enable you to add a reader using the PC card slot. In addition, HP notebooks come bundled with free HP ProtectTools Security Manager software, which you'll use to configure the smart card.

The first thing to do is to determine whether you have an embedded smart card reader. You can find out by checking the Device Manager. In Microsoft Windows Vista, select Start > Control Panel > Hardware and Sound > Device Manager. If you have a reader installed, it will be listed under the Smart Card readers category. If you're using an add-on smart card reader, insert the reader into the PC card slot and then insert the Java Card into the reader.

If you need a smart card or reader, you can visit the HP website and find them at the Supplies and Accessories for Business Notebooks section.

Before we learn how to use a smart card, let's take a brief tour of the HP ProtectTools Security Manager software. To start using the software, open the Start menu and then select HP ProtectTools from the Programs list.

When the program initially opens, it loads security providers.

HP business notebooks include another layer of security in addition to smart card authentication. The Trusted Platform Module (also called T_P_M) embedded security chip lets you perform platform authentication. The TPM chip has a unique key burned in during manufacture. By using the TPM, you can protect against unauthorized access even before the operating system loads.

Another security feature is Single Sign-On (SSO), which helps prevent unauthorized access to your computer and protects your online and network credentials. SSO allows you to create a vault of passwords that are available whenever you access a logon dialog box or web page.

A final security option is a biometric fingerprint reader embedded in your HP business notebook. You can use this to log on to Windows rather than typing a password. Using your fingerprint to log on is more secure because it eliminates the possibility of someone guessing your password. It takes just a few minutes to record your fingerprints in the reader.

Before we learn how to use a smart card, let's review the main menu of HP ProtectTools Security Manager.

Under HP ProtectTools, you can find a couple of options. Use the Backup and Restore feature to protect or recover data files.

BIOS Configuration has a few helpful options as well. Here you can change and view the BIOS settings.

In the Security section under BIOS Configuration, you can enhance security by enabling passwords, Smart Card Power-On Support, TPM Embedded Security, Power-On Authentication, and more.

Go to Credential Manager to find several options that help protect your computer from unauthorized access. In this category, you can create a unique identity, set up multifactor authentication and use Single Sign-on (also called S_S_O), to store passwords for applications, websites and network resources.

Now that we've reviewed the other main menu categories in ProtectTools Security Manager, let's focus on Java Card Security and see how to use a smart card. The Java Card module has both general and advanced settings.

We'll get started by selecting General.

The screen that appears in the frame includes information about whether a smart card reader is available. Once the smart card is configured, additional information will appear on this screen.

Now let's select Advanced.

The New card dialog box appears automatically. Enter your credentials and then click OK.

A confirmation popup appears letting you know that a PIN has been successfully assigned. Click OK.

Notice that the Display Name is no longer blank. The Security Manager also indicates that security must still be configured in Computer Setup.

To do this setup, select BIOS Configuration in the main menu…

and then select Security.

Before setup options can be changed, you must set a password.

At the top of the page, click on Set to start the process.

A dialog box pops up where you will enter and confirm the password. Once you're done, click OK.

In addition to using a smart card, you can also set up a power-on password. You can configure that here as well.

This option is just below the other password setup. Click Set to get started.

Enter and confirm your password in the dialog box that appears and then click OK.

In the middle of the screen, select Enable to enable Smart Card Power-On Support.

Once you have set up the passwords and changed the necessary options, click Apply…

and then click OK.

A popup box appears as you must restart your computer before the new settings take effect. Make sure you remember the passwords you just set. After you restart, return to HP ProtectTools Security Manager and then navigate to Java Card Security to continue configuring smart card protection.

Once you're back in the Advanced settings for Java Card Security, select the checkbox to enable power-on authentication.

In the popup dialog box that appears, enter your Computer Setup password and then click OK.

In the next dialog window you'll enter your current PIN for the card. After this step is complete you'll need the card and PIN to start the computer.

The Java Card Security for HP ProtectTools dialog box appears confirming that power-on authentication is enabled. There's also information about saving a recovery file so that you can create a new Java Card if you misplace your current card. It's strongly recommended that you create a recovery file now.

Click OK to close this dialog box.

A setup wizard appears to create the backup. Click Next to continue.

Select the Java Card Security checkbox…

and then enter your PIN in the text box. Click Next to continue.

On the next screen enter and confirm a password for the recovery file. Although you can save the recovery file to your hard disk, it's highly recommended that you copy the file to removable media for safekeeping.

Once you've set up the password, click the checkbox for automated backups and then click Backup now.

Once the backup is complete, click Finish.

Now let's walk through the process to register the smart card and then see how to include it in the multifactor authentication process.

First select Credential Manager.

Click on Multifactor Authentication and then choose the Credentials tab. Highlight Smart Card Authentication to select it and then click Register.

In the dialog box that pops up, enter your smart card PIN and then click Finish.

After the registration process is complete, the dialog box will close. Note that the smart card shows as registered under Credentials.

To use the smart card for multifactor authentication, click the Policies tab.

The Token Registration Wizard dialog box appears. Your smart card PIN is already entered so click Finish.

You can select any multifactor authentication option. Notice that some options include and and some include or. For this demo, we'll leave the first option selected.

Back in the general options under Java Card Security, you can change your Java Card PIN by clicking on Change.

Go to the Advanced screen if you want to change your Java Card display name or card identity. Just click the appropriate Change button on the screen.

This wraps up our demonstration on using HP ProtectTools Security Manager. You've learned to configure the smart card for pre-book and Windows logon authentication. To end the demonstration, close the web browser demo window.

Write a review

» Please login to review
Printable versionPrintable version » Bookmark the Learning center E-mail this page Email this site
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2009 Hewlett-Packard Development Company, L.P.