Page 1

FingerprintSoftwareDeploymentGuide
Updated:September,2010
Page 2
Page 3

FingerprintSoftwareDeploymentGuide
Updated:September,2010
Page 4

Note:Beforeusingthisinformationandtheproductitsupports,readthegeneralinformationinAppendixB
“Notices”onpage33.
FirstEdition(September2010)
©CopyrightLenovo2010.
LENOVOproducts,data,computersoftware,andserviceshavebeendevelopedexclusivelyatprivateexpenseandare
soldtogovernmentalentitiesascommercialitemsasdenedby48C.F .R.2.101withlimitedandrestrictedrightsto
use,reproductionanddisclosure.
LIMITEDANDRESTRICTEDRIGHTSNOTICE:Ifproducts,data,computersoftware,orservicesaredeliveredpursuant
aGeneralServicesAdministration“GSA”contract,use,reproduction,ordisclosureissubjecttorestrictionssetforth
inContractNo.GS-35F-05925.
Page 5

Contents
Preface.................v
Chapter1.Overview..........1
Chapter2.Installation.........3
Installationproceduresandcommand-line
parameters.................3
Usingmsiexec.exe..............4
StandardWindowsInstallerpublicproperties...7
Installationexamples.............7
InstallingThinkVantageFingerprintSoftware....8
Silentinstallation.............8
Options.................9
InstallingLenovoFingerprintSoftware.....11
Silentinstallation............11
Options................11
Chapter3.WorkingwithFingerprint
Software................15
Managementconsoletool..........15
User-speciccommands.........15
Globalsettingscommands........16
Securemodeandconvenientmode......17
Securemode-administrator.......17
Securemode-limiteduser........18
Convenientmode-administrator.....18
Convenientmode-limiteduser......19
Chapter4.Workingwith
ThinkVantageFingerprintSoftware.21
UsingtheRSASecurIDsoftwaretoken.....21
ProvisioningtheThinkVantageFingerprint
SoftwarefortheRSASecurIDsoftware
token................21
GeneratinganRSASecurIDtokencode...22
AuthenticatingtheRSASecurID-protected
applications..............22
UsingtheThinkVantageFingerprintSoftware
withRSASecurIDReadyVPNclients....22
Considerationsforusingtheexternal
ngerprintreaderwiththeRSASecurID
softwaretoken.............23
UsingThinkVantageFingerprintSoftwarewith
NovellNetwareClient............23
Authenticating.............24
Congurablesettings............24
ThinkVantageFingerprintSoftwareservice....26
Chapter5.WorkingwithLenovo
FingerprintSoftware.........27
ActiveDirectorysupportforLenovoFingerprint
Software.................27
ConsiderationsforusingLenovoFingerprint
Software.................28
DeployingtheghostimagewithLenovo
FingerprintSoftware...........28
Erasingngerprintdata.........28
LenovoFingerprintSoftwareservice......28
AppendixA.Considerationsforthe
LenovoFingerprintKeyboard.....31
Congurationandsetup...........31
Pre-desktopauthentication..........31
Windowslogon..............31
AuthenticationwithClientSecuritySolution...32
AppendixB.Notices.........33
Trademarks................34
©CopyrightLenovo2010
iii
Page 6

ivFingerprintSoftwareDeploymentGuide
Page 7

Preface
InformationpresentedinthisguideistosupportLenovo
®
computersinstalledwitheithertheThinkVantage
orLenovoFingerprintSoftwareprogram.
Note:Inthisdeploymentguide,FingerprintSoftwarereferstobothThinkVantageFingerprintSoftwareand
LenovoFingerprintSoftware.
ThegoalofFingerprintSoftwareistohelpcustomersaddresscorporateITregulatorycompliance,reduce
thecostsassociatedwithmanagingpasswords,andenhancecomputingsecurity.
TheFingerprintSoftwareDeploymentGuideprovidestheinformationrequiredforinstallingFingerprint
Softwareononeormorecomputers,andalsoprovidesinstructionsandscenariosontheadministrative
toolsthatcanbecustomizedtosupportITandcorporatepolicies.
ThisguideisintendedforITadministrators,orthoseresponsiblefordeployingFingerprintSoftwareto
computersthroughouttheirorganizations.Ifyouhavesuggestionsorcomments,communicatewith
yourLenovoauthorizedrepresentative.Thisguideisupdatedperiodically,andyoucancheckthelatest
publicationontheLenovoWebsiteathttp://www-307.ibm.com/pc/support/site.wss/TVAN-ADMIN.html.
ForquestionsandinformationaboutusingthevariouscomponentsinFingerprintSoftwareworkspaces,
refertotheonlinehelpsystemanduserguidesthatcomewithFingerprintSoftware.
®
©CopyrightLenovo2010
v
Page 8

viFingerprintSoftwareDeploymentGuide
Page 9

Chapter1.Overview
TheobjectiveofbiometricngerprinttechnologiesofferedbyLenovoistohelpcustomersaddress
corporateITregulatorycompliance,reducethecostsassociatedwithmanagingpasswords,and
enhancecomputingsecurity.FingerprintSoftwareenablesngerprintauthenticationonindividual
computersandnetworksbyworkingwiththeLenovongerprintreaders.Itcanbeintegratedwith
ClientSecuritySolution8.3orPasswordManager.Formoreinformationabouttheintegrationwith
thetwoprograms,refertotheClientSecuritySolution8.3DeploymentGuide.Y oucanndoutmore
aboutLenovongerprinttechnologiesanddownloadFingerprintSoftwarefromtheLenovoWebsiteat:
http://www-307.ibm.com/pc/support/site.wss/document.do?lndocid=MIGR-73583.
FingerprintSoftwareoffersthesefunctions:
•Clientsoftwarecapabilities
–Microsoft
®
Windows
easy,fast,andsecuresystemaccess.
–BIOSpassword(alsoknownaspower-onpassword)andharddiskdrivepasswordsreplacement:
Replacepasswordswithyourngerprinttoenhancelogonsecurityandconvenience.
–Pre-bootngerprintauthenticationforSafeGuardEnterprisefull-driveencryption:Utilize
ngerprintauthenticationtodecryptyourharddiskdrivebeforestartingtheWindowsoperatingsystem.
–SingleswipetoaccesstheBIOSandtheWindowsoperatingsystem:Swipeyourngerprintat
startuptogainaccesstotheBIOSandtheWindowsoperatingsystem.
–Singleswipetoturnonthecomputer:Swipeyourngerprinttoturnonthecomputer.
®
passwordreplacement:Replaceyourpasswordwithyourngerprintfor
Note:Thisfeaturehasthedependencyonthehardware;therefore,itissupportedbycertaincomputer
models.
–FingerprintSoftwaresensorindicator:Indicatetheworkingstateofthesensor,andthesuccessin
swipingyourngerprintornot.
Note:Thisfeaturehasthedependencyonthehardware;therefore,itissupportedbycertaincomputer
models.
–IntegrationwithClientSecuritySolution:UsewiththeClientSecuritySolutionPasswordManager
andleveragetheTrustedPlatformModule.UserscanswipetheirngertoaccessWebsitesand
selectapplications.
•Administratorfeatures
–Securitymodetoggle:Allowanadministratortotogglebetweensecureandconvenientmodesto
modifyaccessrightsoflimitedusers.
•Securitycapabilities
–Softwaresecurity:Protectusertemplatesthroughstrongencryptionwhenstoredonasystemand
whentransferredfromthereadertothesoftware.
–Hardwaresecurity:Provideasecurityreaderwithaco-processorthatstoresandprotectsngerprint
templates,BIOSpasswords,andencryptionkeys.
©CopyrightLenovo2010
1
Page 10

2FingerprintSoftwareDeploymentGuide
Page 11

Chapter2.Installation
ThischaptercontainsinstructionsoninstallingFingerprintSoftware.
Installationproceduresandcommand-lineparameters
TheMicrosoftWindowsInstallerprovidesseveraladministrativefunctionsthroughcommand-line
parameters.TheWindowsInstallercanperformanadministrativeinstallationofanapplicationorproductto
anetworkforusebyaworkgrouporforcustomization.Command-lineoptionsthatrequireaparametermust
bespeciedwithnospacebetweentheoptionanditsparameter.Forexample:
setup.exe/s/v"/qnREBOOT="R""
isvalid,while
setup.exe/s/v"/qnREBOOT="R""
isnot.
Note:Thedefaultbehavioroftheinstallationwhenexecutedalone(runningsetup.exewithoutany
parameters)istoprompttheusertorebootattheendoftheinstallation.Arebootisrequiredfortheprogram
tofunctionproperly.Therebootcanbedelayedthroughacommandlineparameterforasilentinstallation
asdocumentedintheprecedingsectionandintheexamplesection.
FortheFingerprintSoftwareinstallationpackage,anadministrativeinstallationunpackstheinstallation
sourcelestoaspeciedlocation.
Torunanadministrativeinstallation,runthesetuppackagefromthecommandlineusingthe/aparameter:
setup.exe/a
Anadministrativeinstallationpresentsawizardthatpromptstheadministrativeusertospecifythelocations
forunpackingthesetuples.ThedefaultextractlocationisC:\.Youcanchooseanewlocationthatmay
includedrivesotherthanC:\(forexample,otherlocaldrivesormappednetworkdrives).Youcanalso
createnewdirectoriesduringthisstep.
Torunanadministrativeinstallationsilently,youcansetthepublicpropertyTARGETDIRonthecommand
linetospecifytheextractlocation:
setup.exe/s/v"/qnTARGETDIR=F:\TVTRR"
or
msiexec.exe/i"setup.msi"/qnTARGERDIR=F:\FPR
Note:IfyouarenotusingthelatestversionofWindowsInstaller,thesetup.exelewillbeconguredto
updatetheWindowsInstallerenginetothelatestversion.TheupdateoftheWindowsInstallerenginewill
promptyoutorebootthesystemeveninanadministrativeextractinstallation.T opreventarebootinthis
situation,youcanusetheREBOOTpropertyoftheWindowsInstaller.IftheWindowsInstalleristhelatest
version,thesetup.exelewillnotattempttoupdatetheWindowsInstallerengine.
©CopyrightLenovo2010
3
Page 12

Onceandadministrativeinstallationhasbeencompleted,theadministrativeusercanmakecustomizations
tothesourceles,suchasaddingsettingstotheregistry.
ThefollowingparametersanddescriptionsaredocumentedintheInstallShielddeveloperhelp
documentation.ParametersthatdonotapplytoBasicMSIprojectswereremoved.
Table1.Parameters
ParameterDescription
/a:administrativeinstallationThe/aswitchcausessetup.exetoperforman
administrativeinstallation.Anadministrativeinstallation
copies(anduncompresses)yourdatalestoadirectory
speciedbytheuser,butdoesnotcreateshortcuts,
registerCOMservers,orcreateanuninstallationlog.
/x:uninstallingmodeThe/xswitchcausessetup.exetouninstallapreviously
installedproduct.
/s:silentmodeThecommandsetup.exe/ssuppressesthesetup.exe
initializationwindowforaBasicMSIinstallationprogram,
butdoesnotreadaresponsele.BasicMSIprojectsdo
notcreateorusearesponseleforsilentinstallations.
TorunaBasicMSIproductsilently,runthecommand
linesetup.exe/s/v/qn.(T ospecifythevaluesof
publicpropertiesforasilentBasicMSIinstallation,
youcanuseacommandsuchassetup.exe/s/v"/qn
INSTALLDIR=D:\Destination".)
/v:passargumentstoMsiexecThe/vargumentisusedtopasscommandlineswitches
andvaluesofpublicpropertiesthroughtoMsiexec.
/L:setuplanguageUserscanusethe/Lswitchwiththedecimallanguage
IDtospecifythelanguageusedbyamulti-language
installationprogram.Forexample,thecommandto
specifyGermanissetup.exe/L1031.
/w:waitForaBasicMSIproject,the/wargumentforcessetup.exe
towaituntiltheinstallationiscompletebeforeexiting.If
youareusingthe/woptioninabatchle,youmaywant
toprecedetheentiresetup.execommandlineargument
withstart/WAIT.Aproperlyformattedexampleofthis
usageisasfollows:
start/WAITsetup.exe/w
Usingmsiexec.exe
Toinstallfromtheunpackedsourceaftermakingcustomizations,theusercallsmsiexec.exefromthe
commandline,passingthenameoftheunpacked*.MSIle.msiexec.exeistheexecutableprogramofthe
WindowsInstallerusedtointerpretinstallationpackagesandinstallproductsontargetsystems.
msiexec/i"C:\WindowsFolder\Proles\UserName\
Personal\MySetups\projectname\productconguration\releasename\
DiskImages\Disk1\productname.msi"
Note:Entertheprecedingcommandasasinglelinewithnospacesfollowingtheslashes.
Thefollowingtabledescribestheavailablecommandlineparametersthatcanbeusedwithmsiexec.exe
andexamplesofhowtouseit.
4FingerprintSoftwareDeploymentGuide
Page 13

Table2.Commandlineparameters
ParameterDescription
/Ipackageorproductcode
Usethisformattoinstalltheproduct:
Othello:msiexec/i"C:\WindowsFolder\Proles\
UserName\Personal\MySetups
\Othello\TrialVersion\
Release\DiskImages\Disk1\
OthelloBeta.msi"
ProductcodereferstotheGloballyUniqueIdentier(GUID)thatis
automaticallygeneratedintheproductcodepropertyofyourproduct's
projectview.
/apackageThe/aoptionallowsuserswithadministratorprivilegestoinstallaproduct
ontothenetwork.
/xpackageorproductcodeThe/xoptionuninstallsaproduct.
/L[i|w|e|a|r|u|c|m|p|v|+]logle
Buildingwiththe/Loptionspeciesthepathtothelogle;theseagsindicate
whichinformationtorecordinthelogle:
•ilogsstatusmessages
•wlogsnon-fatalwarningmessages
•elogsanyerrormessages
•alogsthecommencementofactionsequences
•rlogsaction-specicrecords
•ulogsuserrequests
•clogsinitialuserinterfaceparameters
•mlogsout-of-memorymessages
•plogsterminalsettings
•vlogstheverboseoutputsetting
•+appendstoanexistingle
•*isawildcardcharacterthatallowsyoutologallinformation(excluding
theverboseoutputsetting)
/q[n|b|r|f]
The/qoptionisusedtosettheuserinterfacelevelinconjunctionwiththe
followingags:
•qorqncreatesnouserinterface
•qbcreatesabasicuserinterface
/?or/h
Theuserinterfacesettingsbelowdisplayamodaldialogboxattheendof
installation:
•qrdisplaysareduceduserinterface
•qfdisplaysafulluserinterface
•qn+displaysnouserinterface
•qb+displaysabasicuserinterface
EithercommanddisplaysWindowsInstallercopyrightinformation
Chapter2.Installation5
Page 14

Table2.Commandlineparameters(continued)
ParameterDescription
TRANSFORMSTheTRANSFORMScommandlineparameterspeciesanytransformsthat
youwouldlikeappliedtoyourbasepackage.
msiexec/i"C:\WindowsFolder\
Proles\UserName\Personal
\MySetups\
YourProjectName\TrialVersion\
MyRelease-1
\DiskImages\Disk1\
ProductName.msi"TRANSFORMS="NewTransf orm1.mst"
Youcanseparatemultipletransformswithasemicolon.Donotusesemicolons
inthenameofyourtransform,astheWindowsInstallerservicewillinterpret
thoseincorrectly.
Properties
Allpublicpropertiescanbesetormodiedfromthecommandline.Public
propertiesaredistinguishedfromprivatepropertiesandareallcapitalletters.
Forexample,COMPANYNAMEisapublicproperty.
Tosetapropertyfromthecommandline,usethefollowingsyntax:
PROPERTY=VALUE
IfyouwantedtochangethevalueofCOMPANYNAME,youwouldenterthe
following:
msiexec/i"C:\WindowsFolder\
Proles\UserName\Personal\
MySetups\YourProjectName\
TrialVersion\MyRelease-1\
DiskImages\Disk1\ProductName.msi"
COMPANYNAME="InstallShield"
6FingerprintSoftwareDeploymentGuide
Page 15

StandardWindowsInstallerpublicproperties
TheWindowsInstallerhasasetofstandardbuiltinpublicpropertiesthatcanbesetonthecommand
linetospecifycertainbehaviorduringtheinstallation.Thefollowingtableprovidesmostcommonpublic
propertiesusedinthecommandline.
Foradditionalinformation,refertotheMicrosoftWebsiteat:
http://msdn2.microsoft.com/en-us/library/aa367437.aspx.
ThefollowingtableshowsthecommonlyusedWindowsInstallerproperties:
Table3.WindowsInstallerproperties
PropertyDescription
TARGETDIRSpeciestherootdestinationdirectoryfortheinstallation.
Duringanadministrativeinstallationthispropertyisthe
locationtocopytheinstallationpackage.
ARPAUTHORIZEDCDFPREFIX
ARPCOMMENTSProvidesCommentsfortheAddorRemovePrograms
ARPCONTACTProvidesContactfortheAddorRemoveProgramson
ARPINSTALLLOCA TION
ARPNOMODIFY
ARPNOREMOVE
ARPNOREPAIR
ARPPRODUCTICONSpeciestheprimaryiconfortheinstallationpackage.
ARPREADME
ARPSIZE
ARPSYSTEMCOMPONENT
ARPURLINFOABOUT
ARPURLUPDA TEINFO
REBOOTTheREBOOTpropertysuppressescertainpromptsfor
URLoftheupdatechannelfortheapplication.
onControlPanel.
ControlPanel.
Fullyqualiedpathtotheapplication'sprimaryfolder.
Disablesfunctionalitythatwouldmodifytheproduct.
Disablesfunctionalitythatwouldremovetheproduct.
DisablestheRepairbuttonintheProgramswizard.
ProvidesaReadMefortheAddorRemoveProgramson
ControlPanel.
Estimatedsizeoftheapplicationinkilobytes.
PreventsdisplayofapplicationintheAddorRemove
Programslist.
URLforanapplication'shomepage.
URLforapplication-updateinformation.
arebootofthesystem.Anadministratortypicallyuses
thispropertywithaseriesofinstallationstoinstallseveral
productsatthesametimewithonlyonerebootatthe
end.SetREBOOT="R"todisableanyrebootsattheend
ofaninstall.
Installationexamples
Thefollowingtableprovidestheinstallationexamplesusingthesetup.exele.
Chapter2.Installation7
Page 16

Table4.Installationexamplesusingthesetup.exele
DescriptionExample
Silentinstallationwithnoreboot
setup.exe/s/v"/qnREBOOT="R""
Administrativeinstallation
Silentadministrativeinstallationspecifyingtheextract
location
Silentuninstallation
setup.exe/a
setup.exe/a/s/v"/qnTARGETDIR="F:\fpr""
setup.exe/s/x/v/qn
Thefollowingtableprovidestheinstallationexamplesusingthesetup.msile.
Table5.Installationexamplesusingthesetup.msile
DescriptionExample
Installation
Silentinstallationwithno
reboot
Silentuninstallation
msiexec/isetup.msi
msiexec/isetup.msi/qnREBOOT="R"
msiexec/xsetup.msi/qn
InstallingThinkVantageFingerprintSoftware
Thesetup.exeleofThinkVantageFingerprintSoftwareprogramcanbeinstalledthroughthefollowing
methods:
Silentinstallation
TosilentlyinstallThinkVantageFingerprintSoftware,runthesetup.exelelocatedintheinstallationdirectory
onyourCD-ROMdrive.
Usethefollowingsyntax:
Setup.exePROPERTY=VALUE/q/i
whereqisforsilentinstallationandiisforinstallation.Forexample:
setup.exeINSTALLDIR="C:\ProgramFiles\ThinkVantagengerprintsoftware"/q/i
Touninstallthesoftware,usethe/xparameterinsteadof/i:
setup.exeINSTALLDIR="C:\ProgramFiles\ThinkVantagengerprintsoftware"/q/x
8FingerprintSoftwareDeploymentGuide
Page 17

Options
ThefollowingoptionsaresupportedbytheThinkVantageFingerprintSoftware.
Table6.OptionssupportedbytheThinkVantageFingerprintSoftware
ParameterDescription
OTP•0=DisabletheRSASecurIDsupportfeature.
•1=EnabletheRSASecurIDsupportfeature.
Thedefaultvalueis0.
CTRLONCEDisplaystheControlCenteronlyonce.Thedefaultvalue
is0.
CTLCNTR•0=DonotdisplayControlCenteratstartup.
•1=DisplayControlCenteratstartup.
Thedefaultvalueis1.
DEFFUS•0=DonotuseFastUserSwitching(FUS)settings.
•1=UseFUSsettings.
Thedefaultvalueis0.
DEVICEBIOConguresthedevicetypethatwillbeusedbytheuser.
•DEVICEBIO=#3-Usethedevicesensortosavethe
rstenrollment.
•DEVICEBIO=#0-Usetheharddiskdrivetosavethe
enrollment.
•DEVICEBIO=#1-UsetheCompanionChiptosavethe
enrollment.
INSTALLDIRSettheinstallationdirectory.
OEM
PASSPORTSetthedefaultpassporttype.
POSSSO
PSLOGON
REBOOTSuppressesallrebootsincludingpromptsduring
SECURITY
•0=Installwithsupporttoserverpassportsorserver
authentication.
•1=Installonlystandalone-computermodewithlocal
passports.
Thedefaultvalueis1.
•1=Localpassport
•2=Serverpassport
Thedefaultvalueis1.
•1=Enablesinglesign-on.
•0=Disablesinglesign-on.
Thedefaultvalueis1.
•0=Disablethengerprintlogon.
•1=Enablethengerprintlogon.
Thedefaultvalueis0.
installationbysettingtoReallySuppress.
•1=Installinthesecuremode.
•0=Installintheconvenientmode.
Chapter2.Installation9
Page 18

Table6.OptionssupportedbytheThinkVantageFingerprintSoftware(continued)
ParameterDescription
SHORTCUT•0=DonotdisplayControlCentershortcutatstartup.
•1=EnablethedisplayofControlCentershortcutat
startup.
Thedefaultvalueis0.
SHORTCUTFOLDERSetthedefaultnameoftheshortcutfolderintheStart
menu.
Non-administratoruserprivileges
DELETESELF
ENROLLSELF
ENROLLTBX
IMPORTSELF•1=Enablethengerprintimport/exportfor
REVEALPWD•1=EnabletheWindowspasswordrecovery.
Anti-hammeringprotection(LockoutSettings)
LOCKOUT
LOCKOUTCOUNT
LOCKOUTTIME
Authenticationtimeout(InactivitySettings)
GUITMENABLE
GUITMTIME
•1=Enablethengerprintdeletion.
•0=Disablethengerprintdeletion.
Thedefaultvalueis1.
•1=Enablethengerprintenrollment.
•0=Disablethengerprintenrollment.
Thedefaultvalueis1.
•1=Enabletheselectionofngerprintforpower-on.
•0=Disabletheselectionofngerprintforpower-on.
Thedefaultvalueis1.
non-administratorusers.
•0=Disablethengerprintimport/exportfor
non-administratorusers.
Thedefaultvalueis1.
•0=DisabletheWindowspasswordrecovery.
Thedefaultvalueis1.
•1=Enabletheanti-hammeringprotection.
•0=Disabletheanti-hammeringprotection.
Thedefaultvalueis1.
Maximumretries.Thedefaultvalueis5,andyoucanuse
anyvalue.
Timeoutinmilliseconds.Thedefaultvalueis120000,and
youcanuseanyvalueupto360000.
•1=Enabletheauthenticationtimeoutinmilliseconds.
•0=Disabletheauthenticationtimeoutinmilliseconds.
Thedefaultvalueis1.
Authenticationtimeoutduration.Thedefaultvalueis120
000,andyoucanuseanyvalueupto360000.
10FingerprintSoftwareDeploymentGuide
Page 19

Table6.OptionssupportedbytheThinkVantageFingerprintSoftware(continued)
ParameterDescription
PWDLOGON
NOPOPPAPCHECK
CSS•0=AssumethatClientSecuritySolutionhasnotbeen
•1=Enablethengerprint-onlylogonfor
non-administratorusers.
•0=Disablethengerprint-onlylogonfor
non-administratorusers.
Thedefaultvalueis1.
•0=Donotshowthepower-onsecurityoptions.
•1=Alwaysshowthepower-onsecurityoptions.
Thedefaultvalueis0.
installed.
•1=AssumethatClientSecuritySolutionhasbeen
installed.
Thedefaultvalueis0.
Note:Alloptionsareoptional.
TouninstalltheFingerprintSoftware,usethe/xparameterinsteadof/i.Duringthestandarduninstallfrom
theuserinterface,dialogsforselectingwhethertodeleteexistingpassportsanddisablethebootsecurity
featurearedisplayed.Inthesilentuninstallmode,youcanusetheDELPASparameter.SettheDELPAS
valueto"1"todeleteexistingpassports.Iftheseoptionsarenotdened,orhaveanyothervalue,passports
areleftonthecomputerandthebootsecurityremainsenabled.Ifyouleavethebootsecurityon,youwill
notbeabletoeditngerprintsinthebootsecuritymemoryunlessyoure-installtheproduct.Forexample,
runningthefollowingsyntax:
msiexec/iSetup.msiDELPAS="1"/q
woulduninstalltheproduct,deleteallexistingpassports,andleavethebootsecurityonthecomputer.
InstallingLenovoFingerprintSoftware
Thesetup32.exeleoftheLenovoFingerprintSoftwareprogramcanbeinstalledbyusingthefollowing
procedure.
Silentinstallation
TosilentlyinstalltheFingerprintSoftware,runthesetup32.exelelocatedintheinstallationdirectory
onyourCD-ROMdrive.
Usethefollowingsyntax:
setup32.exe/s/v"/qnREBOOT="R""
Touninstallthesoftware,usethefollowingsyntax:
setup32.exe/x/s/v"/qnREBOOT="R""
Options
ThefollowingoptionsaresupportedbyLenovoFingerprintSoftware.
Chapter2.Installation11
Page 20

Table7.OptionssupportedbytheLenovoFingerprintSoftware
ParameterDescription
SHORTCUTDisplaysControlCentershortcutintheStartmenu.
•0=DonotdisplaytheControlCentershortcut.
•1=DisplaytheControlCentershortcut.
Thedefaultvalueis0.
SWAUTOSTART
SWFPLOGON•0=Donotusethengerprintlogon(GINAorCredential
SWPOPP
SWSSO
SWALLOWENROLL
SWALLOWDELETE
SWALLOWIMEXPORT•0=Disablethengerprintimport/exportfor
SWALLOWSELECT
SWALLOWPWRECOVERY
•0=Donotstartngerprintsoftwareatstartup.
•1=Startngerprintsoftwareatstartup.
Thedefaultvalueis1.
Provider).
•1=Usethengerprintlogon(GINAorCredential
Provider).
Thedefaultvalueis0.
•0=Disablepower-onpasswordprotection.
•1=Enablepower-onpasswordprotection.
Thedefaultvalueis0.
•0=Disablethesinglesign-onfunction.
•1=Enablethesinglesign-onfunction.
Thedefaultvalueis0.
•0=Disablethengerprintenrollmentfor
non-administratorusers.
•1=Enablethengerprintenrollmentfor
non-administratorusers.
Thedefaultvalueis1.
•0=Disablethengerprintdeletionfornon-administrator
users.
•1=Enablethengerprintdeletionfornon-administrator
users.
Thedefaultvalueis1.
non-administratorusers.
•1=Enablethengerprintimport/exportfor
non-administratorusers.
Thedefaultvalueis1.
•0=Disabletheselectionofusingngerprinttoreplace
power-onpasswordfornon-administratorusers.
•1=Enabletheselectionofusingngerprinttoreplace
power-onpasswordfornon-administratorusers.
Thedefaultvalueis1.
•0=DisabletheWindowspasswordrecovery.
•1=EnabletheWindowspasswordrecovery.
Thedefaultvalueis1.
12FingerprintSoftwareDeploymentGuide
Page 21

Table7.OptionssupportedbytheLenovoFingerprintSoftware(continued)
ParameterDescription
SWANTIHAMMER
•0=Disabletheanti-hammeringprotection.
•1=Enabletheanti-hammeringprotection.
Thedefaultvalueis1.
SWANTIHAMMERRETRIESSpeciesthemaximumretries.Thedefaultvalueis5.
Note:ThissettingworksonlywhenSWANTIHAMMERis
enabled.
SWANTIHAMMERTIMEOUTSpeciesthetimeoutdurationinseconds.Thedefault
valueis120.
Note:ThissettingworksonlywhenSWANTIHAMMERis
enabled.
SWAUTHTIMEOUT
•0=Disabletheauthenticationtimeout.
•1=Enabletheauthenticationtimeout.
Thedefaultvalueis1.
SWAUTHTIMEOUTVALUESpeciestheperiodofinactivitybeforeauthentication
timeoutinseconds.Thedefaultvalueis120.
Note:ThissettingworksonlywhenSWAUTHTIMEOUTis
enabled.
SWNONADMIFPLOGONONLY
•0=Disablethengerprint-onlylogonfor
non-Administratorusers.
•1=Enablethengerprint-onlylogonfor
non-Administratorusers.
Thedefaultvalueis1.
SWSHOWPOWERON
•0=Donotshowthepower-onsecurityoptions.
•1=Alwaysshowthepower-onsecurityoptions.
Thedefaultvalueis0.
CSS•0=AssumethatClientSecuritySolutionhasnotbeen
installed.
•1=AssumethatClientSecuritySolutionhasbeen
installed.
Thedefaultvalueis0.
Chapter2.Installation13
Page 22

14FingerprintSoftwareDeploymentGuide
Page 23

Chapter3.WorkingwithFingerprintSoftware
ThischapterprovidestheinformationyouwillneedtocongureFingerprintSoftware.Withinthischapter,
youmayndthefollowingtopics:
•“Managementconsoletool”onpage15
•“Securemodeandconvenientmode”onpage17
ThinkVantageFingerprintSoftwareandLenovoFingerprintSoftwaregowithtwodifferentkindsofngerprint
readers.ThinkVantageFingerprintSoftware5.8.5.XXXXor5.9.3.XXXXgoeswiththeUpekngerprintreader;
LenovoFingerprintSoftware3.3.2.XXXXgoeswiththeAuthenticngerprintreader.Y oucancheckthe
ngerprintreadertypeintheBiometricsectionofDeviceManager.
•ForthedetailedinformationaboutThinkVantageFingerprintSoftware,gotoChapter4“Workingwith
ThinkVantageFingerprintSoftware”onpage21
•ForthedetailedinformationaboutLenovoFingerprintSoftware,gotoChapter5“WorkingwithLenovo
FingerprintSoftware”onpage27.
Managementconsoletool
ThemanagementconsoletoolisfortheadministratortocongureFingerprintSoftwarethroughcommand
lines.Thissectionprovidesinformationaboutuser-speciccommandsandglobalsettingcommands.
Note:TheManagementconsoletooldoesnotcomewiththeinstallationpackageofFingerprintSoftware.
Foranydetailedinformationaboutthemanagementconsoletool,contactLenovoSupport.
.
User-speciccommands
Toenrolloreditusers,theUSERsectionisused.Whenthecurrentuserdoesnothaveadministrator
rights,theconsolebehaviordependsonthesecuritymodeoftheFingerprintSoftware.Securemode:no
commandsareallowed.Convenientmode:ADD,EDITandDELETEcommandsarepossibleforstandard
user.However,theusercanmodifyonlyhisownpassport(enrolledwithhisusername).Thefollowingis
thesyntax:
FPRCONSOLEUSERcommand
wherecommandisoneofthefollowingcommands:ADD,EDIT,DELETE,LIST,IMPORT,EXPORT.
Table8.User-speciccommands
CommandSyntaxDescription
Enrollnewuser
Example:
fprconsoleuseradd
domain0\testuser
fprconsoleuseradd
testuser
ADD[username[|domain\
username]]
Iftheusernameisnotspecied,then
thecurrentusernameisused.
©CopyrightLenovo2010
15
Page 24

Table8.User-speciccommands(continued)
CommandSyntaxDescription
Editenrolleduser
Example:
fprconsoleuseredit
domain0\testuser
fprconsoleuseredit
testuser
EDIT[username[|domain\
username]]
Iftheusernameisnotspecied,then
thecurrentusernameisused.
Note:Theenrolledusermustverifyhis
ngerprintrst.
Deleteauser
Example:
fprconsoleuserdelete
domain0\testuser
fprconsoleuserdelete
testuser
fprconsoleuserdelete
/ALL
Enumerateenrolledusers
Exportenrolledusertoale
Importenrolleduser
DELETE[username[|domain\
username|/ALL]]
List
Syntax:EXPORTusername
[|domain\username]le
Syntax:IMPORTle
The/ALLagwilldeleteallusers
enrolledonthiscomputer.Iftheuser
nameisnotspeciedthenthecurrent
usernameisused.
Liststheenrolledusers.
Thiscommandwillexportanenrolled
usertoaleontheharddiskdrive.The
userthencanbeimportedusingthe
IMPORTcommandonothercomputer
oronthesamecomputer,iftheuser
isdeleted.
Thecommandwillimporttheuserfrom
thespeciedle.
Note:Iftheuserintheleisalready
enrolledonthesamecomputerusing
thesamengerprintsthenitisnot
guaranteedwhichuserwillhave
aprecedenceintheidentication
operation.
Globalsettingscommands
TheglobalsettingsoftheFingerprintSoftwarecanbechangedbytheSETTINGSsection.Allthecommands
inthissectionneedadministratorsrights.Thesyntaxis:
FPRCONSOLESETTINGScommand
wherecommandisoneofthefollowingcommands:SECUREMODE,LOGON,CAD,TBX,SSO.
16FingerprintSoftwareDeploymentGuide
Page 25

Table9.Globalsettingscommands
CommandSyntaxDescription
Securitymode
Example:
Tosettoconvenientmode:
fprconsolesettings
securemode0
SECUREMODE0|1
ThissettingswitchesbetweenConvenient
andSecuremodeoftheFingerprint
Software.
Logontype
LOGON0|1[/FUS]
CTRL+ALT+DELmessage
CAD0|1
Power-onsecurity
TBX0|1
Power-onsecuritysinglesign-on
SSO0|1
Thissettingenables(1)ordisables(0)the
logonapplication.Ifthe/FUSparameter
isusedthelogonisenabledinFast
UserSwitchingmodeifthecomputer
congurationallowsthis.
Thissettingenables(1)ordisables(0)the
PressCtrl+Alt+Deletetextinlogon.
Thissettinggloballyturnsoff(0)power-on
securitysupportinthengerprintsoftware.
Whenthepower-onsecuritysupportis
turnedoffnopower-onsecuritywizardsor
pagesareshownanditdoesnotmatter
whataretheBIOSsettings.
Thissettingenables(1)ordisables(0)the
usageofngerprintusedinBIOSinlogon
toautomaticallylogonuserwhentheuser
wasveriedinBIOS.
Securemodeandconvenientmode
FingerprintSoftwarecanberunintwosecuritymodes,asecuremodeandaconvenientmode.Thesecure
modeisintendedforsituationswhenyouwanttoachievehighersecurity.Specialfunctionsarereservedfor
administratorsonly.Onlyadministratorscanlogonusingpasswordwithoutadditionalauthentication.
Theconvenientmodeisintendedforhomecomputerswhereahighsecuritylevelisnotsoimportant.Allthe
userscanperformalloperations,includingeditingpassportsofotherusersandpossibilitytologontothe
systemusingpassword(withoutngerprintauthentication).
Anadministratorisanymemberoflocaladministratorsgroup.Afteryousetthesecuremode,onlythe
administratorcantoggleitbacktotheconvenientmode.
Securemode-administrator
Toenhancesecurity,ifthewrongusernameorpasswordistypedatlogon,thesecuremodedisplaysthe
followingmessage:“Onlyadministratorscanlogonthiscomputerwithusernameandpassword.”
Table10.Optionsforadministratorsinthesecuremode
FingerprintsDescription
Createanewpassport
EditPassportsAdministratorscaneditonlytheirownpassport.
Administratorscancreatetheirownpassportandthey
canalsocreatethepassportofalimiteduser.
Chapter3.WorkingwithFingerprintSoftware17
Page 26

Table10.Optionsforadministratorsinthesecuremode(continued)
FingerprintsDescription
DeletePassportAdministratorscandeletealllimiteduserandother
administratorpassports.Ifotherusersareusingpower-on
security,theadministratorwillhavetheoptiontoremove
usertemplatesfrompower-onsecurityatthistime.
Power-onSecurity
Settings
LogonsettingsAdministratorscanmakechangestoalllogonsettings.
ProtectedscreensaverAdministratorscanaccess.
PassporttypeAdministratorscanaccess-onlyrelevantwithserver.
Securitymode
ProServers
AdministratorscandeleteLimiteduserandadministrator
ngerprintsusedinpower-on.
Note:Theremustatleastbeonengerprintpresentwhen
power-onmodeisenabled.
Administratorscantogglebetweensecureandconvenient
modes.
Administratorscanaccess-onlyrelevantwithserver.
Securemode-limiteduser
DuringaWindowslogon,alimitedusermustuseangerprinttologon.Ifthelimiteduserngerprintreader
isnotworking,anadministratorwillneedtochangethengerprintsoftwaresettingtoconvenientmodeto
enableusernameandpasswordaccess.
Table11.Optionsforlimitedusersinthesecuremode
SettingDescription
Createanewpassport
EditPassportsLimitedusercaneditonlytheirownpassport.
DeletePassportLimitedusercandeleteonlytheirownpassport.
Power-onSecurity
Logonsettings
ProtectedscreensaverLimitedusercanaccess.
PassporttypeLimitedusercannotaccess.
Securitymode
ProServers
Limitedusercannotaccess.
Limitedusercannotaccess.
Limitedusercannotmodifylogonsettings.
Limitedusercannotmodifysecuritymodes.
Limitedusercanaccess-onlyrelevantwithserver.
Convenientmode-administrator
DuringaWindowslogon,administratorscanlogonusingeithertheirusernameandpasswordortheir
ngerprint.
Table12.Optionsforadministratorsintheconvenientmode
SettingsDescription
Createanewpassport
EditPassportsAdministratorscaneditonlytheirownpassport.
DeletePassportAdministratorscandeleteonlytheirownpassport.
Administratorscancreateonlytheirownpassport.
18FingerprintSoftwareDeploymentGuide
Page 27

Table12.Optionsforadministratorsintheconvenientmode(continued)
SettingsDescription
Power-onSecurity
LogonsettingsAdministratorscanmakechangestoalllogonsettings.
ProtectedscreensaverAdministratorscanaccess.
PassporttypeAdministratorscanaccess-onlyrelevantwithserver.
Securitymode
ProServers
AdministratorscandeleteLimiteduserandadministrator
ngerprintsusedinpower-on.
Note:Theremustbeatleastonengerprintpresentwhen
power-onmodeisenabled.
Administratorscantogglebetweensecureandconvenient
modes.
Administratorscanaccess-onlyrelevantwithserver.
Convenientmode-limiteduser
DuringaWindowslogon,limiteduserscanlogonusingeithertheirusernameandpasswordortheir
ngerprint.
Table13.Optionsforlimitedusersintheconvenientmode
SettingsDescription
Createanewpassport
EditPassportsLimiteduserscaneditonlytheirownpassport.
DeletePassportLimiteduserscandeleteonlytheirownpassport.
Power-onSecurity
Logonsettings
ProtectedscreensaverLimiteduserscanaccess.
PassporttypeLimiteduserscannotaccess-onlyrelevantwithserver.
Securitymode
ProServers
Limiteduserscancreateonlytheirownpassword.
Limiteduserscandeleteonlytheirownngerprints.
Limiteduserscannotmodifylogonsettings.
Limiteduserscannotmodifysecuritymodes.
Limiteduserscanaccess-onlyrelevantwithserver.
Chapter3.WorkingwithFingerprintSoftware19
Page 28

20FingerprintSoftwareDeploymentGuide
Page 29

Chapter4.WorkingwithThinkVantageFingerprintSoftware
ThengerprintconsolemustberunfromtheThinkVantageFingerprintSoftwareinstallationfolder.Thebasic
syntaxisFPRCONSOLE[USER|SETTINGS].TheUSERorSETTINGScommandspecieswhichmodeof
operationwillbeused.Thefullcommandisthen"fprconsoleuseraddTestUser".Whenthecommandisnot
knownornotallparametersarespecied,theshortcommandlistisshowntogetherwiththeparameters.
ThinkVantageFingerprintSoftware,installationinstructions,managementconsole,andallrelated
documentationareavailableat:
http://www-307.ibm.com/pc/support/site.wss/TVAN-EAPFPR.html
UsingtheRSASecurIDsoftwaretoken
ThinkVantageFingerprintSoftwareprovisionedwiththeRSASecurIDsoftwaretokenprovidesastrong
authenticationapproachwithoutsacricingenduser’sconvenience.Whenintegratedintocomputersand
computerperipherals,auser'sngerprintcanbeusedasanadditionalauthenticationfactortosecureaccess
todevices,networks,andweb-basedapplicationsandportalsprotectedbytheRSASecurIDsoftwaretoken.
ProvisioningtheThinkVantageFingerprintSoftwarefortheRSASecurID
softwaretoken
TheThinkVantageFingerprintSoftwarecanbeprovisionedviathestandardRSASecurIDsoftwaretoken
le-basedprovisioningmethod,andthereisnoadditionalcongurationrequiredtointer-operatewith
yourexistingRSASecurIDinfrastructure.
Note:TheRSASecurIDsoftwaretokenversion2.0isnotsupportedforusewiththeThinkVantage
FingerprintSoftware.OnlytheRSASecurIDsoftwaretokenversion3.0issupported.
TosetuptheThinkVantageFingerprintSoftwareandimporttheRSASecurIDsoftwaretoken,dothe
following:
1.DownloadtheThinkVantageFingerprintSoftwareversion5.9.3.XXXX(fortheWindows7operating
system)orversion5.8.5.XXXX(fortheWindowsVista
http://www-307.ibm.com/pc/support/site.wss/document.do?lndocid=MIGR-73583.
2.MakesureyousetOTP=1atthecommandlinetoenabletheRSASecurIDsupportfeatureduringthe
installation.Forexample,youcanrunthefollowingcommand:
msiexec-isetup.msi/qnOTP=1.
3.Aftertheinstallationprocesscompletes,restartyourcomputerandenrollyourngerprints.
4.LaunchtheThinkVantageFingerprintSoftware,andclickSecurityTokenstoimporttheRSASecurID
softwaretoken.
5.ClickAdd,andintheTokennameledtypeanameforthetokenyouareimporting.
6.ClickBrowsetoselectthetokenle.
Note:Ifthetokenleispassword-protected,enterthepasswordrst;iftheleisamulti-tokenle,you
willbeaskedtoselectthattokenletobeimported.
7.ClickImport.IftheRSASecurIDsoftwaretokenhasbeensuccessfullyimported,theRSASecurIDicon
willbedisplayedintheYourSecurityT okenssection.
®
orWindowsXPoperatingsystem)at:
©CopyrightLenovo2010
21
Page 30

GeneratinganRSASecurIDtokencode
WhentheThinkVantageFingerprintSoftwarehasbeenprovisionedwithanRSASecurIDsoftwaretoken,you
willbeabletogenerateanRSASecurIDtokencodefromabiometricreaderembeddedinthecomputeror
keyboard.
TogenerateanRSASecurIDtokencode,dothefollowing:
1.ClickStart➙ThinkVantage➙TokencodesGenerator.
2.TheSwipengerwindowisdisplayedtoaskyoutoswipeyourngerprint.
3.Swipeyourngerprinttoauthenticateyouraccount.
4.Selectthetokenyouwanttousefromthedrop-downlistbox.Ifyouhavejustonetoken,thetokencode
willbegeneratedautomatically.
Note:Awindowwillbedisplayedindicatingthevaliddurationofthegeneratedtokencode.The
tokencodeistime-basedanditexpiresafteracertainperiodoftime(typicallyoneminute).Ifthisisa
pinlesstoken,thenthetokencodecanbecopied,pastedorentereddirectlyintoanyapplicationdialogs.
5.Ifthisisapinfultoken,selectUsePIN,enteryourPIN,andclickOK.YoucanalsoselectRemember
thePINtohaveyourpinenteredautomatically.
6.TheTokencodeledwilldisplaytheRSASecurIDtokencodethatcanbeusedforauthenticatingthe
systemsandapplicationsprotectedbytheRSASecurIDsoftwaretoken.Ifyouarepromptedtoenter
theNextT okenmode,selectNexttogenerateanothertokencode.
AuthenticatingtheRSASecurID-protectedapplications
ThefollowingexampleshowshowtousetheRSASecurIDtokencodegeneratedbytheThinkVantage
FingerprintSoftwaretoauthenticatetheRSASecurID-protectedapplications.
1.LaunchaWeb-basedapplicationthatisprotectedbytheRSASecurIDsoftwaretoken,andtheRSA
SecurIDloginwindowisdisplayed.
2.ClickStart➙ThinkVantage➙TokencodesGenerator,andswipeyourngerprinttoauthenticate
youraccount.
3.SelecttheRSASecurIDsoftwaretokenthatprotectstheapplication.Ifthisisapinfultoken,select
UserPIN,andenterthepin.
4.ClickCopytocopytheautomaticallygeneratedtokencode.
5.EntertheusernameintheUserIDeld,andpastethetokencodeyoujustcopiedinthePasscodeled.
6.ClickLogintostarttheauthenticationprocess.
UsingtheThinkVantageFingerprintSoftwarewithRSASecurIDReady
VPNclients
TheThinkvantageFingerprintSoftwarecanbeusedwithanumberofRSASecurIDReadyVPNclientsthat
havetheRSASecurIDsoftwaretokentoprovideenhancedusability.Inthiscase,youareonlyrequiredto
enterthePINfortheRSASecurIDsoftwaretoken,andswipeyourngerprinttoauthorizethereleaseofa
tokencodetotheVPNclient.ThentheVPNclientcanbesuccessfullyconnected.
BeforeenablingtheRSASecurIDReadyVPNclients,youneedtoinstallandconguretheCheckpoint
SecuRemoteprogramasfollows:
1.DownloadtheCheckpointSecuRemoteprogramat:
https://supportcenter.checkpoint.com/supportcenter/portal/user/anon/page/default.psml/
media-type/html?action=portlets.DCFileAction&eventSubmit_doGetdcdetails=&leid=10625,andinstall
theprogramwhenthedownloadprocesscompletes.
22FingerprintSoftwareDeploymentGuide
Page 31

2.Duringtheprograminstallationprocess,selectInstallVPN-1SecuRemoteintheDesktopSecurity
window.
3.Followtheinstructionsonthescreenandrestartthecomputer.
4.Right-clicktheSecuRemoteiconintheWindowsnoticationarea,andselectConnect.Amessageis
displayedtoremindyoutocreateanewsite.ClickY es.
5.TheSiteWizardisdisplayed.EntertheserveraddressornameintheSeverAddressorNameeld,
andclickNext.
6.SelectSecurIDastheauthenticationmethod,andclickNext.
7.SelectUseSecurIDSoftwaretoken,andclickNext.
8.EntertheusernameandPINassociatedwithyourRSASecurIDsoftwaretoken.
9.SelectStandard,andclickNext.
10.FollowtheinstructionsonthescreentosuccessfullyconguretheCheckpointSecuRemoteprogram.
ConsiderationsforusingtheexternalngerprintreaderwiththeRSA
SecurIDsoftwaretoken
Forsecurityreasons,theimportedRSASecurIDsoftwaretokenisalwaysboundwithangerprintreader.
Thenthefollowingtwoscenariosexist:
•WhenyouimporttheRSASecurIDsoftwaretoken,andonlytheinternalngerprintreaderispresent,then
theimportedtokenisalwaysboundwiththeinternalngerprintreader.
•WhenyouimporttheRSASecurIDsoftwaretoken,andboththeinternalandexternalngerprintreaders
arepresent,thentheimportedtokenisboundwiththengerprintreaderthatissetasthepreferred
deviceintheBIOS.
Inthiscase,whenyouwanttoaccesstheRSASecurIDsoftwaretokentogenerateatokencode,youmust
connectthengerprintreaderwithwhichthetokenisboundtothecomputer.Iftwongerprintreadersare
present,youmustsetthengerprintdevicewithwhichthetokenisboundasthepreferreddeviceinthe
BIOS.Otherwise,youwillfailingeneratingatokencode.
ForThinkVantageFingerprintSoftware5.9.3.XXXX,ifyouconnectthengerprintdevicewithwhichthe
importedRSASecurIDsoftwaretokenisboundtothecomputer,andthepriorityofthengerprintdeviceis
setaccordinglyintheBIOS,thenyoucanswipeyourngerprintoneithertheinternalorexternalngerprint
readertoverifyandgenerateatokencode.However,forThinkVantageFingerprintSoftware5.8.5.XXXX,
youcanswipeyourngerprinttoverifyandgenerateatokencodeonlyonthengerprintreaderthatis
setasthepreferreddeviceintheBIOS.
UsingThinkVantageFingerprintSoftwarewithNovellNetwareClient
Topreventconicts,FingerprintSoftwareandNovellNetwareClientusernamesandpasswordsmustmatch.
IfyouhaveFingerprintSoftwareinstalledonyourcomputerandtheninstalltheNovellNetwareClient,some
itemsintheregistrymightbeoverwritten.IfyouencounterproblemswithFingerprintSoftwarelogon,goto
thelogonsettingsscreenandre-enabletheLogonProtector.
IfyouhavetheNovellNetwareClientinstalledonyourcomputerbuthavenotloggedontotheclientbefore
installingFingerprintSoftware,theNovellLogonscreenwilldisplay.Providetheinformationrequestedby
thescreen.
Note:TheinformationinthissectionisforThinkVantageFingerprintSoftwareonly.
TochangeLogonProtectorSettings:
•StarttheControlCenter.
Chapter4.WorkingwithThinkVantageFingerprintSoftware23
Page 32

•ClickSettings.
•ClickLogonsettings.
•EnableordisableLogonProtector.Ifyouwanttousengerprintlogon,checktheReplaceWindows
logonwithngerprint-protectedlogoncheckbox.
Note:EnablinganddisablingLogonProtectorrequiresareboot.
•Enableordisablefastuserswitching,whensupportedbyyoursystem.
•(Optionalfeature)Enableordisableautomaticlogonforauserauthenticatedbypower-onbootsecurity.
•SetNovelllogonsettings.ThefollowingsettingsareavailablewhenloggingontoaNovellnetwork:
–ActivatedFingerprintSoftwareautomaticallyprovidesknowncredentials.IftheNovelllogonfails,the
NovellClientlogonscreenisdisplayedalongwithaprompttoenterthecorrectdata.
–FingerprintSoftwaredisplaystheNovellClientlogonscreenandaprompttoenterthelogondata.
–DisabledFingerprintSoftwaredoesnotattemptaNovelllogon.
Authenticating
TopassNovelltoFingerprintSoftware,dothefollowing:
1.InstallFingerprintSoftware.
2.InstalltheNovellNetwareClient.
3.Whenprompted,clickY estologontotheNovellNetwareClient.
4.Restartthecomputer.
5.Whenprompted,clickY estologontoFingerprintSoftware.
6.StarttheNovellNetwareClient.
7.Authenticatetotheserver.
8.LogontotheWindowsoperatingsystem.
9.Restartthecomputer.
Note:Y ourauthenticationIDandpasswordfortheWindowsoperatingsystemandNovellNetware
Clientmustbeidentical.
Congurablesettings
SomefeaturesofThinkVantageFingerprintSoftwarecanbeconguredthroughthefollowingregistry
settings.
•Prebootorpower-onsoftwareinterface:Themechanismforenablingngerprintprebootorpower-on
supportandstoringngerprintsonthecompanionchipisnotnormallydisplayedinthengerprint
softwareunlessthereareBIOSorharddrivepasswordssetonthesystem.Inordertooverridethis
behaviorandforcetheseoptionstobeshownwithouttheexistenceofBIOSorharddrivepasswords,
addoneofthefollowing,thatapplytoyourcomputermachinetype,totheregistry:
[HKEY_LOCAL_MACHINE\SOFTWARE\ProtectorSuiteQL\1.0]
REG_DWORD"BiosFeatures"=2
or,
[HKEY_LOCAL_MACHINE\SOFTWARE\ProtectorSuiteQL\1.0]
REG_DWORD"BiosFeatures"=4
24FingerprintSoftwareDeploymentGuide
Page 33

ThissettingisusefulwhenSafeGuardEasyisinstalledonasystemwithoutBIOSpasswordsandis
utilizingngerprintauthenticationtodecrypttheharddrive.
•Sounds:FingerprintSoftwarecanbeconguredtoplayasoundcontainedinaWAVleundervarious
circumstanceduringthengerprintauthenticationprocess.Theregistrysettingsforthesesoundsare
asfollows:
HKEY_LOCAL_MACHINE\SOFTWARE\ProtectorSuiteQL\1.0\settings]
'Success'
REG_SZ"sndSuccess"=[pathtosoundle]
Theledesignatedwillplaywheneverasuccessfulswipeisregistered.
'Failure'
REG_SZ"sndFailure"=[pathtosoundle]
Theledesignatedwillplaywheneveranunsuccessfulswipeisattempted.
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ngerprint
'Scan'
REG_SZ"sndScan"=[pathtosoundle]
TheledesignatedwillplaywheneverthengerprintvericationdialogisdisplayedforClientSecurity
Solution-relatedoperations.Ifthevalueisnotpresentorisemptythennosoundisplayed.
'Quality'
REG_SZ"sndQuality"=[pathtosoundle]
Theledesignatedwillplaywheneveranunreadableswipehasoccurred.Ifthevalueisnotpresent
orisemptythennosoundisplayed.
•Passwordvalidationduringsystemunlock:Bydefault,thengerprintsoftwarevalidatesstored
passwordduringsystemunlock.Thevalidationrequirescontactingthedomaincontrollerandmight
causedelay.T oavoidthedelay,disablethepasswordvalidationduringsystemunlockandbyediting
theregistryasfollows:
[HKEY_LOCAL_MACHINE\SOFTWARE\ProtectorSuiteQL\1.0\settings]
REG_DWORD"DoNotT estUnlock"=1
Thengerprintsoftwarewillcontinuetovalidatethepasswordatsystemlogon.
Note:Whentheaboveregistrykeyissetto1,ifthedomainadministratorchangestheuser'swhenthe
user'ssystemislocked,thengerprintsoftwarewillhavetheoldpasswordstoreduntiltheuserlogs
offandlogsonagain.
•Unlockingthecomputerwithngerprint:Bydefault,ThinkVantageFingerprintSoftwareiscongured
toauthenticatetheWindowslogonaccount,andtounlockthecomputer.T odisableitsfeatureof
authenticatingtheWindowslogonaccount,edittheregistryasfollows:
[HKEY_LOCAL_MACHINE\SOFTWARE\ProtectorSuiteQL\1.0\settings\Provider]
[HKEY_LOCAL_MACHINE\SOFTWARE\ProtectorSuiteQL\1.0\settings\Provider\ProviderFilters]
"{18CBEEAA-6708-41A1-9379-D08915333CF2}"=dword:0000000d
Chapter4.WorkingwithThinkVantageFingerprintSoftware25
Page 34

ThinkVantageFingerprintSoftwareservice
Theupeksvr.exeserviceisaddedtothesystemaftertheThinkVantagengerprintsoftwareisinstalled.It
startsrunningwhilestartup,andthenrunsallthetimetheuserisloggingon.Theupeksvr.exeserviceisthe
coreoftheThinkVantageFingerprintSoftwareandrunsalltheoperationswiththedeviceanduser'sdata.It
alsoshowsallthebiometricvericationGUIandprovidessecureaccesstotheuser'sdata.
26FingerprintSoftwareDeploymentGuide
Page 35

Chapter5.WorkingwithLenovoFingerprintSoftware
ThengerprintconsolemustberunfromtheLenovoFingerprintSoftwareinstallationfolder.Thebasic
syntaxisFPRCONSOLE[USER|SETTINGS].TheUSERorSETTINGScommandspecieswhatsetof
operationwillbeused.Thefullcommandis"fprconsoleuseraddT estUser".Whenthecommandisnot
knownornotallparametersarespecied,theshortcommandlistisshowntogetherwiththeparameters.
TheLenovoFingerprintSoftware,installationinstructions,managementconsoleandallrelated
documentationareavailableontheLenovoWebsiteat:http://www.lenovo.com/support
ActiveDirectorysupportforLenovoFingerprintSoftware
ThefollowingtableshowsthepolicysettingsfortheLenovoFingerprintSoftware.
Table14.Policysettings
SettingDescription
Enable/disablengerprintlogonSpeciestheuseofngerprintsinsteadofWindows
passwordstologintothecomputer.Ifyouenablethis
setting,therearetwomoreoptionsyoucanenableor
disable:
•DisableCTRL+AL T+DELdialogforlogoninterfaceIf
youselectthisoption,themessagedirectingtheuser
topressCTRL+AL T+DELtologinisturnedoff.(Only
availableinWindowsXP)
•Requirenon-administratoruserlogonwith
ngerprintauthenticationIfyouselectthisoption,
userswhoarenotadministratorswillonlybeableto
loginusingngerprints.
Allowusertoretrievepasswordthroughngerprint
authentication
Alwaysshowpower-onsecurityoptions
Usengerprintauthenticationinsteadofpower-onand
HDpasswords
SetnumberoffailedattemptsbeforelockoutSetsthenumberoffailedattemptstologonallowed
SetinactivetimeoutSetsthedurationofsysteminactivity(inseconds)allowed
AllowuserstoenrollngerprintsIfyouenablethissetting,thenon-administratorusersare
Ifyouenablethissetting,usersareabletoviewthe
WindowspasswordfortheiraccountintheLenovo
FingerprintSoftwareafterngerprintauthentication.
Ifyouenablethissetting,userswillbeabletoselectusing
theFingerprintReaderinsteadofpower-onandhard
diskdrivepasswordswhenthecomputeristurnedon.
IntheLenovoFingerprintSoftwareenrollmentwindow,
power-onngerprintauthenticationcanbeenabledor
disabledforeachenrollednger.
Ifyouenablethissetting,thengerprintauthentication
willbeusedinsteadofpasswordsforpower-onandthe
harddrive.
beforetheuserislockedout,andalsotheduration(in
seconds)theuserislockedout.
beforetheuserlogsoff.
abletoenrollngerprintsusingtheLenovoFingerprint
Software.
©CopyrightLenovo2010
27
Page 36

Table14.Policysettings(continued)
SettingDescription
AllowuserstodeletengerprintsIfyouenablethissetting,thenon-administratorusersare
abletodeletepreviouslyenrolledngerprintsusingthe
LenovoFingerprintSoftware.
Allowuserstoimport/exportngerprints
Show/Hideelementsinsettingtabofngerprintsoftware
Ifyouenablethissetting,thenon-administratorusersare
abletoimportandexportpreviouslyenrolledngerprints
usingtheLenovoFingerprintSoftware.
Ifyouenablethissetting,theITadministratorsareableto
controlngerprintsoftwaresettingGUI.
ConsiderationsforusingLenovoFingerprintSoftware
ThissectionprovidestheinformationaboutspecialconsiderationsforworkingwithLenovoFingerprint
Software.
DeployingtheghostimagewithLenovoFingerprintSoftware
FingerprintdataisstoredintheLenovoFingerprintSoftwarereaderthatisencryptedbyAES128.Whenyou
createaghostimagefortheWindowsoperatingsystem,theFingerprintdatastoredinthesensorwillnotbe
migratedtotheghostimage.Toavoidthisproblem,usetheexportorimportfeatureprovidedbyLenovo
FingerprintSoftware.Fordetailedinformationabouttheimplementationoftheimportandexportfeature,
referto“Managementconsoletool”onpage15
.
Erasingngerprintdata
OnceLenovoFingerprintSoftwareisinstalled,thengerprintdatawillbestoredintheLenovoFingerprint
Softwarereader.Eachtimewhenyouturnonthecomputer,thesystemwillcheckwhetherthengerprint
dataofLenovoFingerprintSoftwarematchesthedatastoredinthereader.Whenyoumigrateorrestore
theoperatingsysteminstalledwithLenovoFingerprintSoftwaretothetargetcomputer,LenovoFingerprint
Softwaremightnotworkcorrectlyduetothemismatcheddata.
Toxthisproblem,youneedtoerasethengerprintdatastoredinthesensorandre-installLenovo
FingerprintSoftware.
Toerasethengerprintdata,dothefollowing:
1.RepeatedlypressandreleaseF1duringcomputerstartuptoentertheBIOS.
2.SelectSecurity➙Fingerprint➙EraseInternalFingerprintData.
3.ClickYes,andthenthengerprintdatacouldbeerasedfromtheFingerprintreader.
LenovoFingerprintSoftwareservice
Note:TheLenovoFingerprintSoftwarerequirestheterminalserviceonthesystem.Ifyouturnoffthe
terminalservice,someunexpectedresultsmightoccurintheLenovoFingerprintSoftware.
ThefollowingservicesareaddedtothesystemaftertheLenovoFingerprintSoftwareisinstalled:
•ATService.exe(onbydefault):Y oumustturnontheA TService.exeservicetousethengerprintsystem.
Thisservicemanagesrequestsfromapplicationsusingthengerprintsensor.
•DataTransferService(onbydefault):WhenDataT ransferServiceortheATService.exeserviceis
abnormallyterminated,LenovoFingerprintSoftwarewillnotworkasexpected.
28FingerprintSoftwareDeploymentGuide
Page 37

•ADMonitor.exe(offbydefault):Y oumustturnontheADMonitor.exeservicetosupportActiveDirectory
Administration.ThisservicemonitorstheregistryforchangespropagateddownfromActiveDirectoryand
reectsthechangeslocally.
Chapter5.WorkingwithLenovoFingerprintSoftware29
Page 38

30FingerprintSoftwareDeploymentGuide
Page 39

AppendixA.ConsiderationsfortheLenovoFingerprint
Keyboard
ThengerprintdeviceusedinsomeThinkPad
intheLenovoFingerprintKeyboard.Specialconsiderationsmightberequiredifthengerprintkeyboardis
usedonsomeThinkPadnotebookmodels.
Formoreinformation,gotothengerprintsoftwaredownloadpageontheLenovoWebsiteforalistofthese
ThinkPadnotebookmodels.
OnlythemodelslistedforLenovoFingerprintSoftwarerequirespecialconsiderationwhenusedwiththe
ngerprintkeyboard.AllotherThinkPadnotebookmodels,whichuseThinkVantageFingerprintSoftware,
useangerprintdevicethatiscompatiblewiththedeviceincludedinthengerprintkeyboard,anddo
notrequireanyspecialconsideration.
®
notebookmodelsisdifferentthanthengerprintdeviceused
Congurationandsetup
LenovoFingerprintSoftware2.0orlatermustbeinstalledforusewiththengerprintdeviceusedinthe
ThinkPadnotebook.UsersmustenrollngerprintswiththeLenovoFingerprintSoftwareusingtheintegrated
ngerprintdevice.
ThinkVantageFingerprintSoftware5.8orlatermustbeinstalledforusewiththeLenovoFingerprintKeyboard.
UsersmustalsoenrollngerprintswiththeThinkVantageFingerprintSoftwareusingthengerprintkeyboard.
Note:Fingerprintsregisteredwithonedevicearenotinterchangeablewiththeotherdevice.
Pre-desktopauthentication
Eitherthebuilt-inngerprintdeviceorthengerprintkeyboardwillbeusedforpre-desktopauthentication
(replacingthesystempoweronorharddrivepasswordwithangerprint).TheBIOSwilldeterminewhich
devicetousewhenthesystemispoweredon.
Bydefault,theBIOSwillonlyacceptswipesonthengerprintkeyboard,ifitisconnected.Swipesonthe
integratedngerprintdevicewillbeignoredforpre-desktopauthenticationifangerprintkeyboardis
connected.Ifthengerprintkeyboardisnotconnected,theintegratedngerprintdevicewillbeused
forpre-desktopauthentication.
TheBIOSsettingforReaderPrioritycanbechangedtousethebuilt-inngerprintsensor.IftheReader
PrioritysettingissettoInternalonly,thentheintegratedngerprintsensorcanbeusedforpre-desktop
authentication.Swipesonthengerprintkeyboardwillbeignoredinthiscase.
Windowslogon
BoththeLenovongerprintkeyboardandthengerprintdeviceusedwiththeThinkPadnotebookcomputer
modelsprovidetheirowninterfaceforuserstologintoWindowswithanenrolledngerprint.
Important:CompatibilityproblemsintheprocessofWindowslogonmightoccurifthengerprintlogon
interfacesarenotconguredcorrectly.
WhentheThinkPadnotebookcomputermodelisequippedwithboththeLenovongerprintkeyboardand
theintegratedngerprintdevice,andinstalledwiththeClientSecuritySolutionprogram,therearetwo
approachestologintotheWindows7operatingsystemusingngerprintauthentication:
©CopyrightLenovo2010
31
Page 40

•UsingtheFingerprintSoftwarelogoninterfaceThelogoninterfacesofbothLenovoFingerprintSoftware
andThinkVantageFingerprintSoftwaremustbeenabled.Whenbothngerprintlogoninterfaces
areenabledintheWindows7operatingsystem,userscanswipetheirngeroneitherthengerprint
keyboardortheintegratedngerprintdevicetologin.
•UsingtheClientSecuritySolutionlogoninterfaceTheClientSecuritySolutionlogoninterfacecanbe
usedinsteadoftheFingerprintSoftwarelogoninterfaces.WhenusingtheClientSecuritySolutionlogon
interfacetologintotheWindowsoperatingsystemwithngerprintauthentication,theFingerprint
SoftwarelogonisdisabledfromtheSettingsoptionintherespectiveFingerprintSoftwareworkspace,
andtheClientSecuritySolutionlogoninterfaceisconguredintheManagesecuritypoliciesoption
fromtheClientSecuritySolutionAdvancedmenu.
Notes:
1.TheBIOSReaderPrioritysettingdoesnotapplyinthissituation.Eitherdevicecanbeusedfor
logonifbothdevicesareavailable.
2.OnlyClientSecuritySolution8.3orlatersupportsthisfunction.Formoreinformation,see
“AuthenticationwithClientSecuritySolution”onpage32.
AuthenticationwithClientSecuritySolution
Note:ThefollowinginformationappliesonlytoClientSecuritySolution8.3andlater.Previousversions
ofClientSecuritySolutiondonotsupporttheuseoftheintegratedngerprintdevicewiththengerprint
keyboard.
WhenperforminganactionwithClientSecuritySolutionthatrequiresngerprintauthentication,suchas
auto-llingapasswordintoaWebsitewithPasswordManager,usersmustswipeangeronthengerprint
keyboard,ifitisconnected,whenprompted.Swipesonthebuilt-inngerprintdevicewillbeignoredifthe
ngerprintkeyboardisconnected.Ifthengerprintkeyboardisnotconnected,theintegratedngerprint
sensormustbeused.
Aregistrysettingisavailabletorequireuserstousethebuilt-inngerprintsensorforauthenticatingwith
ClientSecuritySolution.Ifthisregistryentryisset,ngerprintauthenticationwithClientSecuritySolution
mustbedonewiththebuilt-insensor,andswipesfromthengerprintkeyboardwillbeignored.
Theregistryentryisasbelow:
[HKLM\Software\Lenovo\TVTCommon\ClientSecuritySolution]
REG_DWORD"PreferInternalFPSensor"=1
Thedefaultvalueoftheaboveregistryentryis0,whenngerprintauthenticationwithClientSecuritySolution
mustbedonewiththengerprintkeyboard,andswipesonthebuilt-inngerprintdevicewillbeignored.
ThissettingmayalsobechangedbyusingtheClientSecuritySolutionAdministrativeTemplatelewith
grouppoliciesforActiveDirectory.
Notes:
1.WhentheBIOSReaderPrioritysettingissettoInternalonly,itisrecommendedtosettheregistry
entryvalueto1.ThiswillenableauthenticationwithClientSecuritySolutiontosimulatethesetting
forBIOSpre-desktopauthentication.
2.TheBIOSsettingandthisregistrysettingareindependent.
32FingerprintSoftwareDeploymentGuide
Page 41

AppendixB.Notices
Lenovomaynotoffertheproducts,services,orfeaturesdiscussedinthisdocumentinallcountries.Consult
yourlocalLenovorepresentativeforinformationontheproductsandservicescurrentlyavailableinyour
area.AnyreferencetoaLenovoproduct,program,orserviceisnotintendedtostateorimplythatonlythat
Lenovoproduct,program,orservicemaybeused.Anyfunctionallyequivalentproduct,program,orservice
thatdoesnotinfringeanyLenovointellectualpropertyrightmaybeusedinstead.However,itistheuser's
responsibilitytoevaluateandverifytheoperationofanyotherproduct,program,orservice.
Lenovomayhavepatentsorpendingpatentapplicationscoveringsubjectmatterdescribedinthis
document.Thefurnishingofthisdocumentdoesnotgiveyouanylicensetothesepatents.Y oucansend
licenseinquiries,inwriting,to:
Lenovo(UnitedStates),Inc
Morrisville,NC27560
USA
Attention:LenovoDirectorofLicensing
LENOVOPROVIDESTHISPUBLICATION“ASIS”WITHOUTWARRANTYOFANYKIND,EITHEREXPRESS
ORIMPLIED,INCLUDING,BUTNOTLIMITEDTO,THEIMPLIEDWARRANTIESOFNON-INFRINGEMENT,
MERCHANTABILITYORFITNESSFORAPARTICULARPURPOSE.Somejurisdictionsdonotallow
disclaimerofexpressorimpliedwarrantiesincertaintransactions,therefore,thisstatementmaynotapply
toyou.
Thisinformationcouldincludetechnicalinaccuraciesortypographicalerrors.Changesareperiodically
madetotheinformationherein;thesechangeswillbeincorporatedinneweditionsofthepublication.
Lenovomaymakeimprovementsand/orchangesintheproduct(s)and/ortheprogram(s)describedinthis
publicationatanytimewithoutnotice.
Theproductsdescribedinthisdocumentarenotintendedforuseinimplantationorotherlifesupport
applicationswheremalfunctionmayresultininjuryordeathtopersons.Theinformationcontainedinthis
documentdoesnotaffectorchangeLenovoproductspecicationsorwarranties.Nothinginthisdocument
shalloperateasanexpressorimpliedlicenseorindemnityundertheintellectualpropertyrightsofLenovo
orthirdparties.Allinformationcontainedinthisdocumentwasobtainedinspecicenvironmentsandis
presentedasanillustration.Theresultobtainedinotheroperatingenvironmentsmayvary.
Lenovomayuseordistributeanyoftheinformationyousupplyinanywayitbelievesappropriatewithout
incurringanyobligationtoyou.
Anyreferencesinthispublicationtonon-LenovoWebsitesareprovidedforconvenienceonlyanddonotin
anymannerserveasanendorsementofthoseWebsites.ThematerialsatthoseWebsitesarenotpartof
thematerialsforthisLenovoproduct,anduseofthoseWebsitesisatyourownrisk
Anyperformancedatacontainedhereinwasdeterminedinacontrolledenvironment.Therefore,the
resultinotheroperatingenvironmentsmayvarysignicantly.Somemeasurementsmayhavebeenmade
ondevelopment-levelsystemsandthereisnoguaranteethatthesemeasurementswillbethesame
ongenerallyavailablesystems.Furthermore,somemeasurementsmayhavebeenestimatedthrough
extrapolation.Actualresultsmayvary.Usersofthisdocumentshouldverifytheapplicabledatafortheir
specicenvironment.
©CopyrightLenovo2010
33
Page 42

Trademarks
ThefollowingtermsaretrademarksofLenovointheUnitedStates,othercountries,orboth:
Lenovo
ThinkCentre
ThinkPad
ThinkVantage
Microsoft,Windows,andWindowsVistaarethetrademarksoftheMicrosoftgroupofcompanies.
Othercompany,product,orservicenamesmaybetrademarksorservicemarksofothers.
34FingerprintSoftwareDeploymentGuide
Page 43
Page 44