FingerprintSoftwareDeploymentGuide
Updated:September,2010
FingerprintSoftwareDeploymentGuide
Updated:September,2010
Note:Beforeusingthisinformationandtheproductitsupports,readthegeneralinformationinAppendixB
“Notices”onpage33.
FirstEdition(September2010)
©CopyrightLenovo2010.
LENOVOproducts,data,computersoftware,andserviceshavebeendevelopedexclusivelyatprivateexpenseandare
soldtogovernmentalentitiesascommercialitemsasdenedby48C.F .R.2.101withlimitedandrestrictedrightsto
use,reproductionanddisclosure.
LIMITEDANDRESTRICTEDRIGHTSNOTICE:Ifproducts,data,computersoftware,orservicesaredeliveredpursuant
aGeneralServicesAdministration“GSA”contract,use,reproduction,ordisclosureissubjecttorestrictionssetforth
inContractNo.GS-35F-05925.
Contents
Preface.................v
Chapter1.Overview..........1
Chapter2.Installation.........3
Installationproceduresandcommand-line
parameters.................3
Usingmsiexec.exe..............4
StandardWindowsInstallerpublicproperties...7
Installationexamples.............7
InstallingThinkVantageFingerprintSoftware....8
Silentinstallation.............8
Options.................9
InstallingLenovoFingerprintSoftware.....11
Silentinstallation............11
Options................11
Chapter3.WorkingwithFingerprint
Software................15
Managementconsoletool..........15
User-speciccommands.........15
Globalsettingscommands........16
Securemodeandconvenientmode......17
Securemode-administrator.......17
Securemode-limiteduser........18
Convenientmode-administrator.....18
Convenientmode-limiteduser......19
Chapter4.Workingwith
ThinkVantageFingerprintSoftware.21
UsingtheRSASecurIDsoftwaretoken.....21
ProvisioningtheThinkVantageFingerprint
SoftwarefortheRSASecurIDsoftware
token................21
GeneratinganRSASecurIDtokencode...22
AuthenticatingtheRSASecurID-protected
applications..............22
UsingtheThinkVantageFingerprintSoftware
withRSASecurIDReadyVPNclients....22
Considerationsforusingtheexternal
ngerprintreaderwiththeRSASecurID
softwaretoken.............23
UsingThinkVantageFingerprintSoftwarewith
NovellNetwareClient............23
Authenticating.............24
Congurablesettings............24
ThinkVantageFingerprintSoftwareservice....26
Chapter5.WorkingwithLenovo
FingerprintSoftware.........27
ActiveDirectorysupportforLenovoFingerprint
Software.................27
ConsiderationsforusingLenovoFingerprint
Software.................28
DeployingtheghostimagewithLenovo
FingerprintSoftware...........28
Erasingngerprintdata.........28
LenovoFingerprintSoftwareservice......28
AppendixA.Considerationsforthe
LenovoFingerprintKeyboard.....31
Congurationandsetup...........31
Pre-desktopauthentication..........31
Windowslogon..............31
AuthenticationwithClientSecuritySolution...32
AppendixB.Notices.........33
Trademarks................34
©CopyrightLenovo2010
iii
ivFingerprintSoftwareDeploymentGuide
Preface
InformationpresentedinthisguideistosupportLenovo
®
computersinstalledwitheithertheThinkVantage
orLenovoFingerprintSoftwareprogram.
Note:Inthisdeploymentguide,FingerprintSoftwarereferstobothThinkVantageFingerprintSoftwareand
LenovoFingerprintSoftware.
ThegoalofFingerprintSoftwareistohelpcustomersaddresscorporateITregulatorycompliance,reduce
thecostsassociatedwithmanagingpasswords,andenhancecomputingsecurity.
TheFingerprintSoftwareDeploymentGuideprovidestheinformationrequiredforinstallingFingerprint
Softwareononeormorecomputers,andalsoprovidesinstructionsandscenariosontheadministrative
toolsthatcanbecustomizedtosupportITandcorporatepolicies.
ThisguideisintendedforITadministrators,orthoseresponsiblefordeployingFingerprintSoftwareto
computersthroughouttheirorganizations.Ifyouhavesuggestionsorcomments,communicatewith
yourLenovoauthorizedrepresentative.Thisguideisupdatedperiodically,andyoucancheckthelatest
publicationontheLenovoWebsiteathttp://www-307.ibm.com/pc/support/site.wss/TVAN-ADMIN.html.
ForquestionsandinformationaboutusingthevariouscomponentsinFingerprintSoftwareworkspaces,
refertotheonlinehelpsystemanduserguidesthatcomewithFingerprintSoftware.
®
©CopyrightLenovo2010
v
viFingerprintSoftwareDeploymentGuide
Chapter1.Overview
TheobjectiveofbiometricngerprinttechnologiesofferedbyLenovoistohelpcustomersaddress
corporateITregulatorycompliance,reducethecostsassociatedwithmanagingpasswords,and
enhancecomputingsecurity.FingerprintSoftwareenablesngerprintauthenticationonindividual
computersandnetworksbyworkingwiththeLenovongerprintreaders.Itcanbeintegratedwith
ClientSecuritySolution8.3orPasswordManager.Formoreinformationabouttheintegrationwith
thetwoprograms,refertotheClientSecuritySolution8.3DeploymentGuide.Y oucanndoutmore
aboutLenovongerprinttechnologiesanddownloadFingerprintSoftwarefromtheLenovoWebsiteat:
http://www-307.ibm.com/pc/support/site.wss/document.do?lndocid=MIGR-73583.
FingerprintSoftwareoffersthesefunctions:
•Clientsoftwarecapabilities
–Microsoft
®
Windows
easy,fast,andsecuresystemaccess.
–BIOSpassword(alsoknownaspower-onpassword)andharddiskdrivepasswordsreplacement:
Replacepasswordswithyourngerprinttoenhancelogonsecurityandconvenience.
–Pre-bootngerprintauthenticationforSafeGuardEnterprisefull-driveencryption:Utilize
ngerprintauthenticationtodecryptyourharddiskdrivebeforestartingtheWindowsoperatingsystem.
–SingleswipetoaccesstheBIOSandtheWindowsoperatingsystem:Swipeyourngerprintat
startuptogainaccesstotheBIOSandtheWindowsoperatingsystem.
–Singleswipetoturnonthecomputer:Swipeyourngerprinttoturnonthecomputer.
®
passwordreplacement:Replaceyourpasswordwithyourngerprintfor
Note:Thisfeaturehasthedependencyonthehardware;therefore,itissupportedbycertaincomputer
models.
–FingerprintSoftwaresensorindicator:Indicatetheworkingstateofthesensor,andthesuccessin
swipingyourngerprintornot.
Note:Thisfeaturehasthedependencyonthehardware;therefore,itissupportedbycertaincomputer
models.
–IntegrationwithClientSecuritySolution:UsewiththeClientSecuritySolutionPasswordManager
andleveragetheTrustedPlatformModule.UserscanswipetheirngertoaccessWebsitesand
selectapplications.
•Administratorfeatures
–Securitymodetoggle:Allowanadministratortotogglebetweensecureandconvenientmodesto
modifyaccessrightsoflimitedusers.
•Securitycapabilities
–Softwaresecurity:Protectusertemplatesthroughstrongencryptionwhenstoredonasystemand
whentransferredfromthereadertothesoftware.
–Hardwaresecurity:Provideasecurityreaderwithaco-processorthatstoresandprotectsngerprint
templates,BIOSpasswords,andencryptionkeys.
©CopyrightLenovo2010
1
2FingerprintSoftwareDeploymentGuide
Chapter2.Installation
ThischaptercontainsinstructionsoninstallingFingerprintSoftware.
Installationproceduresandcommand-lineparameters
TheMicrosoftWindowsInstallerprovidesseveraladministrativefunctionsthroughcommand-line
parameters.TheWindowsInstallercanperformanadministrativeinstallationofanapplicationorproductto
anetworkforusebyaworkgrouporforcustomization.Command-lineoptionsthatrequireaparametermust
bespeciedwithnospacebetweentheoptionanditsparameter.Forexample:
setup.exe/s/v"/qnREBOOT="R""
isvalid,while
setup.exe/s/v"/qnREBOOT="R""
isnot.
Note:Thedefaultbehavioroftheinstallationwhenexecutedalone(runningsetup.exewithoutany
parameters)istoprompttheusertorebootattheendoftheinstallation.Arebootisrequiredfortheprogram
tofunctionproperly.Therebootcanbedelayedthroughacommandlineparameterforasilentinstallation
asdocumentedintheprecedingsectionandintheexamplesection.
FortheFingerprintSoftwareinstallationpackage,anadministrativeinstallationunpackstheinstallation
sourcelestoaspeciedlocation.
Torunanadministrativeinstallation,runthesetuppackagefromthecommandlineusingthe/aparameter:
setup.exe/a
Anadministrativeinstallationpresentsawizardthatpromptstheadministrativeusertospecifythelocations
forunpackingthesetuples.ThedefaultextractlocationisC:\.Youcanchooseanewlocationthatmay
includedrivesotherthanC:\(forexample,otherlocaldrivesormappednetworkdrives).Youcanalso
createnewdirectoriesduringthisstep.
Torunanadministrativeinstallationsilently,youcansetthepublicpropertyTARGETDIRonthecommand
linetospecifytheextractlocation:
setup.exe/s/v"/qnTARGETDIR=F:\TVTRR"
or
msiexec.exe/i"setup.msi"/qnTARGERDIR=F:\FPR
Note:IfyouarenotusingthelatestversionofWindowsInstaller,thesetup.exelewillbeconguredto
updatetheWindowsInstallerenginetothelatestversion.TheupdateoftheWindowsInstallerenginewill
promptyoutorebootthesystemeveninanadministrativeextractinstallation.T opreventarebootinthis
situation,youcanusetheREBOOTpropertyoftheWindowsInstaller.IftheWindowsInstalleristhelatest
version,thesetup.exelewillnotattempttoupdatetheWindowsInstallerengine.
©CopyrightLenovo2010
3
Onceandadministrativeinstallationhasbeencompleted,theadministrativeusercanmakecustomizations
tothesourceles,suchasaddingsettingstotheregistry.
ThefollowingparametersanddescriptionsaredocumentedintheInstallShielddeveloperhelp
documentation.ParametersthatdonotapplytoBasicMSIprojectswereremoved.
Table1.Parameters
ParameterDescription
/a:administrativeinstallationThe/aswitchcausessetup.exetoperforman
administrativeinstallation.Anadministrativeinstallation
copies(anduncompresses)yourdatalestoadirectory
speciedbytheuser,butdoesnotcreateshortcuts,
registerCOMservers,orcreateanuninstallationlog.
/x:uninstallingmodeThe/xswitchcausessetup.exetouninstallapreviously
installedproduct.
/s:silentmodeThecommandsetup.exe/ssuppressesthesetup.exe
initializationwindowforaBasicMSIinstallationprogram,
butdoesnotreadaresponsele.BasicMSIprojectsdo
notcreateorusearesponseleforsilentinstallations.
TorunaBasicMSIproductsilently,runthecommand
linesetup.exe/s/v/qn.(T ospecifythevaluesof
publicpropertiesforasilentBasicMSIinstallation,
youcanuseacommandsuchassetup.exe/s/v"/qn
INSTALLDIR=D:\Destination".)
/v:passargumentstoMsiexecThe/vargumentisusedtopasscommandlineswitches
andvaluesofpublicpropertiesthroughtoMsiexec.
/L:setuplanguageUserscanusethe/Lswitchwiththedecimallanguage
IDtospecifythelanguageusedbyamulti-language
installationprogram.Forexample,thecommandto
specifyGermanissetup.exe/L1031.
/w:waitForaBasicMSIproject,the/wargumentforcessetup.exe
towaituntiltheinstallationiscompletebeforeexiting.If
youareusingthe/woptioninabatchle,youmaywant
toprecedetheentiresetup.execommandlineargument
withstart/WAIT.Aproperlyformattedexampleofthis
usageisasfollows:
start/WAITsetup.exe/w
Usingmsiexec.exe
Toinstallfromtheunpackedsourceaftermakingcustomizations,theusercallsmsiexec.exefromthe
commandline,passingthenameoftheunpacked*.MSIle.msiexec.exeistheexecutableprogramofthe
WindowsInstallerusedtointerpretinstallationpackagesandinstallproductsontargetsystems.
msiexec/i"C:\WindowsFolder\Proles\UserName\
Personal\MySetups\projectname\productconguration\releasename\
DiskImages\Disk1\productname.msi"
Note:Entertheprecedingcommandasasinglelinewithnospacesfollowingtheslashes.
Thefollowingtabledescribestheavailablecommandlineparametersthatcanbeusedwithmsiexec.exe
andexamplesofhowtouseit.
4FingerprintSoftwareDeploymentGuide
Table2.Commandlineparameters
ParameterDescription
/Ipackageorproductcode
Usethisformattoinstalltheproduct:
Othello:msiexec/i"C:\WindowsFolder\Proles\
UserName\Personal\MySetups
\Othello\TrialVersion\
Release\DiskImages\Disk1\
OthelloBeta.msi"
ProductcodereferstotheGloballyUniqueIdentier(GUID)thatis
automaticallygeneratedintheproductcodepropertyofyourproduct's
projectview.
/apackageThe/aoptionallowsuserswithadministratorprivilegestoinstallaproduct
ontothenetwork.
/xpackageorproductcodeThe/xoptionuninstallsaproduct.
/L[i|w|e|a|r|u|c|m|p|v|+]logle
Buildingwiththe/Loptionspeciesthepathtothelogle;theseagsindicate
whichinformationtorecordinthelogle:
•ilogsstatusmessages
•wlogsnon-fatalwarningmessages
•elogsanyerrormessages
•alogsthecommencementofactionsequences
•rlogsaction-specicrecords
•ulogsuserrequests
•clogsinitialuserinterfaceparameters
•mlogsout-of-memorymessages
•plogsterminalsettings
•vlogstheverboseoutputsetting
•+appendstoanexistingle
•*isawildcardcharacterthatallowsyoutologallinformation(excluding
theverboseoutputsetting)
/q[n|b|r|f]
The/qoptionisusedtosettheuserinterfacelevelinconjunctionwiththe
followingags:
•qorqncreatesnouserinterface
•qbcreatesabasicuserinterface
/?or/h
Theuserinterfacesettingsbelowdisplayamodaldialogboxattheendof
installation:
•qrdisplaysareduceduserinterface
•qfdisplaysafulluserinterface
•qn+displaysnouserinterface
•qb+displaysabasicuserinterface
EithercommanddisplaysWindowsInstallercopyrightinformation
Chapter2.Installation5
Table2.Commandlineparameters(continued)
ParameterDescription
TRANSFORMSTheTRANSFORMScommandlineparameterspeciesanytransformsthat
youwouldlikeappliedtoyourbasepackage.
msiexec/i"C:\WindowsFolder\
Proles\UserName\Personal
\MySetups\
YourProjectName\TrialVersion\
MyRelease-1
\DiskImages\Disk1\
ProductName.msi"TRANSFORMS="NewTransf orm1.mst"
Youcanseparatemultipletransformswithasemicolon.Donotusesemicolons
inthenameofyourtransform,astheWindowsInstallerservicewillinterpret
thoseincorrectly.
Properties
Allpublicpropertiescanbesetormodiedfromthecommandline.Public
propertiesaredistinguishedfromprivatepropertiesandareallcapitalletters.
Forexample,COMPANYNAMEisapublicproperty.
Tosetapropertyfromthecommandline,usethefollowingsyntax:
PROPERTY=VALUE
IfyouwantedtochangethevalueofCOMPANYNAME,youwouldenterthe
following:
msiexec/i"C:\WindowsFolder\
Proles\UserName\Personal\
MySetups\YourProjectName\
TrialVersion\MyRelease-1\
DiskImages\Disk1\ProductName.msi"
COMPANYNAME="InstallShield"
6FingerprintSoftwareDeploymentGuide