Managing Smart Cards with the Enterprise Security Client

Red Hat Certificate System 7.3

Managing Smart Cards with the Enterprise Security Client

Edition 7.3


Legal Notice

Copyright © 2008 Red Hat, Inc.. This material may only be distributed subject to the terms and conditions set forth in the Open Publication License, V1.0 or later with the restrictions noted below (the latest version of the OPL is presently available at http://www.opencontent.org/openpub/).

Distribution of substantively modified versions of this document is prohibited without the explicit permission of the copyright holder.

Distribution of the work or derivative of the work in any standard (paper) book form for commercial purposes is prohibited unless prior permission is obtained from the copyright holder.

Red Hat and the Red Hat "Shadow Man" logo are registered trademarks of Red Hat, Inc. in the United States and other countries.

All other trademarks referenced herein are the property of their respective owners.

The GPG fingerprint of the security@redhat.com key is:

CA 20 86 86 2B D6 9D FC 65 F6 EC C4 21 91 80 CD DB 42 A6 0E


1801 Varsity Drive
RaleighNC 27606-2072USAPhone: +1 919 754 3700
Phone: 888 733 4281
Fax: +1 919 754 3701
PO Box 13588Research Triangle ParkNC 27709USA

Updated August 5, 2008

Abstract

This guide is for regular users of Certificate System subsystems. It explains how to manage personal certificates and keys using the Enterprise Security Client, a simple interface which formats and manages smart cards.


About This Guide
1. What Is in This Guide
2. Examples and Formatting
3. Additional Reading
4. Giving Feedback
5. Revision History
1. Overview of the Enterprise Security Client
1.1. About Smart Card Management
1.2. Features
2. Installing the Enterprise Security Client
2.1. Supported Platforms for the Client
2.2. Supported Smart Cards
2.3. Installing and Uninstalling the Enterprise Security Client on Red Hat Enterprise Linux
2.3.1. Installing the Client
2.3.2. Uninstalling on Red Hat Enterprise Linux
2.4. Installing and Uninstalling on Windows
2.4.1. Installing the Client
2.4.2. Uninstalling the Client
2.5. Installing and Uninstalling the Enterprise Security Client on Mac OS X
2.5.1. Installing the Client
2.5.2. Uninstalling the Client
3. Using the Enterprise Security Client
3.1. Launching Enterprise Security Client
3.2. Phone Home
3.2.1. About Phone Home Profiles
3.2.2. Setting Global Phone Home Information
3.2.3. Adding Phone Home Information to a Token Manually
3.2.4. Configuring the TPS to Use Phone Home
3.3. Windows Cryptographic Service Provider
3.4. Smart Card Auto Enrollment
3.5. Customizing the Smart Card Enrollment User Interface
3.6. Managing Smart Cards
3.6.1. Formatting the Smart Card
3.6.2. Resetting a Smart Card Password
3.6.3. Viewing Certificates
3.6.4. Enrolling Smart Cards
3.7. Using Security Officer Mode
3.7.1. Enabling Security Officer Mode
3.7.2. Managing Security Officers
3.7.3. Managing Regular Users
3.8. Diagnosing Problems
4. Using Enterprise Security Client Keys for SSL Client Authentication and S/MIME
4.1. Using the Certificates on the Token for SSL
4.2. S/MIME Applications
A. Enterprise Security Client Configuration
A.1. Configuration
A.2. Enterprise Security Client Mac TokenD
A.3. Enterprise Security Client XUL and Javascript Functionality
A.4. Quick Javascript UI Guide
A.5. Enterprise Security Client File Locations
A.5.1. Windows
A.5.2. Red Hat Enterprise Linux
A.5.3. Mac OS X