OmniPass User Guide
OmniPass User Guide
Version 3.0
Users' Guide
http://www.softexinc.com
Document #:SOF-OP30-UG-1.0
Copyright
Copyright 2003-2004 Softex Incorporated. No part of this publication may
be reproduced, transmitted, transcribed, stored in a retrieval system, or
translated into any language or computer language, in any form or by any
means, electronic, mechanical, magnetic, optical, chemical, manual, or
otherwise, without the prior written permission of Softex Incorporated.
Disclaimer of Warranty
Softex Incorporated makes no representations or warranties with respect to
the documentation herein described and especially disclaims any implied
warranties of merchantability or fitness for any particular purpose. Further,
Softex Incorporated reserves the right to revise this document and to make
changes from time to time in the content without obligation of Softex
Incorporated to notify any person of such revisions or changes.
Trademarks
Many of the designations used by manufacturers and sellers to distinguish
their products are claimed as trademarks. Where those designations appear
in this document, and Softex Incorporated were aware of a trademark claim,
the designations have been printed in initial caps or all caps. References
may be made to Softex, which is a trademark of Softex Incorporated. All
other trademarks observed.
Document Inquiries
When referring to this document, please refer to the title and publication date.
For additional information about Softex products, visit the Softex website at:
http://www.softexinc.com.
Comments are welcome and may be addressed to:
Softex, Inc.
9300 Jollyville Rd., Suite 201
Austin, TX. 78759
When you send information to Softex, you grant Softex a non-exclusive right
to use or distribute the information in any way it believes appropriate without
incurring any obligation to you.
Revision 1.0
Date: 12/15/03
ii
Document #:SOF-OP30-UG-1.0
Contents
CONTENTS ..................................................................................................................................................III
FIGURES .................................................................................................................................................... IV
INTRODUCING SOFTEX OMNIPASS ................................................................................................................ V
Features of OmniPass ........................................................................................................................... v
How This Document is Organized ........................................................................................................ vi
Conventions and Typefaces Used in this Document............................................................................ vi
PART 1. START............................................................................................................. 1
CHAPTER 1. INSTALLING OMNIPASS ............................................................................................................ 2
1.1 System Requirements..................................................................................................................... 2
1.2 Installing the OmniPass Application ............................................................................................... 2
1.3 Verifying Information about the OmniPass Application .................................................................. 3
1.4 Upgrading from a Previous Version of OmniPass .......................................................................... 4
1.5 Uninstalling the OmniPass Application ........................................................................................... 5
CHAPTER 2. USER ENROLLMENT ................................................................................................................. 6
2.1 Master Password Concept.............................................................................................................. 6
2.2 Basic Enrollment ............................................................................................................................. 6
2.3 Enrolling an Authentication Device (Optional) .............................................................................. 12
APPENDIX A: TROUBLESHOOTING......................................................................... 50
Windows 2000/Windows XP Issues .................................................................................................... 51
Dialog appears after OmniPass authentication during Windows Logon ............................................. 52
INDEX ........................................................................................................................................................ 53
Revision 1.0
Date: 12/15/03
iii
Document #:SOF-OP30-UG-1.0
Figures
Figure 1: The About Tab Window of the OmniPass Control Panel.............................................................. 4
Figure 2: OmniPass Enrollment Wizard - Welcome .................................................................................... 7
Figure 3: OmniPass Enrollment Wizard - Verify Username and Password................................................. 8
Figure 4: OmniPass Enrollment Wizard - Secure Storage Device Selection .............................................. 9
Figure 5: OmniPass Enrollment Wizard - Authentication Device Selection............................................... 10
Figure 6: OmniPass Enrollment Wizard - Audio and Taskbar Settings ..................................................... 11
Figure 7: OmniPass Enrollment Wizard - Congratulations ........................................................................ 12
Figure 8: OmniPass Enrollment Wizard - Enrolling an Authentication Device .......................................... 13
Figure 9: Enrolling an Authentication Device - Choose a Finger ............................................................... 14
Figure 10: Enrolling an Authentication Device - Capture Fingerprint ........................................................ 15
Figure 11: Enrolling an Authentication Device - Verify Fingerprint ............................................................ 16
Figure 12: Enrolling an Authentication Device - Set Authentication Rules ................................................ 17
Figure 13: Enrolling an Authentication Device - Device Enrollment Complete.......................................... 18
Figure 14: Alternate Storage Location - Select Storage Device ................................................................ 19
Figure 15: SmartCard Enrollment - Establish PIN ..................................................................................... 20
Figure 16: SmartCard Enrollment - Overwrite Confirmation ...................................................................... 21
Figure 17: The OmniPass Authentication Toolbar..................................................................................... 23
Figure 18: OmniPass Authentication Toolbar - Fully Expanded ................................................................ 24
Figure 19: Microsoft Outlook Login ............................................................................................................ 24
Figure 20: Microsoft Visual SourceSafe Login........................................................................................... 25
Figure 21: The Two Step Remember Password Procedure ...................................................................... 25
Figure 22: Remember Password Options.................................................................................................. 26
Figure 23: Authentication Prompt for Remembered Site ........................................................................... 27
Figure 24: Authentication Prompt - Multiple Authentication Methods........................................................ 28
Figure 25: Authentication Prompt for a Network Share ............................................................................. 29
Figure 26: Vault Management - Manage Passwords................................................................................. 30
Figure 27: Overwrite Credentials ............................................................................................................... 31
Figure 28: Vault Management - Manage Identities.................................................................................... 32
Figure 29: Choose Identity During Login ................................................................................................... 33
Figure 30: Switch User Identity .................................................................................................................. 33
Figure 31: Select Identity ........................................................................................................................... 34
Figure 32: Managing Passwords for Multiple Identities ............................................................................. 34
Figure 33: OmniPass Encrypt File(s) ......................................................................................................... 35
Figure 34: Encrypting a Folder Containing Multiple Files .......................................................................... 35
Figure 35: Decrypt To... ............................................................................................................................. 36
Figure 36: Select Decryption Location ....................................................................................................... 37
Figure 37: OmniPass Sharing.................................................................................................................... 37
Figure 38: OmniPass Encrypted File Sharing............................................................................................ 38
Figure 39: Locked File - Before and After .................................................................................................. 38
Figure 40: Import/Export User.................................................................................................................... 41
Figure 41: Import User Profile - Select Storage Device (Source) .............................................................. 42
Figure 42: Import User Profile - Select Storage Device (Target) ............................................................... 43
Figure 43: User Settings - Set Authentication Rules ................................................................................. 47
Figure 44: Softex Weblink .......................................................................................................................... 50
Figure 45: Sharing and security model for local accounts ......................................................................... 51
Figure 46: Limit local account use of blank passwords ... ......................................................................... 52
Figure 47: OmniPass/Windows Login Error............................................................................................... 52
Figure 48: OmniPass Reconfirm Password ............................................................................................... 53
Revision 1.0
Date: 12/15/03
iv
Document #:SOF-OP30-UG-1.0
Features of OmniPass
OmniPass augments your Windows-based system with a rich feature set,
enhancing your computing experience with the following characteristics:
Revision 1.0
Date: 12/15/03
Easy to use master password for all Windows, application, and online
passwords
Document #:SOF-OP30-UG-1.0
Part 1, Start
Part 2, Use
Part 3, Configure
Appendix A, Troubleshooting
The terms choose, select, and click are used interchangeably. They all
mean either: hovering your mouse over the selection and left-click once, or
hitting the <TAB> button until the selection is highlighted and hitting
<ENTER>.
Start
Chapter 3.2.2
WARNING
Revision 1.0
Date: 12/15/03
vi
Document #:SOF-OP30-UG-1.0
Part 1. Start
Part 1 guides you through the preparation of your Windows-based system for
the OmniPass application. You will be led through the OmniPass installation
process. You will also be led through the procedure of enrolling your first
user into OmniPass. If you have a supported hardware security device
installed, its enrollment into OmniPass will also be shown. Upon completion
of Part 1, you will be ready to start using OmniPass.
Revision 1.0
Date: 12/15/03
Document #:SOF-OP30-UG-1.0
The presence of the golden key shaped OmniPass icon in the taskbar
If one of the cases above is true for your system, then you may skip down to
Chapter 2. User Enrollment. Otherwise, please continue with this chapter
which will cover the following:
Installing of OmniPass
Uninstalling of OmniPass
Before you can install OmniPass, you must determine whether or not your
system will support it.
Document #:SOF-OP30-UG-1.0
NOTE: For installation on Windows 2000, Windows XP, or Windows 2003,
OmniPass requires that the user installing OmniPass have administrative
privileges to the system. If your current user does not have administrative
privileges, log out and then log in with an administrator user before
proceeding with OmniPass installation.
To install OmniPass on your system you must:
1. Insert the installation media for the OmniPass application into the
appropriate drive. If you are installing from CD-ROM or DVD-ROM, the
OmniPass installation program should automatically launch and
provide directions for you to follow.
NOTE: If you are not using CD or DVD media to install OmniPass or if
the OmniPass installation program does not automatically launch, then
you may have to perform a manual installation. Files may need to be
extracted before you can manually launch SETUP.EXE.
2. Follow the directions provided in the OmniPass installation program.
Specify a location to which you would like OmniPass installed.
WARNING: It is recommended that you NOT install OmniPass in the
root directory (e.g. C:\). OmniPass file encryption does not permit the
encryption of files within the OmniPass installation directory. Installing
OmniPass to root will seriously limit where files can be encrypted on
your system.
3. Once OmniPass has completed installation you will be prompted to
restart you system. Once your system has rebooted you will be able to
use OmniPass. If you choose not to restart immediately after
installation, OmniPass will not be available for use until the next reboot.
The installation program automatically places an icon (Softex OmniPass) in
the Windows Control Panel as well as a golden key shaped icon in the
taskbar. This concludes OmniPass installation. If you would like to proceed
with using OmniPass, skip to Chapter 2. User Enrollment. Otherwise
continue this chapter to learn more about upgrading or uninstalling
OmniPass.
Document #:SOF-OP30-UG-1.0
Softex OmniPass in the Control Panel, and the OmniPass Control
Panel will appear. If it does not appear, then the program is not
properly installed.
Or
Click the Start button, select Programs, and from the submenu select
the Softex program group, from that submenu click OmniPass Control
Center.
2. Select the About tab at the top of the OmniPass Control Panel. If the
About tab is not visible, you will need to navigate along the tabs until
you find it. The About tab window appears with version information
about OmniPass (see Figure 1).
Document #:SOF-OP30-UG-1.0
WARNING: Before you uninstall the software, decrypt all OmniPass
encrypted files and export all OmniPass User Profiles. Failure to do so may
result in permanent loss of encrypted file data, and permanent loss of all
remembered passwords and associated information (see Chapter 5.
Exporting and Importing Users).
1. Uninstall the previous version of OmniPass. Follow the steps outlined
in Chapter 1.5 Uninstalling the OmniPass Application.
2. After the system has been rebooted, you can install the new version of
OmniPass. For directions refer to Chapter 1.2 Installing the OmniPass
Application.
3. Reboot your system. Now you can use the new version of OmniPass.
Proceed to the next chapter to start user enrollment.
Revision 1.0
Date: 12/15/03
Document #:SOF-OP30-UG-1.0
Document #:SOF-OP30-UG-1.0
The OmniPass Enrollment Wizard will guide you through the process of
enrolling an OmniPass user.
Unless you specified otherwise, after
OmniPass installation the OmniPass Enrollment Wizard will launch on
Windows login. If you do not see the OmniPass Enrollment Wizard, you can
bring it up by clicking Start on the Windows taskbar; select Programs; select
Softex; click OmniPass Enrollment Wizard (see Figure 2).
2.2.1 Enroll
Revision 1.0
Date: 12/15/03
Document #:SOF-OP30-UG-1.0
2.2.2 Verify Credentials
Enter the password you use to log in to Windows. This will become the
master password for this OmniPass user.
In most cases, the Domain: value will be your Windows computer name. In
a corporate environment, or when accessing corporate resources, the
Domain: may not be your Windows computer name.
Click Next to continue (see Figure 4).
Revision 1.0
Date: 12/15/03
Document #:SOF-OP30-UG-1.0
Revision 1.0
Date: 12/15/03
Document #:SOF-OP30-UG-1.0
Revision 1.0
Date: 12/15/03
10
Document #:SOF-OP30-UG-1.0
2.2.6 Congratulations
Revision 1.0
Date: 12/15/03
11
Document #:SOF-OP30-UG-1.0
12
Document #:SOF-OP30-UG-1.0
typing your master password each time, you could authenticate with the
security device (e.g. use your fingerprint).
You can enroll devices manually in the OmniPass Control Center. With an
OmniPass user logged in, double-click the system tray OmniPass icon.
Select the User Settings tab and click Enrollment under the User Settings
area.
Click Enroll Authentication Device and authenticate at the
OmniPass authentication prompt to start device enrollment.
13
Document #:SOF-OP30-UG-1.0
You will be prompted to select the finger you wish to enroll. Fingers that
have already been enrolled will be marked by a green check. The finger you
select to enroll at this time will be marked by a red arrow. OmniPass will
allow you re-enroll a finger. If you choose a finger that has already been
enrolled and continue enrollment, OmniPass will enroll the fingerprint,
overwriting the old fingerprint. Select a finger to enroll and click Next (see
Figure 9).
Revision 1.0
Date: 12/15/03
14
Document #:SOF-OP30-UG-1.0
Revision 1.0
Date: 12/15/03
15
Document #:SOF-OP30-UG-1.0
2.3.4 Verifying the Fingerprint
Once OmniPass has successfully acquired the fingerprint, the Verify
Fingerprint screen will automatically appear (see Figure 11).
Revision 1.0
Date: 12/15/03
16
Document #:SOF-OP30-UG-1.0
2.3.5 Setting Authentication Rules (default)
After fingerprint verification, the Set Authentication Rules screen will
automatically appear (see Figure 12). These settings allow you to restrict
access to OmniPass functions. By default, with no security devices enrolled,
all OmniPass functions require master password authentication. Once you
enroll a security device, you can set OmniPass to require authentication via
that security device to access OmniPass functions. More about these
settings and their ramifications can be found under Chapter 6.2 User
Settings. For now, keep the default selection (no boxes checked) and click
Next. This setting will allow you to access OmniPass functions with your
enrolled finger, but fingerprint authentication will not be required.
Revision 1.0
Date: 12/15/03
17
Document #:SOF-OP30-UG-1.0
2.3.6 Completing Device Enrollment
After you set the authentication rules for the enrolled device, the Device
Enrollment Complete screen will automatically appear (see Figure 13).
Revision 1.0
Date: 12/15/03
18
Document #:SOF-OP30-UG-1.0
19
Document #:SOF-OP30-UG-1.0
2.4.2 SmartCard Enrollment - Set PIN
This example assumes you are using a fresh, blank SmartCard. If you are
using a SmartCard that has already been used with OmniPass or another
application, you will be prompted to enter your PIN.
WARNING: Depending upon how the SmartCard was initially configured, a
limited number of failed PIN attempts may be enforced. If this is the case,
and you exceed the maximum failed PIN attempts, the card may become
locked and permanently unusable. To find out more, contact whoever
configured your SmartCard for you, or the SmartCard manufacturer.
If you are using a fresh SmartCard you will be greeted with a screen
prompting you to establish your PIN (see Figure 15). Please take note of this
PIN, if you forget it you risk being locked out of your SmartCard. Enter your
PIN in both fields and click Next.
Revision 1.0
Date: 12/15/03
20
Document #:SOF-OP30-UG-1.0
2.4.3 SmartCard Enrollment - Overwrite Confirmation
If your SmartCard already contains data when you select it as a storage
device (from 2.4.1 of SmartCard Enrollment), you will be warned that the
current data on the SmartCard will be overwritten. This may also happen if
you try to use a SmartCard as a storage device that is already being used as
such by another OmniPass user. There is a limitation of one OmniPass user
per SmartCard. To proceed, check the box next to I want to overwrite the
SmartCard and click Next (see Figure 16).
Revision 1.0
Date: 12/15/03
21
Document #:SOF-OP30-UG-1.0
Part 2. Use
You are now ready to begin using OmniPass. Used regularly, OmniPass will
streamline your authentication procedures. For the credentials registered
with it, OmniPass is a secure repository. In the event you forget any of those
passwords, you can find them in OmniPass.
Part 2. Use covers basic OmniPass functionality. Review this section to
quickly get familiar with the OmniPass functions you will most use. If your
system is shared among several users (often the case in a home PC or
SOHO environment) then you may find some additional useful features in
Part 3. Configure.
Revision 1.0
Date: 12/15/03
22
Document #:SOF-OP30-UG-1.0
23
Document #:SOF-OP30-UG-1.0
methods are not. When you click the icon for an unselected authentication
method, the authentication prompt associated with that method is displayed
(see Figure 18).
Revision 1.0
Date: 12/15/03
24
Document #:SOF-OP30-UG-1.0
Revision 1.0
Date: 12/15/03
25
Document #:SOF-OP30-UG-1.0
3.2.1 Associating a Friendly Name
After clicking the OmniPass key cursor near the login prompt OmniPass will
prompt you to enter a friendly name for this remembered site (see Figure
22). You should enter something that reminds you of the website, the
company, or the service you are logging into. In its secure database,
OmniPass associates this friendly name with this website.
Revision 1.0
Date: 12/15/03
26
Document #:SOF-OP30-UG-1.0
If you uncheck both boxes in Settings for this Password Site, OmniPass
will prompt you for your master password (or authentication device). Once
you have authenticated with OmniPass your credentials will be filled in the
site login prompt, but you will have to click the website OK, Submit, or Login
button to gain access to the site.
Click Finish to complete the remember password procedure. The site
location, the credentials to access the site, and the OmniPass authentication
settings for the site are now stored in OmniPass secure database. The
OmniPass authentication settings (Settings for this Password Site) can
always be changed in Vault Management (see Chapter 3.5 Password
Management).
Revision 1.0
Date: 12/15/03
Document #:SOF-OP30-UG-1.0
Revision 1.0
Date: 12/15/03
28
Document #:SOF-OP30-UG-1.0
29
Document #:SOF-OP30-UG-1.0
The exception to the above rule is the resetting of your Windows password.
If your password is reset in Windows, then the next time you login to
Windows, OmniPass will detect the password change and prompt you to
Update or Reconfirm your password with OmniPass. Enter your new
Windows password in the prompt(s) and click OK and your OmniPass
master password will still be your Windows password.
30
Document #:SOF-OP30-UG-1.0
go to www.hobbitmail.com OmniPass prompts you to authenticate, and then
you are granted access to your [email protected] Inbox. Now let us say
you registered for another email account at www.hobbitmail.com with the
username smeagle and password gollum.
You then go to
www.hobbitmail.com and you hit Cancel on the OmniPass authentication
prompt instead of authenticating. You fill in the webmail login prompt with
your other credentials (smeagle and gollum) and you use Remember
Password to register the credentials with OmniPass. OmniPass will notify
you that you have already remembered a set of credentials for this site, and
will ask you if you wish to proceed (See Figure 27).
Revision 1.0
Date: 12/15/03
31
Document #:SOF-OP30-UG-1.0
Revision 1.0
Date: 12/15/03
32
Document #:SOF-OP30-UG-1.0
3.6.1 Choosing User Identity during Login
To choose your identity during login, type your username in the User Name:
field. Press <TAB> and see that the Domain: field self-populates. Click the
Password: field to bring the cursor to it, and you will see the pull-down menu
in the Identity: field become available. Select the identity you wish to login
as and then click OK to login (see Figure 29).
Revision 1.0
Date: 12/15/03
33
Document #:SOF-OP30-UG-1.0
34
Document #:SOF-OP30-UG-1.0
35
Document #:SOF-OP30-UG-1.0
Revision 1.0
Date: 12/15/03
36
Document #:SOF-OP30-UG-1.0
Revision 1.0
Date: 12/15/03
37
Document #:SOF-OP30-UG-1.0
38
Document #:SOF-OP30-UG-1.0
Revision 1.0
Date: 12/15/03
39
Document #:SOF-OP30-UG-1.0
Part 3. Configure
If Part 2 could be viewed as a Getting Started Guide then this part can be
viewed as an Administrators Guide. This part will give an overview of both
the Export/Import function and the OmniPass Control Center. Much of what
is discussed in this part could be considered customization of OmniPass.
Customizations can be made on a per-user basis, or globally. Authentication
rules will be discussed; in OmniPass, authentication rules can be configured
so as to require very stringent levels of authentication (Multi-Factor
Authentication).
Revision 1.0
Date: 12/15/03
40
Document #:SOF-OP30-UG-1.0
41
Document #:SOF-OP30-UG-1.0
Click Exports an OmniPass user profile. OmniPass will prompt you to
authenticate.
Upon successfully authentication, you must name the
OmniPass user profile and decide where to save it. An .opi file is generated,
and you should store a copy of it in a safe place.
This .opi file contains all your user specific OmniPass data, and it is both
encrypted and password protected. This user profile does NOT contain any
of your encrypted data files.
Revision 1.0
Date: 12/15/03
42
Document #:SOF-OP30-UG-1.0
If you did not enroll any alternate secure storage devices, then select
OmniPass Import/Export File (*.opi) and click Next. OmniPass will then
prompt you to browse for the file you had previously exported (.opi file).
When you select the .opi file for importation, OmniPass will prompt you for
authentication. The credentials that will allow a user profile to be imported
are the Windows login credentials of the exported user. They are the
credentials that had to be submitted when the user profile was exported.
You will need User Name, Password, and Domain. If you dont remember
the value for Domain, in a corporate environment your network administrator
should know, and in a PC or SOHO environment Domain should be your
computername.
Once authentication is successful, OmniPass will prompt you to select a
storage device for this users OmniPass data (see Figure 42).
Revision 1.0
Date: 12/15/03
43
Document #:SOF-OP30-UG-1.0
Assume you export a local Windows User profile from OmniPass, and
you want to import that profile to another machine that has OmniPass.
Before you can import the profile, a Windows user with the same login
credentials must be created on the machine importing the profile.
Example I have a Windows user with the username Kasahara and
the password Motorcycle on my system. I have enrolled Kasahara into
OmniPass and remembered passwords. I want to take all my passwords
to new system. I export Kasaharas OmniPass user profile. I go to my
new system and using the Control Panel I create a user with the
username Kasahara and the password Motorcycle. I can now
successfully import the OmniPass user data to the new system.
When you export from OmniPass a Windows domain user, you can
import that OmniPass user profile on any domain computer running
OmniPass.
Example Balthasar and Melchior are computers on the NERV
domain. I work on Balthasar with the username Ikari and the password
PenPen on the NERV domain. I have enrolled this user, Ikari, in
OmniPass and remembered passwords. I want to take all my passwords
to Melchior. I export Ikaris user profile from OmniPass on Balthasar. I
go to OmniPass on Melchior and import Ikaris OmniPass data. Since
Balthasar and Melchior are on the same domain, the import is
successful. If you do not know the domain you are using, you should
contact your network administrator for assistance.
Revision 1.0
Date: 12/15/03
If you export an OmniPass-only user, you can import that user to any
computer running OmniPass, provided that a user with that name is not
already enrolled in OmniPass.
If you attempt to import a user profile who has the same name as a user
already enrolled in OmniPass, the OmniPass import function will fail.
44
Document #:SOF-OP30-UG-1.0
Click the Start button; select the Programs group; select the Softex
program group; and click the OmniPass Control Center selection.
Open the Windows Control Panel (accessible via Start button -->
Settings --> Control Panel) and double-click the Softex OmniPass
icon.
45
Document #:SOF-OP30-UG-1.0
access denied, etc.). The details of each setting under the Audio Settings
and Taskbar Tips interfaces are self-explanatory.
The Encrypt/Decrypt interface under User Settings allows you to choose
either the Softex Roaming Profile or a Digital Certificate that is already
installed on your system. If you choose Softex Roaming Profile then the keys
used for encryption are part of your OmniPass User Profile. Portability of
OmniPass encryption functions to other computers require only your
OmniPass User Profile. If you choose Digital Certificate then the keys used
for encryption are separate from your OmniPass User Profile. Portability of
OmniPass encryption functions will require migration of both your OmniPass
User Profile and the installed Digital Certificate. NOTE: Do not remove this
Digital Certifcate. If it is removed from the system, you will not be able to
recover any of the encrypted files!
The Enrollment interface allows you to enroll authentication devices, enroll
fingerprints, and set authentication rules for enrolled devices. For the
procedure to enroll and authentication device refer to Chapter 2.3. To enroll
additional fingerprints, click Enroll Authentication Device, and authenticate
with OmniPass. Select the fingerprint recognition device in the Select
Authentication Device screen (it should already be marked by a green
check if you have a finger enrolled) and click Next. The rest of the procedure
to enroll an additional finger can be found starting with Chapter 2.3.2.
If you click Set Authentication Rules in the Enrollment interface, you will be
prompted to authenticate. Upon successful authentication you will see the
Set Authentication Rules screen (see Figure 43).
Revision 1.0
Date: 12/15/03
46
Document #:SOF-OP30-UG-1.0
Revision 1.0
Date: 12/15/03
Document #:SOF-OP30-UG-1.0
b. If you attempt to encrypt or decrypt a file with OmniPass, you will
be prompted to authenticate and OmniPass will not allow you to
encrypt/decrypt until you successfully authenticate with an
enrolled SmartCard. Successful authentications with master
password or enrolled finger are not sufficient.
c.
If you log out of Windows (or OmniPass) and attempt to log back
in, you will be prompted to authenticate and OmniPass will not
allow you to log back on until you successfully authenticate with
BOTH a fingerprint reader AND a SmartCard. This dual
authentication requirement is a Multi-Factor Authentication.
Successful authentication with a master password, or with just
the fingerprint reader are not sufficient. Neither are successful
authentications with just the SmartCard. Loss or failure of either
the SmartCard or the fingerprint reader will result in an
inaccessible system.
48
Document #:SOF-OP30-UG-1.0
To get back to the XP Welcome Screen or to turn FUS back on, the user will
have to disable Strong Logon Authentication, reboot the system and then
manually enable the XP Welcome Screen and FUS from the User Accounts
in Windows Control Panel. Once this is done the fingerprint reader or other
security device can no longer be made as a "Required" device for login to
the PC.
This feature is specific to Windows XP only. For Windows 2K and 2003
Server Strong Logon Authentication is always enabled.
6.4 Encrypt/Decrypt
The Encrypt/Decrypt tab provides a windows through which you can do
encryption and decryption functions (see Chapter 4). Similar to the Windows
Explorer, the Encrypt/Decrypt window presents the directory structure of your
system. You can select files and folders and use the Encrypt and Decrypt
buttons to encrypt and decrypt files. Some files and folders used by the
Windows system or by other programs cannot be encrypted by OmniPass.
Directing OmniPass to encrypt or decrypt a file will result in OmniPass
prompting you for authentication. If you cannot authenticate successfully, the
file will not be encrypted or decrypted. You can bypass the Encrypt/Decrypt
tab by using the OmniPass encryption/decryption shell extension. In the
normal course of browsing and accessing you files, if you right-click the file
and see OmniPass Encrypt File(s) or OmniPass Decrypt Files(s), those
OmniPass functions are available to you. Encryption and decryption will
occur upon successful authentication.
6.5 About
The About tab displays version information about OmniPass. If you click
Check For Updates then the Softex Weblink application will launch.
Revision 1.0
Date: 12/15/03
49
Document #:SOF-OP30-UG-1.0
Appendix A: Troubleshooting
Most major problems can be avoided by paying special attention to the
NOTES and WARNINGS distributed throughout this document. Other
common problems are discussed in this appendix. For support not covered
in this document contact [email protected].
Revision 1.0
Date: 12/15/03
50
Document #:SOF-OP30-UG-1.0
Revision 1.0
Date: 12/15/03
51
Document #:SOF-OP30-UG-1.0
Click Start, Control Panel, Administrative Tools, and Local Security
Settings. Expand Local Policies, expand Security Options, and doubleclick Accounts: Limit account use of blank passwords to console login
only. This setting should be set to Disabled (see Figure 46).
52
Document #:SOF-OP30-UG-1.0
If you are having difficulties due to the first reason, you will need to update
OmniPass with your changed Windows account password. Click Update
Password and you will be prompted with a dialog to reconfirm your
password (see Figure 48).
Index
Revision 1.0
Date: 12/15/03
53
Document #:SOF-OP30-UG-1.0
M
A
About tab..............................................................4, 51
Add/Remove User....................................................47
Audio Settings ..........................................................48
authentication device ....... 6, 11, 13, 18, 23, 27, 28, 48
Authentication Rules .................. 17, 18, 25, 28, 48, 49
Automatically log on .................................................50
D
decrypt ................................... 5, 13, 38, 43, 47, 50, 51
default identity ..........................................................34
Digital Certificate ......................................................48
Domain...........................................................9, 34, 45
password management..............................................v
password protected............ v, 6, 27, 28, 30, 34, 35, 44
password replacement ...................... vi, 23, 24, 25, 26
Password Replacement ................................ vi, 23, 50
PIN ...............................................................20, 21, 25
F
File and Folder Locking....................................... vi, 36
file encryption .........................................................v, 3
fingerprint ... v, 6, 13, 14, 15, 16, 17, 29, 30, 47, 48, 50
friendly name............................................................27
I
Identities...........................................31, 32, 33, 35, 36
import ............................................ v, vi, 42, 43, 44, 46
Import/Export User .......................................43, 44, 47
install....................................................... vi, 2, 3, 5, 52
R
Reconfirm.....................................................31, 54, 56
Remember Password...............................6, 26, 27, 30
remembered site ....................................24, 27, 28, 30
S
secure database.................................................27, 28
security device .................. See Authentication device.
Set as Default...........................................................34
share .............................................................. v, 39, 40
SmartCard........ v, 6, 10, 19, 20, 21, 22, 25, 29, 45, 50
Switch User Identity .................................................34
T
Taskbar Tips ................................................12, 30, 48
Troubleshooting .................................................. vi, 53
Revision 1.0
Date: 12/15/03
54
Document #:SOF-OP30-UG-1.0
uninstall................................................................. vi, 5
unlock workstation....................................................49
Unmask Values ........................................................30
Update Password................................. See Reconfirm
upgrade................................................................. vi, 5
user enrollment .......................... 5, 6, 7, 11, 12, 13, 20
User Enrollment ............................................ vi, 2, 3, 6
User Management....................................................47
user profile ............... 13, 19, 40, 41, 43, 44, 45, 46, 47
Revision 1.0
Date: 12/15/03
W
WARNING.......................... 3, 5, 13, 18, 20, 27, 47, 49
Weblink ..............................................................51, 52
Windows login credentials..................................45, 50
Windows Logon.................................. v, 24, 49, 50, 55
55