Security functions
Access rights of SmartCards
SmartCardSmartCardSmartCard
A n ew SmartCard initially only has a preset PIN and PUK. Access rights and the customised
PIN and PUK are not assigned until the S martCard is initialised. The SmartCard type
depends on the access rights assigned to the card, as described below:
• User SmartC ard: starting the system, changing the PIN
• SuperUser SmartCard: starting the system, changes in BIOS Setup, changing the PIN
• Service SmartCard: changes in BIOS-Setup, operating system boot-up not possible
• Admin SmartCard: starting the system, changes in BIO S Setup , c hanging the PIN,
uninstalling SystemLock, initialising SmartC ards, blocking SmartCards
The following table shows an overview of the rights granted with each type of
SmartCard whe n a PIN or PUK is entered:
User
SmartCard
SuperUser
SmartCard
Service
SmartCard
Admin
SmartCard
PIN PUK PIN PUK PIN PUK PIN PUK
Start-up system
xx x
Run BIOS Setup
xxx
Change own PIN
xx xxx
Unblocking own
blocked SmartCard
x* x* x*
x
Unblocking all blocked
SmartCards
x
Generating user c ards
x
Uninstall SystemLock
x
* BIOS Setup setting (Unblock own SmartCard)
Usually there is always one Admin Sma rtCard and at least one User or SuperUser
SmartCard that will allow a system to be operated.
84 Fujitsu Technology Solutions