Preparing the installation
16Administration manual 4603.7988.02 ─ 03
You can reset the smart card PIN with the PUK. Additionally, the PUK is needed to
unlock the smart card if the PIN was entered incorrectly three times.
You can enter the PUK incorrectly up to ten times before the smart card is irreversibly
locked.
To install R&S Trusted Disk on a workstation, the certificate stored on the administra-
tor's smart card is needed (see Chapter 4.3, "Installing R&S Trusted Disk",
on page 21). Installing R&S Trusted Disk with the administrator certificate ensures
that the administrator can access the encrypted workstation.
To save the administrator certificate, proceed as follows:
1. Select the tab "User Certificates".
2. Click "Export Certificate".
3. Select the administrator's smart card.
4. Click "Next".
5. Select the destination folder.
6. Click "Next" > "Execute".
The administrator certificate is saved.
7. Rename the exported certificate to SecurityAdminCertificate.crt.
3.3.4 Personalizing a smart card for the user
You need to personalize at least one smart card for a user. Users with permission to
access a workstation identify themselves with their smart card and PIN during pre-boot
authentication. You can give any amount of user smart cards permission to access a
workstation.
1. Connect a smart card.
2. If the smart card has not been personalized before, initialize the smart card.
a) Open CardOS Viewer.
b) Select your card reader from the list.
c) Click "Card" > "Initialize Card...".
d) Fill in the required information.
e) Click "OK".
3. Open R&S Trusted Identity Manager (Standalone).
4. Select the tab "Token".
5. Click "Personalize token".
6. Configure the smart card.
Configuring R&S
Trusted Identity Manager