EMBASSY Remote Administration Server (ERAS) Helpdesk Guide ERAS Version 2.8 Document Version 0.0.0.2 http://www.wave.com ERAS v 2.8. Wave Systems Corp. 2010
Contents Contents... 2 1. Introduction... 3 Additional Documentation... 3 Technical Support... 3 2. ERAS Helpdesk Operations... 4 Contents User List Display... 6 Reset Password... 7 Passwords... 8 View Recovery Password... 10 Errors and Exceptions... 14 Password Reset Error... 14 Password Filter Message... 15 SafeNet ProtectDrive Password Recovery Screen... 15 BitLocker Password Recovery Screen... 16 2 Contents Wave Systems Corp. 2011
1. Introduction This document is provided as a guide for the ERAS Helpdesk provided specifically for use by HP/GM personnel outside of the scope of the ERAS Admin Manual for Wave s EMBASSY Remote Administration Server (ERAS) software to provide instructions and further details for the Helpdesk component. Intended Audience This document is intended for information technology and administrative personnel responsible for administering and support the EMBASSY Remote Administration Server (ERAS) software and Helpdesk. Additional Documentation Please read over the ERAS Installation Guide, the ERAS Admin Manual and the readme.txt file included with the software. This will provide the information you will need to configure and use ERAS. Technical Support Additional information, technical support and contact information for the ERAS can be found online: Refer to the Wave Systems website http://support.wavesys.com or E-mail your questions or issues to: support@wavesys.com Toll free: (800) WAVE-NET Tel: (413) 243-1600 Fax: (413) 243-0045 3 Introduction Wave Systems Corp. 2011
2. ERAS Helpdesk Operations A very useful feature that is included with ERAS is the helpdesk feature. It provides the ability for those designated access to use a browser to retrieve\regenerate Trusted Drive recovery password and reset Trusted Drive user password. The help desk is accessible from any platform connected to the network in a single or multi-domain environment. This also allows staff to be assigned this task without providing them direct physical access to the server. Help Desk can be opened in a Web page: the URL is http://<eras_server_name>/erashelpdesk/introduction.aspx A prompt for authorization will appear for login. On the web page, search for the platform using Computer Name, TD Serial number, User Login or Recovery Serial Number. Wild card searches are supported (using *): In order to add the following features to the HelpDesk: Refresh Platform Regenerate TD Recovery Password Reset TDM User Password Follow the instructions below from the ERAS console to make changes To change CompanyName logo goes to the installation path C:\Program Files\Wave Systems\EMBASSY Remote Administration Server\ErasHelpdesk\Images And replace companyname.gif 4 ERAS Helpdesk Operations Wave Systems Corp. 2011
Select Computer Name and in this case a search was performed using a wildcard *, one could also seach on computers that started with the word wave by typing wave*. See illustration of the search results below: 5 ERAS Helpdesk Operations Wave Systems Corp. 2011
User List Display This view is generated by clicking on the Trusted Drive listed in the Host Description above. All users of the selected computer (host) are listed, providing the Helpdesk Administrator the ability to view recovery passwords, regenerate password and reset passwords for individual users. Users can be selected from a dropdown list. 6 ERAS Helpdesk Operations Wave Systems Corp. 2011
Reset Password Reset Password was clicked on the previous screen next to EM-ERAS0\WaveUser112. In the display below user EM-ERAS0\WaveUser112 can now have their password reset once prompted. 7 ERAS Helpdesk Operations Wave Systems Corp. 2011
Passwords Error checking for typed passwords as indicated below when passwords do not match when Reset Password is clicked. Operation successful when two matching passwords are typed. 8 ERAS Helpdesk Operations Wave Systems Corp. 2011
Click on Back To User List to return user list display. 9 ERAS Helpdesk Operations Wave Systems Corp. 2011
View Recovery Password When static recovery is set on the ERAS server, the password will display on right as shown below, after clicking on View Recovery Password. Recovery Password can be regenerated by clicking Regenerate Recovery Password 10 ERAS Helpdesk Operations Wave Systems Corp. 2011
Challenge Response Recovery Password: The Challenge Response Recovery Password (CRRP-II) is a onetime recovery password using either a 128-bit or 256-bit key. The size of the key depicts the number of characters the user would have to type in order to unlock the drive, 31 and 61 characters respectively. If the User Recovery Type is set to CRRP II on the ERAS server, users will need to supply a challenge string to the Helpdesk Administrator when they in order to get a recovery password. More detail can be found in the ERAS Administration Manual for ERAS version 2.8.x 11 ERAS Helpdesk Operations Wave Systems Corp. 2011
After entering the challenge string, the Helpdesk Administrator clicks View Recovery Password. 12 ERAS Helpdesk Operations Wave Systems Corp. 2011
The password is displayed and can be read to the user. ( It is not necessary for the user to enter the dashes -.) 13 ERAS Helpdesk Operations Wave Systems Corp. 2011
Errors and Exceptions If errors or exceptions are encountered, ERAS Helpdesk will display warning and error messages which would also appear on the ERAS management console in response to failures that occur under the same conditions. This is true for operations that originate from the ERAS management console under the same conditions ERAS will log all management operations originated from Helpdesk to the ERAS database log, using the same log format that would be used if the same operations were executed from the ERAS management console. Password Reset Error When password complexity rules, server error or some other privilege is not being met by the Hard Drive Administrator, expect to see this or a similar message. or 14 ERAS Helpdesk Operations Wave Systems Corp. 2011
Password Filter Message Note: This release of Helpdesk will not enable operators to view a log of the pass fail data on operations they performed. SafeNet ProtectDrive Password Recovery Screen ProtectDrive ony support a static recovery and the user must log on to local machine rather than on the domain using Recovery_Agent as user ID 15 ERAS Helpdesk Operations Wave Systems Corp. 2011
BitLocker Password Recovery Screen This screen is only available if FIPS mode is not turned on for BitLocker. If the organization has decided to utilize FIPs enabled encryption for BitLocker please reference Part III of the Administratior Manual in section one covering BitLocker. The administrator will be required to use recovery key and deliver it out band to client machine. 16 ERAS Helpdesk Operations Wave Systems Corp. 2011