Yale Software Library http://www.yale.edu/its/software/ For assistance contact the ITS Help Desk 203-432-9000, helpdesk@yale.edu Two-factor authentication: Installation and configuration instructions for on-campus machines - Windows This process consists of the following steps I. Installation of the Aladdin etoken software and drivers. II. Initialization of the etoken. III. Creating your Active Directory Certificate. IV. Copy your PGP Keys to the etoken device (FOR PGP USERS ONLY). V. Installation of Registry Keys. I. Installation instructions 1. Download the Aladdin Two-Factor Authentication software from the ITS Software Library: a. http://www.yale.edu/its/software b. Login via CAS using your Yale NetID and password c. Click the Windows operating system button d. Locate Aladdin Two-Factor Authentication software in the available software list and click on it. e. Click the Download Now button. f. You will be prompted to download the etoken software. Click the appropriate version button based on the operating system you are using. (Note: If you re not sure whether a computer is running a 32 or 64 bit version of the Windows operating system, visit the Microsoft support website: http://support.microsoft.com/kb/827218 for instructions on how to determine this.) Last modified 25-Mar-10 (jj) Page 1 of 1
2. Depending on your Windows Firewall is configured; you may see one or both of the following warning screens: In either case: Click Run. 3. Click Yes when prompted to install Aladdin Etoken now? 4. The installation will begin. You will see numerous installation status windows during this process. When the installation is complete you will be notified. Click OK. 5. A new icon will appear in the system tray. Last modified 25-Mar-10 (jj) Page 2 of 14
II. Initializing the etoken 1. Insert the USB etoken into one of the USB ports on your machine. Create a new password for this token: a. In the Current etoken Password field enter: 1234567890 b. New etoken Password: Enter a new password (must be alphanumeric with upper and lower case and a special character.) c. Confirm New etoken Password: re-enter the new password. d. Click OK button when complete. The following dialog box will appear, click OK. 2. Click the Start menu > All Programs > etoken PKI Client > etoken Properties: Last modified 25-Mar-10 (jj) Page 3 of 14
3. Click on the Advanced View icon in the menu bar: The following detailed window will appear: Last modified 25-Mar-10 (jj) Page 4 of 14
Select the etoken > right click on the token and choose Initialize from the menu. Change the following fields: etoken Name: enter your Yale NetID Password: Needs to be different from your NetID password. (Must be alphanumeric with upper and lower case and a special character). Uncheck the box Password must be changed on first logon. Click the Start button. Last modified 25-Mar-10 (jj) Page 5 of 14
The initialization process will start. Click OK. When the process is complete, click the OK button: III. Creating your Active Directory Certificate 1. Open Internet Explorer and go to Yale Certificate Authority (CA) web page (https://certreq.yale.edu/certsrv/) 2. Authenticate with your Yale NetID and Yale NetID password (Yale\NetID). 3. You will be directed to the Microsoft Active Directory Certificate Services page. Select Request a certificate. Last modified 25-Mar-10 (jj) Page 6 of 1
4. Click the Create and Submit a request to this CA link: 5. You will need to change two options on the Advanced Certificate Request page: From the drop down menu items select the following: Certificate Template: YALE ITS Smartcard Logon Under Key Options > CSP: etoken Base Cryptographic Provider Click the Submit> button Last modified 25-Mar-10 (jj) Page 7 of 14
The following box will appear: Select Yes. 6. You will now be prompted for the password you set on the etoken: Click the OK button. 7. You will be prompted to install the certificate. Click Install this certificate Last modified 25-Mar-10 (jj) Page 8 of 14
8. Click the Yes button when asked if you want the program to add the certificate now? 9. Close the browser window after your new certificate has installed. Last modified 25-Mar-10 (jj) Page 9 of 14
IV. Import your PGP Keys to the etoken (for PGP USERS ONLY) - If you do not have PGP skip to step V 1. Open PGP Desktop. 2. Right Click on the PGP Desktop icon located in your taskbar. 4. Choose Open PGP Desktop. You will be prompted to enter the password of the etoken. Enter the password of the etoken and click Next> 5. The Key Generation Progress bar will appear and then you will receive a message indicating it was successful. Click Finish. Last modified 25-Mar-10 (jj) Page 10 of 14
6. The PGP Desktop application window will now be present. Verify that the Smartcard Keys entry is located in the PGP Keys window. If it is not, remove the etoken from the USB port and plug it back in. 7. You will now need to copy your PGP Key to the etoken device. From the PGP Desktop, Select My Private Keys: 8. Locate your PGP Key (which will be your NetID) and right click on it. Last modified 25-Mar-10 (jj) Page 11 of 14
9. Select Add To, then select Smartcard Keys: 10. Click OK 11. Enter your PGP Passphrase and click OK 12. Enter the etoken PIN, click OK Last modified 25-Mar-10 (jj) Page 12 of 14
13. Select Yes 14. Click OK V. Installation of Registry Keys 1. Locate and double-click the Aladdin Yale Settings Registry File folder icon located on your desktop (created during the installation). 2. Double-click the registry key named Aladdin YALE ONLY Workstation Registry settings.reg Last modified 25-Mar-10 (jj) Page 13 of 14
3. Click the Yes button when prompted with: 4. Click the OK button when prompted with: 5. You will now need to reboot your machine. During the reboot process remove the etoken from the USB port of your machine. 6. Upon reboot you will be prompted with the standard windows login screen. Place the etoken in the USB port and you will be prompted to type the pin (password) that you set during the initialization of the etoken. Note: If you are using PGP Whole Disk Encryption (WDE) the bootguard password will be changed to be the pin of your etoken after the 2 nd reboot of your device. Last modified 25-Mar-10 (jj) Page 14 of 14