MAG 3.6.2 - Windows 7 Strong Key Protection Software Update Author: Christoper Broccoli Exostar Security Development Description of Document This document describes a software update that has been made available in the Exostar MAG 3.6.2 release to address an issue found on Windows 7 Operating Systems during the Exostar FIS certificate creation process. Background To support end user Federated Identity Service (FIS) certificate issuance for the MAG application, Exostar makes available a software component distributed in the form of a signed Microsoft ActiveX control. This control can be downloaded to end user machines via web download or installed via a Microsoft Software Installation package (MSI) that Exostar makes available. During the certificate creation process, the Microsoft operating system creates resources called private keys. Each certificate generated for a user has an associated and unique private key. Microsoft offers users three options to protect the private key resources on the users system: 1. No protection. The private keys can be used without any notice that they are being used. 2. Medium Level protection. The user is notified each time a private key is created and/or used. 3. Strong Key Protection. The user must supply a password when a private key is created and whenever it is accessed. Software Issue on Windows 7 Platforms A software issue has been discovered in the Exostar Certificate Issuance control when used on the Microsoft Windows 7 platform that forces Strong Key protection to be used on all private keys generated and used for Exostar FIS certificates. Copyright 2010 Exostar LLC. All rights reserved Page 1 of 7
In some environments, forcing the user to provide a password every time an Exostar certificate is created or used becomes tedious and also costly to support as some end users may forget the password that they have created. The updated Exostar ActiveX Certificate Issuance software no longer forces Strong Key protection when running on the Windows 7 platform. Additional Information about the Update New users obtaining Exostar FIS certificates for the first time on a Windows 7 platform will automatically receive the updated ActiveX software via web download or by installation using the Microsoft Installer. No further steps are necessary and the remainder of this document can be skipped. Exostar MAG users who have already downloaded Exostar FIS certificates and provided passwords for the private key resources associated with those certificates will need to continue to provide passwords whenever these certificates are used. There isn t a way to remove or change the protection level once set, so the behavior of previously issued certificates will remain the same regardless of the update. Installation of the updated control (as described in the remainder of this document) is optional and as mentioned, will not affect the protection level already set on existing certificates. Exostar MAG users who are currently in the process of obtaining or renewing Exostar FIS certificates on Windows 7 platforms can avoid having to provide a password for Exostar certificates by removing their existing Exostar ActiveX Certificate Issuance control and downloading or installing the updated version before completing the Exostar certificate download process. The remainder of this document describes the process of removing the existing Exostar ActiveX control and installing the updated version either via web download or installation via the Microsoft Installer. Copyright 2010 Exostar LLC. All rights reserved Page 2 of 7
Removing the Existing Exostar ActiveX Control and Installing the Update Regardless of how the existing Exostar ActiveX control was obtained; either via web download or via installation via the Microsoft installer made avaialble by Exostar, the existing control must be removed in order to install the update. 1. On the Windows 7 machine click Start and then Control Panel as shown below. 2. Select Programs and Features as shown below: Copyright 2010 Exostar LLC. All rights reserved Page 3 of 7
3. In the window that appears, locate and select the XEnrollPlusVistaMSI published by Exostar. Click un-install to being the removal process. 4. An un-install confirmation will appear as shown below. Click the Yes button to continue. Copyright 2010 Exostar LLC. All rights reserved Page 4 of 7
5. If UAC (User Account control) is enabled a prompt will appear asking the user to allow the uninstaller to gain the permissions needed to perform the software removal. NOTE:If the logged in user does not have administrator privileges they will be prompted for, and need to provide the administrator password in order to continue. Click the Yes button to continue the removal process. 6. After the un-install has completed the control software must also be removed from a software cache maintained by Microsoft Internet Explorer. To clear the IE browser cache, launch the Microsoft Internet Explorer browser. NOTE that it is not necessary to log into the Exostar MAG application to clear the IE browser cache. 7. Select Tools from the IE browser menu and then select Internet Options from the dropdown menu as shown below. Copyright 2010 Exostar LLC. All rights reserved Page 5 of 7
8. On the general tab of the Internet Options dialog select the Delete button located in the Browsing history section (middle of page) as shown below. Copyright 2010 Exostar LLC. All rights reserved Page 6 of 7
9. Make sure that Temporary Internet files is selected (checked). Uncheck any other items that you do not want deleted. Then click the Delete button. 10. Close all browser dialogs and then close the browser. Installing the Software Update On end user systems where users are allowed to download and install ActiveX components, the users will receive the updated control when they log into the Exostar MAG application and navigate to the certificate download area. NOTE: A prompt may appear notifying the user that the updated Exostar ActiveX control will be downloaded and installed. The user should allow the control to be installed. On end user systems where users are restricted from downloading ActiveX controls, Exostar makes a Microsoft Installer package (MSI) available. This installer can be run by an administrator to install the updated Exostar control. Additional information on the installer is available separately from Exostar. Copyright 2010 Exostar LLC. All rights reserved Page 7 of 7