Exhibit 015 - DOJ Ref Mapping PIVCard Certificates to a Privileged Account Open Version.pdf

PDF 2 MB Posted

Attached to
Cash PAK System Federal contract opportunity
Solicitation number
2031ZA23R00015
Issued by
Department of the Treasury Bureau of Engraving and Printing

About this file

This document provides guidance for mapping PIV card certificates to privileged user accounts on Microsoft Active Directory. It outlines technical requirements including supported server and workstation operating systems as well as an approved cryptographic service provider. Steps are described for privileged users to request certificate mapping via digitally signed email. The support team then exports the user's certificate, maps it to the privileged account in Active Directory, and configures required policies on the workstation. Finally, the document provides instructions for privileged users to log in to their accounts using the mapped certificate. Relevant details are included regarding auditing, security considerations, and configuring Outlook for digital signatures.

View the file

Other files for this federal contract opportunity

Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

JUNE 2011

Mapping PIVCard Certificates to a Privileged Account

MULTI-FACTOR AUTHENTICATION FOR PRIVILEGED USERS

ACCESSING PIV-ENABLED SYSTEMS

Identity Management Services

Enterprise Solutions Staff

Office of the Chief Information Officer

Information Resources Management

Justice Management Division

U.S. Department of Justice

James Burke, CISSP

Technical Lead

IDMS Program Management Office

2 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

U.S. DEPARTMENT OF JUSTICE

PREREQUISITES

Identity Management Services (IDMS) has written this document for Department of Justice enterprise information technology professionals who have responsibilities related to the implementation of PIVCard logon in accordance with Homeland Security Presidential

Directive 12 (HSPD-12).

With regard to domain expertise, Identity Management Services assumes that readers are knowledgeable about:

DOJ PIVCard

HSPD-12-compliant smart cards public key infrastructure

APPLICABILITY TO OTHER AGENCIES

IDMS has written this document for general applicability to Federal agencies. To make use of this document, other agencies must substitute their own agency-specific terms for the following DOJ-specific terms:

DOJ TERM AGENCY-SPECIFIC SUBSTITUTE TERM

Department of Justice Agency name

DOJ Agency abbreviation

DOJ PIVCard Agency-specific term for the agency’s HSPD-

12 compatible smart card or the generic term “PIV card.”

Support Agency’s central support organization

MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT 3

IDENTITY MANAGEMENT SERVICES

LEXICON

CMS card management system

The Department’s PIVCard issuer uses ActivClient as its CMS.

CSP cryptographic service provider

DAR data at rest

EKU extended key usage

GFE government-furnished equipment

HSPD-12 Homeland Security Presidential Directive 12 (2004)

IDMS DOJ Identity Management Services

MMC Microsoft Management Console

MSO Managed Services Office

With regard to HSPD-12 implementations, “MSO” typically refers to the General Services

Administration’s HSPD-12 Managed Services Office, which offers the USAccess Program.

OID object identifier

OU organization unit

PIN Personal identification number (in this document, the PIVCard PIN)

PIVAUTH PIV authentication certificate

The X.509 digital certificate on the PIVCard that contains the public key issued by the CA.

PIV-I PIV interoperable

A PIV interoperable card is one that:

is issued in accordance with the FIPS 201 process for enrollment and activation meets the FIPS 201 technical standards for interfacing with a PIV-enabled LACS or

PACS

allows Federal relying parties to trust the card across agencies

In print, the term PIV-I (“PIV eye”) is easily confused with PIV-1 (“PIV one”), the section of

FIPS-201 that describes minimum requirements for a Federal personal identification system.

SEE Symantec Endpoint Encryption™

SP 800-53 National Institute of Standards and Technology Special Publication 800-53:

Recommended Security Controls for Federal Information Systems and Organizations

UPN user principle name

4 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

CONTENTS

I. INTRODUCTION

I.A System Requirements

I.A.1 SERVER

I.A.2 WORKSTATION OPERATING SYSTEM

I.A.3 CRYPTOGRAPHIC SERVICE PROVIDER

II. MIDDLEWARE

II.A Windows Vista II.B Windows 7

III. SECURITY CONSIDERATIONS

III.A Domain Controller Auditing

III.A.1 PRE-AUTHENTICATION TYPE 15

III.A.2 PRE-AUTHENTICATION TYPE 16

IV. MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS

IV.A Privileged User: E-mail Support to request mapping IV.B Standard Configuration/ActivClient IV.C Support: Export the Privileged User’s Digital Certificate IV.D Support: Map the PIVCard Digital Certificate to the Privileged Account

V. CONFIGURING THE WORKSTATION

V.A Required Policies

V.A.1 ALLOW CERTIFICATES WITH NO EXTENDED KEY USAGE CERTIFICATE ATTRIBUTE

V.A.2 ALLOW SIGNATURE KEYS VALID FOR LOGON

V.A.3 ALLOW USER NAME HINT

V.B Accessing Policy Settings V.C Enable Policy Settings

V.C.1 ALLOW CERTIFICATES WITH NO EXTENDED KEY USAGE CERTIFICATE ATTRIBUTE

V.C.2 ALLOW SIGNATURE KEYS VALID FOR LOGON

V.C.3 ALLOW USER NAME HINT

VI. LOGGING ON

VII. APPENDIX A: CONFIGURING OUTLOOK FOR DIGITAL SIGNATURE

VIII. AUTHOR

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 5

I. INTRODUCTION

“PIVCard logon” refers to the use of digital certificates on the PIVCard as the common means of authentication for access to departmental information systems.

The Department’s policy is to enable PIVCard logon for all information systems – current and future. However, in implementing PIVCard logon, system owners must resolve a conflict between two Federal documents:

Homeland Security Presidential Directive 12 (HSPD-12) requires that the

Department issue one PIVCard to each organizational user for authentication and authorization to access departmental facilities and information systems.

NIST Special Publication 800-53 (SP 800-53) distinguishes between organizational users and “privileged users” -- i.e., key management, network/system/database/Web administrators whom the Department has authorized to perform security-relevant functions. SP 800-53 recommends that privileged users provide additional assurances of authentication and authorization (e.g., a second PIVCard with additional digital certificates) when logging on to privileged accounts on PIV-enabled information systems.

To resolve the conflict between HSPD-12 and SP 800-53, IDMS recommends mapping the digital certificates on each privileged user’s PIVCard to that user’s privileged account(s) – and not issuing the privileged user a second PIVCard.

Mapping will meet the “one-card” requirement of HSPD-12 and the additional assurances recommendation of SP 800-53.

In addition, mapping PIVCard certificates to privileged accounts has two ancillary benefits:

Mapping facilitates privileged account logon for users who have temporary assignments at locations served by different domains

Mapping facilitates the use of other trusted credentials, e.g. PIV interoperable

(PIV-I)

This document details the process for mapping PIVCard digital certificates to privileged accounts on Microsoft Active Directory™.

http://www.dhs.gov/xabout/laws/gc_1217616624097.shtm http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf

6 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

I.A System Requirements

In complying with HSPD-12, the Department may use only those products that the General Services Administration (GSA) includes on its Approved Products

List (APL). The solution described in this document applies only to systems using the following GSA-approved products:

I.A.1 SERVER

Windows Server 2008

I.A.2 WORKSTATION OPERATING SYSTEM

Windows Vista

Windows 7 subsequent releases of Windows operating systems

I.A.3 CRYPTOGRAPHIC SERVICE PROVIDER

Windows Vista does not include a cryptographic service provider (CSP) and this solution requires a more robust CSP than Microsoft has provided with the Windows 7 mini-driver.

GSA has approved several middleware applications, however the

Department’s PIVCard issuer uses the ActivIdentity™ card management system, ActivClient™ 6.2. Therefore, IDMS used

ActivClient 6.2 in designing and testing this solution.

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 7

II. MIDDLEWARE

II.A Windows Vista

To enable PIVCard logon for workstations running Windows Vista, the

Department must integrate middleware.

II.B Windows 7

Windows 7 includes a mini-driver for basic PIVCard functions. However, the mini-driver does not the support the cryptographic service provisions required for this solution. IDMS recommends that the Department integrate middleware into its Windows 7 solution to provide a more robust CSP and to access the additional functions that middleware provides.

Following is a table comparing the functionality of the Windows 7 mini-driver with ActivClient:

8 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

WINDOWS 7 MINI-DRIVER ACTIVCLIENT

FUNCTIONALITY NOTES

WINDOWS NETWORK LOGON

-- standard access The Department’s current agreement with the middleware vendor is per-PIVCard licensed, not per-installation licensed. For example, even if a user has a government-furnished equipment (GFE) workstation, GFE laptop, and personal PC, the Department would pay for only one license because the user has only one PIVCard, which can be used to log onto all three machines. PIVCard logon does not apply for local/non-domain logon.

WINDOWS NETWORK LOGON

-- privileged access (admin account) With Microsoft Server 2008 domain controllers on the backend and Vista/Windows 7 on the workstation, the

PIVCard digital signing certificate can be mapped to a user's privileged account. During logon, ActivClient prompts the user to choose which account to log onto (standard or privileged). However, the Windows 7 native CSP errs on privileged account access.

DAR/SEE

-- laptop startup/single sign-on ActivClient is required during the card registration process when using Symantec Endpoint Encryption (SEE).

PIN CHANGE

If a user logs on to a workstation with PIVCard+PIN, the user can change that PIN at the workstation.

PIVCARD UNLOCK AND RESET

(through USAccess) If a user locks a PIVCard (after six failed attempts at entering the correct PIN), the user must go to a USAccess

System Activation Station to unlock the PIVCard and reset the PIN. This process cannot be done at the user’s workstation.

CERTIFICATE UPDATE

(through USAccess) The GSA MSO uses ActivIdentity for its backend CMS so PIVCard digital certificate updates can be done only through

ActivClient. (Before enabling digital certificate updates via user workstations, this functionality should be tested thoroughly.) In addition, ActivClient will be updated without delay to take advantage of new features, particularly the

128k cards that the GSA MSO will roll out in late 2011 to enable key escrow.

PIN CACHING

The PIN is cached for the PIVAuth certificate as long as the PIVCard is in the card reader. For subsequent authentication requests while the PIN is cached, the user will be prompted to select the PIVAuth certificate, but will not have to re-enter the PIN.

PIVCARD DIAGNOSTICS

(e.g., view data, picture, CHUID, etc.)

ActivClient provides detailed PIVCard information that the Helpdesk can use for troubleshooting.

WEB APPLICATION AUTHENTICATION

DIGITAL SIGNING: ADOBE PDF FORMAT

DIGITAL SIGNING: MS OFFICE

CERTIFICATE FRIENDLY NAMES SET

ActivClient provides this function as part of its card registration process. Certificate usage is appended at the end of the friendly name and generally not visible in the certificate selection window. However, hovering the mouse over the certificate name triggers a popup showing the full friendly name, allowing the user to choose which certificate to use. With native Windows 7, IDMS recommends creating a Windows startup script that will set the certificate friendly name for all registered certificates in the local certificate store and prepend certificate usage to the friendly name to facilitate user selection.

LOCAL CERTIFICATE STORE CLEAN-UP

ActivClient can be configured to remove the user's certificates from the Windows local certificate store upon card removal. This minimizes storage of older certificates that have been invalidated by a certificate update. However, if clean up is enabled, IDMS recommends using ActivClient's certificate registration process and default setting of friendly names because the customized friendly names script (described above) cannot be integrated automatically into the card registration process.

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 9

III. SECURITY CONSIDERATIONS

The Department should develop security-assurance criteria for determining which personnel will be authorized to map PIVCard certificates to privileged accounts.

Typically, if an administrator attempts to gain unauthorized access to another user’s privileged account by changing the password, the user will detect and report the change immediately, triggering a domain controller audit.

However, with a user’s PIVCard certificates mapped to the privileged account, unauthorized access could be transparent to the user and so not detected until a regularly scheduled domain controller audit

III.A Domain Controller Auditing

Microsoft Active Directory™ logs different types of events. The two event types that are most important for PIVCard logon are Pre-Authentication Type

15 and Type 16.

10 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

III.A.1 PRE-AUTHENTICATION TYPE 15

Pre-authentication type 15 logs the use of a certificate with the

UserPrincipleName (UPN) for standard logon:

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 11

III.A.2 PRE-AUTHENTICATION TYPE 16

Pre-authentication type 16 logs the use of a certificate without the UPN for mapping to a privileged account:

12 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

IV. MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS

There are many ways to get the information required to map PIVCard certificates to privileged accounts. As an example, following is a process that IDMS tested and successfully implemented for one division of the Agency:

IV.A Privileged User:

E-mail Support to request mapping

Open Microsoft Outlook.

Click New to launch a new message template.

TO FIELD

Key in [Support e-mail address]

SUBJECT FIELD

Key in Map certificate to [name of your Active Directory privileged account]

This is the administrative account to which you want your PIVCard digital certificate mapped. Support will verify this information before mapping.

EXAMPLE

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 13

MESSAGE TAB/OPTIONS MENU

Click the Sign icon.

If the Sign icon is not on your menu, see Appendix A for instructions on configuring Outlook for digital signature.

Click Send.

14 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

IV.B Standard Configuration/ActivClient

The Department is deploying ActivClient™ software to increase workstation security. The examples in this section show both the standard Windows configuration and the configuration with ActivClient installed.

If your PIVCard is not already in the card reader, the system prompts you to insert it:

STANDARD CONFIGURATION WITH ACTIVCLIENT INSTALLED

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 15

Insert your PIVCard in the card reader.

Once the system has read your PIVCard, it prompts you to click OK to continue.

Click OK.

16 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

The system prompts you to enter your PIN.

PIN

Key in the personal identification number (PIN) for the PIVCard.

(Users who forget their PINS must follow their agency’s policies and processes for PIN reset before continuing.)

Click OK to send the e-mail to Support.

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 17

IV.C Support:

Export the Privileged User’s Digital Certificate

Open Outlook.

DIGITALLY SIGNED MESSAGES

APPEAR WITH THE DIGITAL

SIGNATURE ICON NEXT TO

THEM:

NON-DIGITALLY SIGNED

MESSAGES APPEAR WITH THE

REGULAR ENVELOPE ICON:

Open the digitally signed e-mail from the privileged user requesting mapping.

If ActivClient displays an Auto Contacts message, click No.

On the right side of the address panel, just below the timestamp, the system displays the digital signature icon:

Click the digital signature icon.

xsmith Support

Privileged User-xsmith xsmith@agency.gov

18 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

DIGITAL SIGNATURE: VALID

Click Details…

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 19

MESSAGE SECURITY PROPERTIES/SECURITY LAYERS

Click to highlight the security layer that begins with Signer:

Click View Details…

20 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

SIGNATURE/GENERAL TAB

Click View Certificate.

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 21

VIEW CERTIFICATE

Click the Details tab.

DETAILS TAB

Click Copy to File to launch the Certificate Export Wizard.

22 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

CERTIFICATE EXPORT WIZARD

Click Next.

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 23

CERTIFICATE EXPORT WIZARD/EXPORT FILE FORMAT/

SELECT THE FORMAT YOU WANT TO USE

Click Base-64 encoded X.509 (.CER).

24 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

CERTIFICATE EXPORT WIZARD/FILE TO EXPORT/FILE NAME

Click Browse.

Navigate to c:\temp

SAVE AS/FILE NAME

Name the certificate.

For easy reference, name the certificate for the privileged account to which you are mapping it.

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 25

Click Save.

Privileged User-xsmith

26 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

CERTIFICATE EXPORT WIZARD/FILE TO EXPORT/FILE NAME

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 27

CERTIFICATE EXPORT WIZARD/

COMPLETING THE CERTIFICATE EXPORT WIZARD

Click Finish.

28 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

CERTIFICATE EXPORT WIZARD/THE EXPORT WAS SUCCESSFUL

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 29

IV.D Support:

Map the PIVCard Digital Certificate to the Privileged Account

Open Active Directory Users and Computers.

ACTIVE DIRECTORY USERS AND COMPUTERS

Click the View tab.

VIEW TAB

Turn on Advanced Features.

ACTIVE DIRECTORY USERS AND COMPUTERS

Find the user name to which the digital certificate should be mapped.

ACTIVE DIRECTORY USERS AND COMPUTERS

Right click on the user name.

From the drop-down, select Name Mappings…

30 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

SECURITY IDENTITY MAPPING/X.509 CERTIFICATES TAB

Click Add.

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 31

ADD CERTIFICATE

Browse to the administrator’s digital certificate saved earlier.

Click Open.

32 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

ADD CERTIFICATE/CERTIFICATE PROPERTIES/IDENTITY MAPPING

Leave both boxes checked.

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 33

SECURITY IDENTITY MAPPING/X.509 CERTIFICATES TAB

Using a PIVCard, the privileged account holder may now log onto a privileged account from a machine running Windows Vista, Windows 7, or Windows

Server 2008.

NOTE: When a privilege user has their PIVCard Re-Keyed or a new PIVCard issued, remapping is not required unless there is a change in the

“Distinguished Name” e.g. user changes components.

34 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

V. CONFIGURING THE WORKSTATION

This section includes configurations that were tested at the workstation level and then applied at a Microsoft Active Directory Organization Unit (OU) level to all workstations within that OU.

V.A Required Policies

For this solution to work, there are three policies that must be applied to the workstation.

There are a number of ways to apply the policies. In the example below, IDMS used Microsoft Management Console (MMC).

V.A.1 ALLOW CERTIFICATES WITH NO EXTENDED KEY USAGE CERTIFICATE

ATTRIBUTE

In Windows operating systems before Vista, smart card certificates used for logon required an enhanced key usage (EKU) extension with a smart card logon object identifier (OID).

With this policy setting enabled, certificates with the following attributes can be used to log on with a PIVCard:

certificates with no EKU certificates with an All Purpose EKU certificates with a Client Authentication EKU

V.A.2 ALLOW SIGNATURE KEYS VALID FOR LOGON

With this policy setting enabled, the logon screen will list all available

PIVCard certificates that have a signature key.

V.A.3 ALLOW USER NAME HINT

With this policy setting enabled, the system will display an optional field during logon and elevation allowing the user to enter user name or username+domain to associate the user with a PIVCard certificate.

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 35

V.B Accessing Policy Settings

There are a number of ways to access the policy settings. In the example below, IDMS used Microsoft Management Console (MMC).

Click the Start icon.

In the search field, key in MMC.

Enter

Microsoft Management Console opens with an empty console (or administrative tool). The empty console has no management functionality until you add snap-ins.

MICROSOFT MANAGEMENT CONSOLE

Click File

36 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

FILE

Click Add/Remove Snap In

AVAILABLE SNAP-INS

Click Group Policy Object Editor

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 37

Click Add to launch the Group Policy Wizard

SELECT GROUP POLICY OBJECT

Leave the Group Policy Object field set to Local Computer.

Click Finish

Click OK

38 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

CONSOLE/CONSOLE ROOT

Click the triangle to the left of “Local

Computer Policy” to expand the selection.

Click the triangle to the left of

“Computer

Configuration” to expand the selection.

Click the triangle to the left of

“Administrative

Templates” to expand the selection.

Click the triangle to the left of

“Windows

Components” to expand the selection.

Click Smart Card

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 39

V.C Enable Policy Settings

V.C.1 ALLOW CERTIFICATES WITH NO EXTENDED KEY USAGE CERTIFICATE

ATTRIBUTE

Highlight Allow Certificates with no extended key usage certificate attribute.

Click Edit policy setting. .

Click Enabled.

Click OK.

V.C.2 ALLOW SIGNATURE KEYS VALID FOR LOGON

Highlight Allow signature keys valid for logon.

Click Edit policy setting.

Click Enabled.

Click OK.

V.C.3 ALLOW USER NAME HINT

Highlight Allow user name hint.

Click Edit policy setting.

Click Enabled.

40 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 41

VI. LOGGING ON

Insert the PIVCard in the card reader.

Microsoft Windows automatically identifies the certificate with the OID and presents that certificate for authentication.

Click Switch User.

42 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

At this point, the logon screen differs between workstations with ActivClient 6.2 and those with ActivClient 7 (beta) installed:

ACTIVCLIENT 6.2 ACTIVCLIENT 7 (BETA)

The certificate with the transparent box around it is the PIV

Authentication Certificate.

The certificate on the right is the PIV digital signing certificate. Select this certificate for mapping.

The certificate with the transparent box around it is the PIV authentication certificate.

The certificate in the middle is the PIV digital signing certificate. Select this certificate for mapping.

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 43

Key in the PIN

Key in the account as follows…

IF ACCOUNT IS WITHIN THE SAME DOMAIN AS THE COMPUTER:

username

IF ACCOUNT IS ON A DIFFERENT DOMAIN THAN THE COMPUTER:

domain\username

If the user’s digital certificate is mapped to only one account and that account is within the same domain as the computer, then the “Hint” field is not required.

For either certificate -- PIV authentication or PIV digital signature – if incorrect information is entered into the “Hint” field, the system will deny logon.

44 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

VII. APPENDIX A: CONFIGURING OUTLOOK FOR DIGITAL SIGNATURE

Open Outlook.

MENU

Click Tools.

TOOLS

Click Trust Center…

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 45

TRUST CENTER

Click E-Mail Security.

Although Outlook displays an E-Mail Security option for “Encrypted E-mail,” this is not a recommended encryption solution.

E-MAIL SECURITY/ENCRYPTED E-MAIL

If not checked already, check the box to select Send clear text signed message when sending message.

E-MAIL SECURITY/ENCRYPTED E-MAIL

Click Settings.

46 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

The Department is deploying ActivClient™ software to increase workstation security. The examples in this section show both the standard Windows configuration and the configuration with ActivClient installed.

If your PIVCard is not already in the card reader, the system prompts you to insert it:

Once the system has read the PIVCard, it will prompt you to click OK to continue.

MAPPING PIVCARD CERTIFICATES TO PRIVILEGED ACCOUNTS 47

CHANGE SECURITY SETTINGS

The Security Settings auto-populate from the PIVCard.

You have now configured Outlook for digital signature.

48 MAPPING PIVCARD CERTIFICATES TO A PRIVILEGED ACCOUNT

VIII. AUTHOR

James Burke is an expert in identity, credential, and access management with extensive experience developing technology strategy and architecture for access control systems.

At the U.S. Department of Justice, Mr. Burke provides technical leadership for Identity

Management Services as senior consultant on Federal policies for e-authentication, PKI, and personal identity verification.

James Burke, CISSP, MCSE

Technical Lead 202-305-4370

Identity Management Services james.burke@usdoj.gov

Enterprise Solutions Staff Two Constitution Square

Office of the Chief Information Officer 145 “N” Street, NE

Information Resources Management Washington, DC 20002

Justice Management Division

U.S. Department of Justice mailto:james.burke@usdoj.gov

File details come from the government source that posted it. Updated .