Page 1 of 1

Thinkpad security / managing where to use pw's and fingerprn

Posted: Thu Jul 06, 2006 1:55 pm
by Torque
Hello Thinkpad forums.

When I first got the T43 in my signature, I enabled the fingerprint reader. Its set up so I have to swipe or enter a password, when I log on to Windows and when the Thinkpad starts up again after a standby session.

Since then, I've updated most of the software using the Software Installer.

Thing is, I want to enable the fingerprint ready for the power-on password, and deactivate the windows-logon and post-standby-logon.
Maybe the layout of the software has changed, or maybe I just have a bad memory - but where do I do this?
Have been all around the fingerprint control panel, without luck. Also enabled the power-on password in BIOS.

So, how do I deactivate the fingerprint windows-logon and standby-logon, aswell as enabling the fingerprint reader for power-on password?

Posted: Fri Jul 07, 2006 4:47 am
by mhca
I guess we have the same versions of the software if you have updated.
My apologies if my translastions from Danish versions of software to English causes confusion.

EDIT: Hehe just noticed you were a fellow Dane :-) Just PM me if you need the danish names for it but I guess you should be able to figure it out :-)

First go to Programs - ThinkVantage - ThinkVantage Fingerprint Software and choose Control Center.

Press the settings menu and choose System settings.
In the new window you should press the Logon tab. Check the box saying "Allow secure single sign-on at startup"


That will skip your Windows logon if you booted the machine and already scanned your finger for power-on password.


Then in the bios there is an option to enable fingerprint "Predesktop Authentication" which should be set to enabled. This option is found in Security -> Fingerprint.


Enjoy :-)

Posted: Fri Jul 07, 2006 5:23 am
by Torque
Hi, and thanks alot for your post :)

Now I'm set up so I only have to authenticate at powerup. But right after (in pre-boot) it asks me to enter the password aswell. How do I set up the thing to only want me to swipe?

Posted: Fri Jul 07, 2006 9:52 am
by mhca
Hmm sounds like you maybe have both harddisk and power-on passwords enabled?

I have only power-on and windows enabled so I don't know what to do about that.

Posted: Fri Jul 07, 2006 10:01 am
by Torque
I have the same settings. No password for the HDD.

BIOS: Power-on password and predesktop fingerprint authentication.
Windows: Logon (is bypassed by the single-logon feature).

Really strange :(

Posted: Fri Jul 07, 2006 10:07 am
by Torque
It works!

After a couple of sessions of trial and error, I raised the security level from "normal" to "secure".
now works like a charm :)

Posted: Fri Jul 07, 2006 10:13 am
by mhca
You changed it in bios?

I have considered if I should do that too but doesn't it require a longer password or something else to increase security?

I don't really need the security badly... I just like that ppl can't randomly turn on my laptop and use it.

Posted: Fri Jul 07, 2006 10:26 am
by Torque
mhca wrote:You changed it in bios?

I have considered if I should do that too but doesn't it require a longer password or something else to increase security?

I don't really need the security badly... I just like that ppl can't randomly turn on my laptop and use it.
It requires a Supervisor password which overrides the others, as far as I know. After making a supervisor password, I raised the security level. As far as I remember, all it does is to require that supervisor password to be typed in, in case the fingerprint reader cannot read or verify your swipe.

Posted: Tue Jul 11, 2006 12:56 pm
by mhca
[censored] now my password manager / CSS is annoying me again. It asks me to swipe my finger at startup as it did for a while but now it is asking for my password instead of asking me to swipe my finger at the sites where I saved my passwords.

That's why I searched for this post to find out what you actually asked about hoping I would find answers to my problems :)
sadly I didn't.


But I just realised what you experienced with the passwords after swiping your finger at boot.... that is because the first times you are using your fingerprint instead of password at boot it pairs the fingerprint together with your password. As soon as you have all your fingers paired it wont ask for password again. So if you delete them sometime you should expect to type passwords after swiping. Just wanted to let you know.

did css change the way it works?

Posted: Tue Jul 11, 2006 11:26 pm
by johnp126
I had previously had the computer set on power on to ask fingerprint 1x. if it was a soft boot, it also asked one time but when windows was logging in.

Since the last upgrade now I get the power on swipe
a swipe at windows
a css user login box that can be swiped and another one for the secure drive, this is crazy and it never asked me to change anything.

any ideas?

Posted: Wed Jul 12, 2006 2:53 am
by mhca
johnp, have you checked if you have single sign-on checked in the fingerprint control center?

I usually disable the CSS authentication which is done by entering CSS and choosing Expanded (??? I have danish version) and Administrate safety politics.

css auth

Posted: Wed Jul 12, 2006 11:41 am
by johnp126
under security mode i have convenient

under policies i have
login to windows / unlock computer / open pass mgr
predefined more secure

r&r protect with pass

Posted: Wed Jul 12, 2006 11:59 am
by mhca
Yeah but what about in Fingerprint Control Center

in settings and system settings there is a tab called "logon". Have you checked the box with single sign-on?

I haven't got my laptop at me right now and my versions are danish so I might confuse you a bit with my straight Danish to English translations.


Btw plz update your profile with location info.

css

Posted: Wed Jul 12, 2006 12:44 pm
by johnp126
in the logon box it shows

the thinkvantage css has been enabled on this computer. to change logon settings go to client security solution and manage security policies on advanced menu

and thats where i have 4 user actions listed in the thread above..