Identity Assurance Solution Readme

April 20, 2010

1.0 Overview

Identity Assurance Solution by Novell® (IAS) enables federal agencies to comply with the credential issuance, physical and logical access requirements of Homeland Security Presidential Directive 12 (HSPD-12). This solution provides convenient yet controlled access to disparate logical IT systems and physical facilities by using combinations of biometrics, passwords, personal identification numbers, smart cards, X.509 digital certificates, and other forms of advanced authentication.

It is fully integrated with Novell Identity Manager and meets FIPS 201 workflow, identity management, and card life cycle requirements. Personal Identity Verification (PIV) cards issued using this solution enable users to have physical and logical access to facilities and IT systems. This solution enables convergence of IT and physical systems to provide a complete end-to-end and seamless control system.

2.0 Known Issues

2.1 Smart Card Usage Behavior Differs from IASC 3.0.6

Firstly, card monitoring fails if you remove the smart card from the card reader before the Windows login process is complete.

Secondly, after a smart card based login to eDirectory through NWTray, removing the smart card from the card reader triggers the configured card removal action (workstation lock or log off). However, this is the expected behavior and can be ignored.

2.2 Issue with GemSafe and Ceres Card on Internet Explorer

On Windows XP, when trying to read certificates that are on a GemSafe smart card through internet explorer using the Novell Enhanced Smart Card iManager plug-in, a blank page appears.

Similarly, on Windows Vista, when trying to read certificates that are on a Ceres smart card through internet explorer using the Novell Enhanced Smart Card iManager plug-in, a blank page appears.

2.3 Issue with Unattended Installation of NESCM

On Windows XP, after an unattended installation of NESCM when you reboot the workstation, the card monitoring feature may not work for the first time. To use the card monitoring feature, lock the workstation and unlock it using NESCM.

2.4 Issue while Upgrading from IAS Client 3.0.6 to 3.0.7

After upgrading IAS Client from 3.0.6 to 3.0.7, the installer wizard neither performs an automatic restart nor does it prompt for system restart. Therefore, it is recommended to manually restart the machine after upgrading IAS client to 3.0.7.

3.0 Documentation

The following sources provide information about the Identity Assurance Solution:

4.0 Documentation Conventions

In this documentation, a greater-than symbol (>) is used to separate actions within a step and items in a cross-reference path.

A trademark symbol (® , ™, etc.) denotes a Novell trademark; an asterisk (*) denotes a third-party trademark

5.0 Legal Notices

Novell, Inc. makes no representations or warranties with respect to the contents or use of this documentation, and specifically disclaims any express or implied warranties of merchantability or fitness for any particular purpose. Further, Novell, Inc. reserves the right to revise this publication and to make changes to its content, at any time, without obligation to notify any person or entity of such revisions or changes.

Further, Novell, Inc. makes no representations or warranties with respect to any software, and specifically disclaims any express or implied warranties of merchantability or fitness for any particular purpose. Further, Novell, Inc. reserves the right to make changes to any and all parts of Novell software, at any time, without any obligation to notify any person or entity of such changes.

Any products or technical information provided under this Agreement may be subject to U.S. export controls and the trade laws of other countries. You agree to comply with all export control regulations and to obtain any required licenses or classification to export, re-export, or import deliverables. You agree not to export or re-export to entities on the current U.S. export exclusion lists or to any embargoed or terrorist countries as specified in the U.S. export laws. You agree to not use deliverables for prohibited nuclear, missile, or chemical biological weaponry end uses. Please refer to the Novell International Trade Services Web page for more information on exporting Novell software. Novell assumes no responsibility for your failure to obtain any necessary export approvals.

Copyright © 2008 - 2010 Novell, Inc. All rights reserved. No part of this publication may be reproduced, photocopied, stored on a retrieval system, or transmitted without the express written consent of the publisher.

Novell is a registered trademark of Novell, Inc. in the United States and other countries.

SUSE is a registered trademark of Novell, Inc., in the United States and other countries.

All third-party trademarks are the property of their respective owners.