3.2.2 Steps for Initializing and Configuring
User's TCG Password Vault
- Start the EMBASSY Security Center (Figure 3.22), select Password and then select Settings. This will open the TCG Security password settings screen shown in Figure 3.23.
- The Password Vault Status shows the current state of the TCG Security Password Vault:
- Created - vault exists, functioning normally
- Not Created - vault not yet created
- TPM Inactive - TPM disabled or TPM ownership not taken
- Vault Invalid - vault is not functioning normally; this is typically due to the TPM being reset and new ownership being established.
Select Create to configure the TCG Security Password Vault. This requires that the user create a Master Password (see Figure 3.24) and press OK. At this time, the user may configure the authentication method ("Master Password Only," "Master Password or Biometric," "Master Password and Biometric," or "Biometric only."
Once the TCG Security Password Vault has been created (see Figure 3.25), the status of the vault will change from Not Created to Created.

Figure 3.22: ESC - TCG Security Password

Figure 3.23: ESC - User's TCG Password Vault - Not Created
Note: The user must create the vault prior to enabling the Password Vault Function

Figure 3.24: ESC - Creating User's TCG Password Vault

Figure 3.25: ESC - User's TCG Password Vault Created
- Your TCG Security Password Vault is enabled by default when you create your Master password (see Figure 3.26). This will simplify password entry for use of the TPM keys. Once the Password Vault is enabled, users simply need to enter their Master Password to access the keys stored on their TPM. If other Authentication Types are enabled, users may access the vault using those types, such as a using a fingerprint in addition to the Master Password.
Note: Take full advantage of the TCG Security Password Vault by storing all of your TPM Key Passwords in the Vault. Simply check the "Save to TCG Security Password Vault" box when creating the TPM Password.

Figure 3.26 : Enable User's TCG Security Password Vault
- You are now ready to select the Vault login option (see Figure 3.27).
ESC Security settings allow the user to define how often the password/biometric must be entered when accessing the TPM.
The settings function as follows:
- High - The 'High' security setting provides the most security by requiring a password and/or fingerprint for every TPM Key access.
- Medium - The 'Medium' setting allows users specify the length of time that must pass before another password/fingerprint must be entered.
- Low - The 'Low' security setting provides the most convenience, requiring a password and/or fingerprint only once per Windows Session.
User's Security Settings may be defined by the IT Administrator. If this is the case, users will not be able to modify the Security Settings.

Figure 3.27 : ESC - TCG Security Password Vault Login Options
|