3.4.4 Steps to Enroll/Update TPM
- Start the EMBASSY Security Center and select Windows Login.
- Select the radio button next to TPM Secuity Chip and select the Enroll/Update button (as shown in Figure 3.48).

Figure 3.48: ESC - Select the Enroll/Update TPM
Note: Only a Domain Administrator will have access to Enroll/Update TPM. If the Enroll/Update TPM button is inactive, it's because you first need to install a digital certificate.
- Selecting the Enroll/Update TPM will launch a wizard that will guide you through creating a TPM-based certificate and enrolling users for TPM-based authentication (see Figure 3.49).

Figure 3.49: TPM-based PKI Enrollment Wizard
- Press Next, then the Select User and Domain to Enroll dialog box will be displayed (see Figure 3.50)
- Press the Select User button; this will display the window shown in Figure 3.51.

Figure 3.50: TPM-based PKI Enrollment Wizard - Select User

Figure 3.51: TPM-based PKI Enrollment Wizard - Enter Userid
- Press Location to verify the location and press Check Names to verify it's a valid user id (see Figure 3.52). Then Press OK.

Figure 3.52: TPM-based PKI Enrollment Wizard - Enter Userid
- Figure 3.53 shows the information of the userid and domain entered in the Select User and Domain to enroll window. Verify information, you can make corrections by pressing Back, otherwise press Next to continue.

Figure 3.53: TPM-based PKI Enrollment Wizard - User to enroll selected

Figure 3.54: TPM-based PKI Enrollment Wizard - Create Key
- Then next step is to create the password that the user will use to login, see Figure 3.54, then press OK.
- Once the password has been created, you need to associate the password with the Digital certificate of authority that was previously installed on the computer. See Figure 3.55, enter the name of the server where you obtained your certificate of authority, then press Next.
- Figure 3.56 shows that it's building a certificate request, once the request has been build it will prompt you to enter the password you just created (see Figure 3.57), enter the password and press OK.

Figure 3.55: TPM-based PKI Enrollment Wizard - CA Selection

Figure 3.56: TPM-based PKI Enrollment Wizard - Building Certificate Request

Figure 3.57: TPM-based PKI Enrollment Wizard - Enter password
- Figure 3.58 shows that it's accepting the certificate, once that step has completed successfully, you would have successfully enrolled your user, see Figure 3.59.
Note: To enroll additional users you will repeat the steps just performed.

Figure 3.58: TPM-based PKI Enrollment Wizard - Accepting Certificate

Figure 3.59: TPM-based PKI Enrollment Wizard - Enrollment Complete
|