3.2.1 Steps for Initializing and Configuring
User's TCG Password Vault
- Start the EMBASSY Security Center (Figure 3.7), select Password and then select Settings. This will open the TCG Security password settings screen shown in Figure 3.8.
- The Password Vault Status shows the current state of the TCG Security Password Vault:
- Initialized - vault is initialized, functioning normally
- Not Initialized - vault not yet initialized
- TPM Inactive - TPM disabled or TPM ownership not taken
- Vault Invalid - vault is not functioning normally; this is typically due to the TPM being reset and new ownership being established.
Select Initialize to configure the TCG Security Password Vault. This requires that the user enter their Windows Password (see Figure 3.9) and press OK.
Once the TCG Security Password Vault has been initialized (see Figure 3.10), the status of the vault will change from Not initialized to Initialized.

Figure 3.7: ESC - TCG Security Password

Figure 3.8: ESC - User's TCG Password Vault - Not Initialized
Note: A user must initialize the vault prior to enabling the Password Vault Function

Figure 3.9: ESC - Initializing User's TCG Password Vault

Figure 3.10: ESC - User's TCG Password Vault Initialized
- Once the TCG Security Password Vault Status shows as Initialized, you are ready to enable the TCG Security Password Vault. Check the box next to "Enable my TCG Security Vault" (see Figure 3.11). This will simplify password entry for use of the TPM keys. Once the Password Vault is enabled, users simply need to enter their Windows Password for accessing the keys stored on their TPM. Additionally, if other Authentication Types are enabled from the Windows Login window, users may access the vault using those types, such as a using a Fingerprint in addition to the Windows Password.

Figure 3.11: ESC - Enable User's TCG Security Password Vault
Note: Take full advantage of the TCG Security Password Vault by storing all of your TPM Key Passwords in the Vault. Simply check the "Save to TCG Security Password Vault" box when creating the TPM Password.
- You are now ready to select the Vault login option (see Figure 3.12).
ESC Security settings allow the user to define how often the password/biometric must be entered when accessing the TPM.
The settings function as follows:
- High - The 'High' security setting provides the most security by requiring a password and/or fingerprint for every TPM Key access.
- Medium - The 'Medium' setting allows users specify the length of time that must pass before another password/fingerprint must be entered.
- Low - The 'Low' security setting provides the most convenience, requiring a password and/or fingerprint only once per Windows Session.
User's Security Settings may be defined by the IT Administrator. Should this be the case, users will not be able to modify the Security Settings.

Figure 3.12 : ESC - TCG Security Password Vault Login Options
|