You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 78 Next »

During system deployment stage it is necessary to set up configuration files of each service. Configuration files of all system services are located in the root directory of IIS web applications (default path is %SystemDrive%\inetpub\wwwroot). 

Card Monitor service configuration files are located in %ProgramFiles%\Axidian CertiFlow\CardMonitor.

Configuration files are set up via Axidian CertiFlow Configuration Wizard which runs automatically if you check the option Run Axidian CertiFlow Configuration Wizard in Installation Wizard.
Or you can run the configuration wizard manually: Start - All ProgramsAxidian.

Here are the Axidian CertiFlow Setup Wizard parameters:

SectionDescription
Before starting work

Axidian CertiFlow Setup Wizard purpose and features

Restore configurationUploading a backup copy of Axidian CertiFlow configuration.

System features

  • Common features
  • Event Log
  • Microsoft CA
  • AirCard Enterprise
  • Client Agent

Configuring internal settings for Axidian CertiFlow web applications:

Management Console

Self-Service


Event Log:


Microsoft CA: Configure settings for working with Microsoft Certification Authority.

AirCard Enterprise: Configure integration with Axidian AirCard Enterprise virtual smart card server.

Client Agent: Configure Axidian CertiFlow Agent.

Users catalog

  • Active Directory
  • Tracked attributes

Information about users catalog and user attributes . 

The list of tracked user attributes in Microsoft CA certificate templates settings includes the following attributes by default:

  • Common name
  • E-mail
  • User principal name
You can track changes in user attributes only in Subject and Subject Alternative Name fields of the certificate.

Access control

  • Role administrator

Defining access settings to system services.

Specify an account to configure user privileges in Roles of Axidian CertiFlow Management Console. 

The specified account must have a User Principal Name (UPN) and belong to the specified users directory.

Database

  • Active Directory
  • Microsoft SQL
  • PostgreSQL
  • Encryption key

Information about the system's data storage and encryption algorithm.
Creating an encryption key, a backup copy or a key recovery from backup. Storage connection settings depend on selected storage type.

Card Monitor service

Card Monitor service controls smart card usage. Operations:

    • Revoking expired temporary cards
    • Deactivating (optional) cards and revoking certificates for users with disabled Active Directory accounts
    • Deleting AD disabled accounts (optional) from Axidian CertiFlow users catalog
    • Revoking and withdrawing (optional) cards for deleted users
    • Setting/resetting a card content status (about to expire/expired)
    • Updating card contents (available if a card is updated through Axidian CertiFlow Agent and the CA operator does not approve certificates automatically)
    • Registering There is no connection from the agent for a long time event in the system log
    • Sending email notifications to system administrators and users about the following events:
      • Expiring user certificates
      • Approve/reject to issue a card
      • Approve/reject to renew a certificate
      • Approve/reject to replace a card
      • Modifying a system policy applied to a user
      • Changing user attributes in users catalog 

For the Card Monitor service to run regularly, the account specified in the setup wizard must be part of Administrators group on the CertiFlow server and have permission to Log on as a batch job.

For Card Monitor service to work properly, create a service role with an account for Card Monitor in Roles section and define the following privileges for the role:

  • Disabling cards
  • Updating cards
  • Revoking cards
  • Cleaning cards
  • Unassigning cards
  • Removing cards
  • Removing AirCard

  • Removing record from custom log

    Set privileges to work with virtual smart cards, if AirCard integration is configured.

Confirmation

Summary of all settings and creating a backup copy of Axidian CertiFlow configuration.

When installing Axidian CertiFlow for the first time, save a copy of your configuration settings (option Backup current configuration settings in Confirmation section).

Configuration backup includes all settings, as well as encryption key and algorithm. When deploying new system servers, you can use the backup file - upload it in Restore configuration section. 

The backup file also includes all service accounts data. Keep the backup file in a secure place.

Results

Information about saving the specified values to the service configuration files.

When you finish configuring the Setup Wizard settings, the specified values are written to configuration files and encrypted. Encryption is performed using Microsoft .NET key (NetFramework ConfigurationKey) and RSA algorithm.


  • No labels