
TPM as a Virtual Smart Card | Wave Systems Corp. 2012
ESC 2.9.5 Client Manual
5.5.1 Cached Virtual Smartcard Expiration
How long the VSC credential is cashed is based on configurations set on the network domain controller.
The endpoint’s local security policy also needs to be set for how long the credential will remain cached:
1. Open an elevated command prompt.
2. Type gpedit.msc.
3. Navigate to Local Security Policy -> Computer Configuration -> Windows Settings -> Security
Settings -> Local Policies .
4. Open the Interactive logon: Number of previous logons to cache (in case domain controller is
not available) policy.
5. Configure this number to be above the number of user accounts that access the system.
a. EXAMPLE: If 5 people access the same machine, increase this setting to 6 or above.
b. NOTES:
i. Default value = 25
ii. Disable caching = 0
iii. Cache 50 logon attempts = <50
5.6. Uninstallation/Removal
An uninstallation script is provided to help resolve potential compatibility issues with other smart cards.
To remove this functionality from the Client Computer:
2. Copy Uninstall_Virtual_SmartCard_v<x>.<y>.vbs from the ERAS installation media to the client.
3. Open a Windows Command Prompt with Admin rights. This can be done by right clicking the
“Command Prompt” in the start menu and selecting “Run as administrator”.
4. Navigate to the folder containing the .vbs script and run “cscript.exe
Uninstall_Virtual_SmartCard_<x>.<y>..vbs”
5.7. Troubleshooting
Issue: The VBScript fails to run, and the TPM Virtual Smart card driver in device manager is listed as
“unknown”
Resolution: Turn of the Windows Update service and run the .VBS script again.
Comentarios a estos manuales