
Self-Encrypting Drive Management | Wave Systems Corp. 2012
ESC 2.9.5 Client Manual
Smart Card to SED - Supported Card Readers
Internal smart card readers are supported on Dell and Lenovo Platforms. External smart card readers are
supported on Dell, Lenovo, and HP platforms. The external smart card readers must be CCID-compliant.
HP platforms require external readers for pre-boot authentication.
Smart Card to SED – Preparation
The smart card must be prepared in advance. Before Wave can enroll the certificate on the card into
pre-boot, you must be able to use the card for Windows logon. This consists of three steps; refer to the
smart card vendor documentation for guidance on completing these steps – some of them may already
be completed.
1. Provision the card - This involves setting up the setting up the PIN, maximum authentication
attempts to the card, allocating size for each certificate, and other settings. (.NET smart cards
are already provisioned)
2. Install certificates onto the card.
3. Configure the domain to use the certificate for Authentication (CAC/PIV).
Someone in your organization must also remotely initialize the client for Smart card authentication using
ERAS before a smart card can be used to authenticate to the drive; this process is documented in the
ERAS Admin Manual.
Smart Card to SED - TDM Enrollment Wizard
Depending on settings made on the server, you may need to initiate the TDM Enrollment Wizard to
make the SED recognize the self-encrypting drive. This Wizard is also called the Multifactor Enrollment
Wizard.
The TDM Enrollment Wizard will ask you for your smart-card pin. This was created before the card was
set-up for Windows Authentication. It may also ask for a drive password. This is a temporary drive
password used for the purpose of unlocking the drive in order to enroll the smart card.
Figure 1 - You may need to enter a password and pin, depending on settings made at the server
Comentarios a estos manuales