User's Manual

End-User Reference Guide
21
For all information about the TrueCrypt software, please refer to the
documentation available at http://www.truecrypt.org.
Accept all default values during the installation. Any deviation from the default
values may compromise the installation.
While the secure drive is being created (by request of your IT administrator), your
keyboard and mouse will be locked for a short time. Do not reboot your laptop during
this process. . The keyboard and mouse will unlock when the secure drive creation
completes after a couple of minutes.
USING A LAPTOP THAT IS CONFIGURED FOR SMART CARD LOGIN
You can skip this section if your laptop is configured for the default NT Domain login.
If the laptop is configured for smart card login, everything remains the same except
the following:
1. To start the login and logout procedures you must press the Ctrl-Alt-Backspace
key combination instead of the Ctrl-Alt-Delete combination. To login, please
enter your six digit PIN. Default PIN is 123456, and it should be changed using the
steps described below. Note that the smart card - Authentication works only if you
are using laptop key, any external keyboard may not authenticate.
2. To complete the login procedure you must enter a six-digit PIN instead of your NT
Domain username and password.
3. To change the login PIN, click Start > Run, type the command <pintool>, and click
OK. You finish by entering the old PIN and the new one.
4. Your login certificate is removed from your card and your smart card login is
disabled after four consecutive unsuccessful login attempts made with an invalid
PIN.
5. If the smart card login is disabled in your laptop you must contact your IT
helpdesk to re-enable it. After the smart card login is re-enabled, the PIN is reset
to a fixed default value (<123456>). For security reasons, you should invoke the
pintool command to customize the PIN value immediately after the smart card
login is re-enabled.
6. If you press the Ctrl-Alt-Backspace key combination after having logged into your
laptop using the same sequence and your PIN, you may observe different
behaviors depending on the Group Policy settings that your administrator has
applied to your laptop. Note that the smart card - Authentication works only if
you are using laptop key, any external keyboard may not authenticate. The
following options are available: (i) <No Action>; (ii) <Lock Workstation> (to
temporarily lock your laptop); and (iii) <Force Logoff> (to close your user session).
You can verify the settings for you laptop by entering the gpedit.msc command at
the Start>Run prompt and then checking the value of the Local computer
Policy>Computer Configuration>Windows Settings>Security Settings>Local
Policies>Security Options>Interactive logon: Smart card removal behavior policy.
Note: - If your laptop is coming out of sleep mode or hibernate mode than the NLG
LED will blink a red light for few seconds. Wait until it turns to a solid red light and
then login by pressing Ctrl-Alt-Backspace.