Setup guide

UNCLASSIFIED
UNCLASSIFIED
84
Chapter 6 –
Future Guidance
4. Type a name for the new keychain in the Save As box in the window, and
click on Create. For this example, the name of the new keychain is
“accounts_keychain”.
5. Select a new password for the keychain and enter it in the window that
appears on the screen. Use the password assistant (the “i” button) to check
the strength of the password.
6. Select Change Settings for keychain “accounts_keychain”… from the Edit
menu.
7. Make sure the Lock when sleeping option is selected, and that the Lock
after x minutes of inactivity option is selected and set to 0 (Figure 36).
Note that if the value ‘0’ is used here, the user will not be able to see the
password for any items in the keychain without first changing the value to ‘1’
or higher.
Figure 36:Accounts Keychain Settings
8. Move any items containing credentials for web-based accounts, or any other
items to be protected by this keychain, into the newly created keychain. This
can either be done using the Cut and Paste features from the Edit menu, or
by selecting the item to be moved and dragging it over the new keychain.
Keychain Access will then prompt for the keychain password of the
keychain originally containing the item. Enter the password and click the
Allow Once button. The item should appear in the item list for the new
keychain, and should no longer appear in the original keychain.
9. Configure all items now in this keychain. Select an item in the list, and click
on Access Control. Make sure both Confirm Before Allowing Access
and the Ask for keychain password are selected. If there are any entries
in the access list, select and remove them. Repeat this step for all items in the
list.
Setting the Default Keychain
As stated earlier, any new items automatically saved to a keychain by an application
are stored in the default keychain, which is initially set to be the login keychain.
The user can designate any keychain as the default. The default keychain should be
one that is completely protected. The login keychain as configured earlier in this