62
12
CoSign User Guide
150
Help Menu
The following options are available from the
Help
drop-down menu:
About
– Displays the version of the CoSign configuration utility as well as a link to the ARX web site.
Contents
– Displays the content of this chapter in on-line help format.
Create report
– Enables generating a report listing information on both the CoSign Client installation
and the CoSign appliance installation. Click
Save
to save the report to a file. The file can be sent to
ARX support for problem analysis.
The report includes three parts:
CoSign Client installation files – Includes all the files of the CoSign installation, their dates, sizes
and version information.
CoSign Client and Server parameters – Includes CoSign Client and Server parameters. The
parameters also include information that is displayed in the CoSign console.
Environmental information – Displays information about the PC in which the CoSign client is
installed, the version of the installed MS Office application, and other parameters that can be
valuable to ARX support for problem analysis.
Running the CoSign Configuration Utility in End User Mode
The CoSign Configuration Utility can also be used for editing and viewing a specific machine’s settings.
When the application runs in End User mode, it looks for all the CoSign components that are installed, and
for each component reads its settings and displays them in the relevant dialog box.
To run the CoSign Configuration Utility in End User mode:
Select
Start > Programs > ARX CoSign > CoSign Control Panel
. The CoSign Control panel
appears. Select
Client Configuration
. The CoSign configuration utility’s main window appears.
In End User mode, the information in the right pane reflects the state of the CoSign client parameters in the
Windows registry. For each group of parameters, the
Use Defaults
option is selected if none of this group’s
values were set in the Windows registry, and the fields are grayed out. If some of the group’s values were set
in the Windows registry, the
Set <Sub-node Name> Parameters
option is selected. After editing the
parameters’ values, the changes must be applied in order to update the Windows registry. These actions are
described below.
Note: To change settings in End User Mode, the current user must have the appropriate permissions to
change Windows registry values under HKEY_LOCAL_MACHINE.
Following is the list of actions that can be performed in End User mode:
Viewing and Editing CoSign Client Settings.
Applying the Changes to the Local Windows Registry.
Reloading the Windows Registry Configuration.
C# PDF Library SDK to view, edit, convert, process PDF file for C# PDF SDK for .NET allows you to read, add, edit, update, and delete PDF file metadata, like Title, Subject, Author, Creator, Producer, Keywords, etc.
pdf metadata editor online; pdf remove metadata
54
CoSign Configuration Utility
12
151
Exporting the configuration to a configuration file (refer to Exporting the Configuration to a
Configuration File).
Importing settings from a configuration file (refer to Importing Settings from a Configuration File).
Installing and downloading the CoSign CA certificate (refer to Install CoSign CA Certificate and
Download CoSign CA Certificate). This action is relevant in a CoSign Client installation only.
Downloading the CoSign CA CRL (Certificate Revocation List) (refer to Download CoSign CA CRL). This
action is relevant in a CoSign Client installation only.
Viewing and Editing CoSign Client Settings
To view and edit the CoSign Client Settings, follow the instructions in Using the CoSign Configuration Utility.
Changing CoSign client values using the CoSign Configuration Utility does not automatically change the
machine’s configuration. They must be explicitly applied in order to take effect (refer to Applying the
Changes to the Local Windows Registry).
Applying the Changes to the Local Windows Registry
Changes performed using the CoSign Configuration Utility do not automatically change the machine’s
configuration. They must be explicitly applied to the Windows registry in order to take effect. Select
File >
Apply (save to registry)
to apply all changes to the local machine settings.
If you close the application without specifying
Apply (save to registry)
you will lose all the changes you
have made.
Note: If you would like to restore default values after applying changes to the Windows registry, do not
use the
Not Configured
option. Instead, use the
Use Defaults
option which enforces resetting of the
parameters back to the default values.
Reloading the Windows Registry Configuration
If you are not satisfied with the changes you made to the configuration, and have not yet saved them to the
Windows registry, or if the local setting was changed outside the application and you want to reload the
current setting from the Windows registry, select
File > load (from registry)
to clear all current values in
the application dialog boxes and replace them with the Windows registry values.
Exporting the Configuration to a Configuration File
To export the local machine settings to a configuration file, select
File > Export to configuration file >
Export to 32bit
or select
File > Export to configuration file
>
Export to 64bit
. Browse to the desired file
name and location. Use the generated file in an operating system that matches the specified 32/64 bit
output file.
32
12
CoSign User Guide
152
Importing Settings from a Configuration File
Select
File > Import configuration file
to import settings from a configuration file. Browse to the desired
file name and location.
Setting Client Configuration – CoSign Client
The client configuration contains parameters related to connectivity and authentication with CoSign. The
CoSign client is the basic CoSign component; therefore all CoSign-enabled applications are affected by the
client’s settings.
Client configuration is composed of the following groups:
Appliances
– In this group you can manually define the addresses of the CoSign appliances and their
authentication mechanism.
Login dialog
– In this group you can set all the parameters relating to the login dialog box for the
environments in which such a dialog box appears.
Timeouts
– In this group you can set the various timeouts relating to communication between the
CoSign client and the CoSign appliance.
Miscellaneous
– In this group you can set logging parameters and other miscellaneous parameters.
Client - Appliances
This group enables you to manually set the IP address or DNS name of the CoSign appliances the machine
should work with, usually in Directory Independent environments, and whether to display the logon and
signing dialog boxes.
30
CoSign Configuration Utility
12
153
Figure 116 Configuring Client – Appliances Parameters
In the
Appliances
group, you can set the following CoSign client parameters:
Client optimization
–
If this value is checked,
the CoSign client uses optimized communication with
the CoSign appliance. Change this setting only if instructed to do so by ARX.
SSL Proxy definitions
– If the CoSign client can connect to the CoSign appliance only through an
SSL proxy, provide the SSL proxy parameters to enable communications. Specify the following:
Enable automatic ssl proxy detection
– If this parameter is checked, the CoSign client will
use the local PC definitions of the SSL proxy. In this case other SSL proxy parameters are
disabled.
SSL Proxy address
– The DNS name or IP address of the SSL Proxy.
Port
– The TCP/IP port number of the SSL proxy.
CoSign supports various authentication methods that may be required in order to access the CoSign
appliance through an HTTP proxy.
73
12
CoSign User Guide
154
If the HTTP proxy requires a userID and password authentication, the user will be prompted with a
userID and password request window. The user should enter a userID and password that are relevant
for the HTTP proxy.
Note: After changing HTTP proxy configuration, you must perform a hardware restart of the PC.
Prompt for logon method
– Select one of the following values if you wish to enforce a specific logon
method that is different from the one defined in CoSign:
Auto
(default) – The value is chosen automatically according to system setup.
SSPI
– Enable login through Single-Sign-On mode (relevant for Active Directory environments).
User Pwd Server Side (AD/LDAP)
– The user and password are passed to the server for
verification and the authentication check is performed by the CoSign appliance. This option is
relevant for Active Directory, and LDAP environments.
SSPI User Pwd Client Side (AD)
– The user is requested to input the user name and
password, which will be verified by the CoSign client. This option is relevant only for Microsoft
Active Directory environments.
Directory Independent Prompt
– The user password mechanism used in Directory
Independent environments.
SAML Server Side
– ADFS or SAML authentication will be used in Active Mode to enable the
client application to access the remote CoSign Server. The CoSign Client will first access the
local ADFS system for local authentication; the provided SAML ticket will then be presented to
the remote CoSign appliance.
Prompt for sign method
– Select one of the following values if you wish to enforce a specific
authentication method that is different from the one defined in CoSign:
Auto
(default) – The value is chosen automatically according to system setup.
None
– No prompt appears upon digital signature operation.
User Pwd Server Side (AD/LDAP)
– The user name and password are passed to the server for
verification. This option is relevant for Active Directory and LDAP environments.
Directory Independent Prompt
– The user password mechanism used in Directory
Independent environments.
Directory type
– Specify the directory used for synchronizing the CoSign users:
Auto
(default) – The directory type is taken from the CoSign server.
AD
– The CoSign users are defined in Active Directory.
Directory Independent
– The CoSign users are not automatically synchronized with any
directory.
LDAP
– The CoSign users are defined in an LDAP Directory.
Note: The directory type influences the automatic behavior of the prompt for logon method
and prompt for sign method.
51
CoSign Configuration Utility
12
155
Preferred Server
– If this field is not empty, the CoSign client will first attempt to connect to this
CoSign appliance. The Preferred server must be listed either in the SCP CoSign servers list or in the
following Appliances List.
Appliances list
– Enter the list of all available CoSign appliances. If more than one appliance is
added, the CoSign client performs load balancing between them. Use the
Add
and
Remove
buttons
to edit the list. You can specify a CoSign appliance by either its IP address or its DNS name.
You can also indicate which appliances are your preferred appliances by selecting the
relevant checkboxes. These selections are relevant for a high availability environment – the
CoSign client will first try to connect with the preferred appliances. This means that if more
than one appliance is listed, the CoSign client will first try to connect with the preferred
appliances.
In a non-high-availability configuration, preferences are ignored.
Figure 117 Indicating Preferred Servers for a High Availability Environment
REALM service
– The URL definition of the remote CoSign service. This is used by the ADFS system
to generate a SAML ticket that is suitable for the CoSign remote system.
Identity Provider
– The URL definition of the local ADFS server. The format of this URL is usually:
https://<DNS of local ADFS Server>/.
STS endpoint
– Specify which authentication method is used in the local Active Directory
environment:
Kerberos
or
Username and Password.
Kerberos
authentication – In this case, the end user will not be prompted for a user ID and a
password, and authentication will be based on a previous domain logon.
Username and Password
authentication – In this case, the user will be required to present a
user ID and a password when accessing the remote CoSign appliance. This user ID and
password will be validated against the local Active Directory deployment.
You must make sure that the mode you select is also enabled in your ADFS configuration.
Client – Login Dialog
This group enables you to control the login dialog behavior.
30
12
CoSign User Guide
156
Figure 118 Configuring Client – Login Parameters
In the
Login
group, you can set the following CoSign client parameters:
Automatic prompt for sign
–
If this value is checked, the CoSign client can sometimes use an
extended authentication mode. This mode can be used by the CoSign Connector for SharePoint,
when using cache-based extended authentication mode.
Verify user name in prompt for sign
– If this value is checked, the user has to provide both the user
name and password if prompt for sign is set. Otherwise, the user name is provided automatically by
the Prompt for Sign dialog box.
Force upper case user name
– Change this value only if instructed to do so by ARX support.
Close dialog when inactive for <number> Sec.
– Determines the time of inactivity the login dialog
box waits before automatically closing itself.
Note: If the login dialog box closes itself, the logon operation fails.
Permit known applications only
– Select this option to specify that CoSign can be used from a set
of known applications. This option is enabled by default. For the exact list of known applications,
48
CoSign Configuration Utility
12
157
contact ARX. Note that applications that use CoSign Signature APIs are automatically included in the
list.
Permit
login dialog pop-up except for designated applications
– Select this option to enable all
applications to display the login dialog box, except for the applications listed in the
Designated
applications
list.
Deny login dialog pop-up except for designated applications
– Select this option to enable only
the applications listed in the
Designated applications
list to display the login dialog box.
Note: The
Permit login
and
Deny login
options are relevant only in environments where a login
dialog box should appear before working with CoSign.
Disable login dialog
– Prevent all applications from popping up the login dialog box. If this option is
selected and an application tries to pop up the login dialog box, the operation will fail, and no dialog
box is displayed. This option should be used for unattended environments.
Designated applications
– A list of applications referenced by the options
Permit login dialog pop-
up except for designated applications
and
Deny login dialog pop-up except for designated
applications
. Use the
Add
and
Remove
buttons for editing this list.
Client – Timeouts
This group enables you to set the various timeouts relating to communication between the CoSign client
and the CoSign appliance.
Note: Do not change the timeouts parameters unless instructed to do so by ARX technical support. Incorrect
values might prevent the user from succeeding in connecting to the CoSign appliance.
Documents you may be interested
Documents you may be interested