3.1 Card Settings

Advanced Authentication supports the Microsoft policy Interactive logon: Smart card removal behavior, which allows to select an action on a card event. You can configure it to perform a force log off or lock a user session when a user presents card to the reader.

To use LEGIC LM3000 or LEGIC LE-762-1N readers, you must disable the other card plug-ins to avoid conflicts. To do this, perform the following steps:

  1. Open the configuration file depending on the platform:

    • Microsoft Windows: C:\ProgramData\NetIQ\Device Service\config.properties.

    • Linux: LEGIC and RFIDeas readers are not supported.

    • Apple Mac OS X: LEGIC and RFIDeas readers are not supported.

  2. Change the existing parameters based on the following scheme:

    • card.omnikeyEnabled: false

    • card.rfideasEnabled: false

    • card.smarfidEnabled: true

    • card.desfireEnabled: false

    • card.isCardIdGenerated=true to generate a new card identifier during enrollment. The default value is false and during each enrollment, the card identifier is not changed. The feature can be used only for LEGIC readers.

    • card.smarfidManualMode=true Without the card.smarfidManualMode in the config file or when card.smarfidManualMode=false, the reader’s LED is blue (read mode) by default and it always starts to blink when you put a card on it. When card.smarfidManualMode=true the reader’s LED is green (ready mode) by default and does not blink when you put a card on the reader. It will blink only if you are on Logon/Unlock screen and Windows Client requests to put a card. 1:N has to be disabled to disable auto-waiting for a card for Logon/Unlock screen. For more information on disabling 1;N, refer to Disabling 1:N. Also Interactive logon: Smart card removal behavior policy must be disabled to disable auto-waiting for a card when a user is logged in. For more information on disabling Smart card removal behavior policy, refer to the link. You can use the feature only for LEGIC readers.

    • card.smarfidManualBeepEnabled=true. You can use this option only when the manual mode is enabled (card.smarfidManualMode=true). When you set card.smarfidManualBeepEnabled to true, you can hear beeps from a supported LEGIC reader when you put a card on it. The default value of the parameter is false and the beeps are muted.

  3. Save the changes.

  4. Restart the workstation.