4.7 Configuring Gemalto Smart Card with Advanced Authentication

This section provides the configuration information of the following Gemalto smart cards:

  • IDPrime .NET Smart cards

  • SafeNet eToken 51x0

To configure the Advanced Authentication with Gemalto smart card, perform the following configuration tasks:

4.7.1 Installing the SafeNet Authentication Client 10

  1. Download the SafeNet Authentication Client 10.

  2. Navigate to the Customization Package folder and execute the SACCustomizationPackage-10.0.msi file.

    The SafeNet Authentication Client Customization Package Installation wizard is displayed.

  3. Click Next.

  4. Read the license agreement, and select I accept the terms in the license agreement. Click Next.

  5. Click Change to select a different destination folder or install the Customization Tool’s into the default folder:

    C:\Program Files\SafeNet\Authentication\

  6. Click Install.

  7. Click Finish.

4.7.2 Generating the Customized MSI file

  1. Click Start and navigate to Programs > SafeNet > SACAdmin > SAC Customization Tool.

  2. Select Features to install in the left pane.

  3. Select IDGo 800 Compatible Mode from the list.

  4. Click Actions > Generate MSI.

  5. Specify the file name and save files in the preferred folder.

    The generated msi files are as follows:

    • <file name>msi-x32-10.0

    • <file name>msi-x64-10.0

  6. Install the msi file according to the bits of your Operating System.

    The Installation wizard is displayed.

  7. Follow the installation steps and click Finish.

    NOTE:Ensure that the file IDPrimePKCS11.dll is available in one of the following paths:

    • C:\Program Files (x86)\Gemalto\IDGo 800 PKCS#11

    • C:\Program Files\Gemalto\IDGo 800 PKCS#11

4.7.3 Configuring PKCS Path in the Device Service

  1. Install NetIQ Advanced Authentication Device Service.

  2. Navigate to C:\ProgramData\NetIQ\Device Service\config.properties.

  3. Set the pki.vendorModule to the customized PKCS file path as follows:

    pki.vendorModule= C:\\Program Files (x86)\\Gemalto\\IDGo 800 PKCS#11\\IDPrimePKCS11.dll.

    NOTE:Do not use a 64 bit library file (IDPrimePKCS1164.dll).

  4. Save and Restart Device Service.

NOTE:If you have SafeNet Authentication Client (SAC) version v8.x, set the pki.vendorModule to auto. The SAC uses eToken.dll library for IDPrime cards.