NetIQ SecureLogin Quick Start Guide

November 2015

It is highly recommended that you read this guide carefully before proceeding with installing, configuring, and deploying NetIQ SecureLogin. This document contains hardware and software details and information about the required versions of the dependent components necessary for successfully setting up SecureLogin.

1.0 What Is SecureLogin?

SecureLogin is an enterprise single sign-on product. It provides authentication solutions for web, Windows, host, and legacy applications. SecureLogin functions as a credential provider for all the applications that users access.

It is also a credential management tool developed to increase an organization's network security while lowering support costs.

SecureLogin securely manages and encrypts the users credential information in the directory. It stores usernames and passwords and automatically retrieves them for users, when required.

2.0 Prerequisites

The following hardware and software configurations are required for the successful installation and deployment of SecureLogin:

2.1 Disk Space

A minimum of 128 MB space is required in the Windows file system. An additional 55 MB is required for temporary files, which is deleted after the installation is complete.

2.2 Operating Systems

  • Windows 10

  • Windows 8.1

  • Windows 8

  • Windows 7

  • Windows 2012

  • Windows 2008

  • Windows 2003

  • Windows Vista

  • Windows XP

  • Citrix

2.3 Terminal Servers

  • Citrix ICA client version 12 and above

  • Presentation Server 6.0 and 6.5

  • Microsoft Terminal Services clients, Remote Desktop Protocol 5.0 or later

2.4 Directories

  • Active Directory installed on Windows 2003, 2008 0r 2012

  • eDirectory 8.8.8 installed on Open Enterprise Server, Windows or SUSE Linux Enterprise System

  • eDirectory 8.8.7 installed on Open Enterprise Server, Windows or SUSE Linux Enterprise System

  • OpenLDAP

    NOTE:SecureLogin can be installed on any LDAP v3-compliant directory.

2.5 Browsers

  • Chrome 45 and above

  • Mozilla Firefox 2.0 to 40

  • Internet Explorer 8.0 to 11.0

2.6 Miscellaneous

  • iManager 2.7.7

  • iManager 2.7.6

  • iManager 2.7

  • .NET framework 3.5, 4.0 or 4.5

  • Sun Java Runtime Environment and Oracle Java Forms

  • Support for a variety of Smartcard Middleware

    • ActiveClient

    • NESCM

  • Client Login Extension [required for Emergency Access feature. Client Login Extension 3.9 is not bundled with the SecureLogin installer.]

NOTE:You can download the latest version of Client Login Extension from the Downloads website.

3.0 Downloading SecureLogin

  1. Log in to the Customer Centre

  2. Download SecureLogin 8.1 or any required service packs.

4.0 Installing SecureLogin Using the Installer

  1. Extract the NetIQ SecureLogin zip file contents to a location on your system.

  2. Run NetIQSecureLogin.exe to start the installation.

  3. Accept the End-User License Agreement.

  4. Select the Datastore to install SecureLogin. Click Next.

  5. From the Custom Setup screen, select the features you want to install.

  6. Click Next and follow the prompts to install SecureLogin.

5.0 Installing SecureLogin Using Command-Line Options

If you prefer to install SecureLogin using command-line options, see Installing through the Command Line in the NetIQ SecureLogin Installation Guide

6.0 Installing in a Different Locale

The SecureLogin installer detects the default locale on the system and completes the installation.

For example, if the default locale on your system is Spanish, SecureLogin is installed in Spanish.

If you want to change the locale, execute the following command:

NetIQSecureLogin.exe -lang language-code

Replace language-code with the code from the following supported languages:

  • 1028 - Chinese

  • 1031 - German

  • 1033 - English (default)

  • 1034 - Spanish

  • 1036 - French

  • 1041 - Japanese

  • 1045 - Polish

  • 1046 - Portugese

For example, to install in French, the command is:

NetIQSecureLogin.exe -lang 1036

7.0 Modifying, Repairing or Removing an Installation

  1. Run NetIQSecureLogin.exe

  2. Use the following options to change the existing configuration:

    Table 1 Installer Options

    Option

    Description

    Modify

    Use the Modify operation to uninstall features installed during installation.

    Repair

    Use the Repair operation to install any missing components.The installation program detects the previously installed components and re-installs them

    Uninstall

    Use the uninstall operation to uninstall SecureLogin and do a fresh install.

    For more information about Installer options, seeModifying, Repairing, or Uninstalling in the NetIQ SecureLogin Installation Guide

8.0 Upgrading SecureLogin

  1. Run NetIQSecureLogin.exe

  2. You are prompted to proceed with the upgrade with the current language settings. Click Proceed.

  3. The Installation Wizard is launched. Click Next

  4. The license agreement page appears. Accept the license agreement.

For more information about Upgrading SecureLogin, see Upgrading in the NetIQ SecureLogin Installation Guide

9.0 Legal Notice

THIS DOCUMENT AND THE SOFTWARE DESCRIBED IN THIS DOCUMENT ARE FURNISHED UNDER AND ARE SUBJECT TO THE TERMS OF A LICENSE AGREEMENT OR A NON-DISCLOSURE AGREEMENT. EXCEPT AS EXPRESSLY SET FORTH IN SUCH LICENSE AGREEMENT OR NON-DISCLOSURE AGREEMENT, NETIQ CORPORATION PROVIDES THIS DOCUMENT AND THE SOFTWARE DESCRIBED IN THIS DOCUMENT "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SOME STATES DO NOT ALLOW DISCLAIMERS OF EXPRESS OR IMPLIED WARRANTIES IN CERTAIN TRANSACTIONS; THEREFORE, THIS STATEMENT MAY NOT APPLY TO YOU.

This document and the software described in this document may not be lent, sold, or given away without the prior written permission of NetIQ Corporation, except as otherwise permitted by law. Except as expressly set forth in such license agreement or non-disclosure agreement, no part of this document or the software described in this document may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, electronic, mechanical, or otherwise, without the prior written consent of NetIQ Corporation. Some companies, names, and data in this document are used for illustration purposes and may not represent real companies, individuals, or data.

This document could include technical inaccuracies or typographical errors. Changes are periodically made to the information herein. These changes may be incorporated in new editions of this document. NetIQ Corporation may make improvements in or changes to the software described in this document at any time.

© 2015 NetIQ Corporation and its affiliates. All Rights Reserved.

U.S. Government Restricted Rights: If the software and documentation are being acquired by or on behalf of the U.S. Government or by a U.S. Government prime contractor or subcontractor (at any tier), in accordance with 48 C.F.R. 227.7202-4 (for Department of Defense (DOD) acquisitions) and 48 C.F.R. 2.101 and 12.212 (for non-DOD acquisitions), the government’s rights in the software and documentation, including its rights to use, modify, reproduce, release, perform, display or disclose the software or documentation, will be subject in all respects to the commercial license rights and restrictions provided in the license agreement.

Check Point, FireWall-1, VPN-1, Provider-1, and SiteManager-1 are trademarks or registered trademarks of Check Point Software Technologies Ltd.

Access Manager, ActiveAudit, ActiveView, Aegis, AppManager, Change Administrator, Change Guardian, Cloud Manager, Compliance Suite, the cube logo design, Directory and Resource Administrator, Directory Security Administrator, Domain Migration Administrator, Exchange Administrator, File Security Administrator, Group Policy Administrator, Group Policy Guardian, Group Policy Suite, IntelliPolicy, Knowledge Scripts, NetConnect, NetIQ, the NetIQ logo, PlateSpin, PlateSpin Recon, Privileged User Manager, PSAudit, PSDetect, PSPasswordManager, PSSecure, Secure Configuration Manager, Security Administration Suite, Security Manager, Server Consolidator, VigilEnt, and Vivinet are trademarks or registered trademarks of NetIQ Corporation or its affiliates in the USA. All other company and product names mentioned are used only for identification purposes and may be trademarks or registered trademarks of their respective companies.

For purposes of clarity, any module, adapter or other similar material ("Module") is licensed under the terms and conditions of the End User License Agreement for the applicable version of the NetIQ product or software to which it relates or interoperates with, and by accessing, copying or using a Module you agree to be bound by such terms. If you do not agree to the terms of the End User License Agreement you are not authorized to use, access or copy a Module and you must destroy all copies of the Module and contact NetIQ for further instructions.

If this product claims FIPS compliance, it is compliant by use of one or more of the Microsoft cryptographic components listed below. These components were certified by Microsoft and obtained FIPS certificates via the CMVP.

893 Windows Vista Enhanced Cryptographic Provider (RSAENH)

894 Windows Vista Enhanced DSS and Diffie-Hellman Cryptographic Provider (DSSENH)

989 Windows XP Enhanced Cryptographic Provider (RSAENH)

990 Windows XP Enhanced DSS and Diffie-Hellman Cryptographic Provider (DSSENH)

997 Microsoft Windows XP Kernel Mode Cryptographic Module (FIPS.SYS)

1000 Microsoft Windows Vista Kernel Mode Security Support Provider Interface (ksecdd.sys)

1001 Microsoft Windows Vista Cryptographic Primitives Library (bcrypt.dll)

1002 Windows Vista Enhanced Cryptographic Provider (RSAENH)

1003 Windows Vista Enhanced DSS and Diffie-Hellman Cryptographic Provider (DSSENH)

1006 Windows Server 2008 Code Integrity (ci.dll)

1007 Microsoft Windows Server 2008 Kernel Mode Security Support Provider Interface (ksecdd.sys)

1008 Microsoft Windows Server 2008

1009 Windows Server 2008 Enhanced DSS and Diffie-Hellman Cryptographic Provider (DSSENH)

1010 Windows Server 2008 Enhanced Cryptographic Provider

1012 Windows Server 2003 Enhanced Cryptographic Provider (RSAENH)

This product may also claim FIPS compliance by use of one or more of the Open SSL cryptographic components listed below. These components were certified by the Open Source Software Institute and obtained the FIPS certificates as indicated.

918 - OpenSSL FIPS Object Module v1.1.2 - 02/29/2008 140-2 L1

1051 - OpenSSL FIPS Object Module v 1.2 - 11/17/2008 140-2 L1

1111 - OpenSSL FIPS Runtime Module v 1.2 - 4/03/2009 140-2 L1

Note: Windows FIPS algorithms used in this product may have only been tested when the FIPS mode bit was set. While the modules have valid certificates at the time of this product release, it is the user's responsibility to validate the current module status.

EXCEPT AS MAY BE EXPLICITLY SET FORTH IN THE APPLICABLE END USER LICENSE AGREEMENT, NOTHING HEREIN SHALL CONSTITUTE A WARRANTY AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS, AND WARRANTIES INCLUDING, WITHOUT LIMITATION, ANY IMPLIED WARRANTY OR CONDITION OF FITNESS FOR A PARTICULAR PURPOSE ARE HEREBY EXCLUDED TO THE EXTENT ALLOWED BY APPLICABLE LAW AND ARE EXPRESSLY DISCLAIMED BY NETIQ, ITS SUPPLIERS AND LICENSORS.