Ensure Technologies – User’s Guide for XyLoc Client ver 8.x.x
Drawing#: 510-0100-003 Drawing Rev: 0.08 Rev Date: 04-25-2006
Page 8 of 62
XyLoc Secure Login and Password Overview
Windows 2000/XP
The Windows NT based Operating Systems (2000/XP) are designed with more inherent
security. There is already a GINA in place which controls the logins, profiles and security
permissions on the workstation. The XyLoc system also has a GINA, which takes over the
primary windows logon and in turn “calls” the Microsoft GINA. Most of the inherent
Microsoft security is still in place, and XyLoc enhances that security with a proximity based
solution.
The XyLoc Secure Login will be the first screen that is displayed on the PC, and the same
basic login process will be used. The exception is that hitting “CTRL+ALT+DEL” on the
keyboard will allow access to the standard Microsoft/Novell login box and a user can login
with a valid local or domain account and override XyLoc. This is to allow an Administrator
to still gain access to the PC, even if that Administrator does not have a XyLoc account.
There is a registry setting that can be enabled which will block all non-XyLoc accounts from
gaining access to the system, even Administrators, however this setting is disabled on the
default installation.
Also, the F8 keystroke at boot up is not disabled at login. This is due to the security of
Windows itself, and only an Administrator should have access to truly bypass XyLoc in Safe
Mode.
Lastly, in Windows 2000/XP, the password-protected screensaver is no longer password
protected. Because XyLoc takes control of the security of the workstation, XyLoc also
handles the locking action of the PC. Since the system will lock immediately when the user
leaves his/her active range the password protection on the screensaver is no longer needed. It
will still function as a standard screensaver, but will no longer have a password.
XyLoc Password
For flexibility and security, the XyLoc system provides an additional password, the
XyLoc
Password
(sometimes referred to as a PIN). The XyLoc password is only used in a Kiosk
account and has two possible applications:
1.
It is used by the
Kiosk Account
feature to provide multi-factor authentication in a shared
log-on account.
NOTE
: Starting in version 8.2.4, this is the only password that is
accepted in conjunction with a user’s XyLoc key.
2.
It is used in conjunction with the user’s
Personal Name
when performing a
Password
Override
in a Kiosk account to ensure individual security even when a XyLoc Key is not
present.
NOTE: In a XyLoc Solo, when used in a unique account environment, the XyLoc Password
(PIN) will synchronize with the user’s unique account password. The Kiosk account is the
only type that will have a XyLoc password that can differ from the user’s system account
password. If it is desired to use at PIN with a unique account, XyLoc 8.3.6
with
XSS 4.2.4
must be used. Earlier version of either will not support this functionality.