Connecting with an Entrust Certificate

This section provides important information about what to expect when connecting with an Entrust certificate under certain conditions.

Accessing Your Profile

If you are not already logged in, you must log in to Entrust Entelligence to access your Entrust Entelligence certificate profile, using the following procedure:

After you choose Connect on the VPN Client main window, the Entrust logon window appears.

  1. Choose a profile name from the pull-down menu.

    Your network administrator has previously configured one or more profiles for you through Entrust Entelligence. If the software is installed on your system but there are no profiles available, then you need to get a profile from your network administrator or directly through Entrust. Refer to Entrust Entelligence Quick Start Guide for instructions on obtaining a profile. The VPN Client Administrator Guide contains supplementary configuration information.

  2. After choosing a profile, enter your Entrust password.

    Check the Work offline field to use Entrust Entelligence without connecting to the Entrust PKI. If Work offline is checked and you press OK, the Entrust wizard displays the.

    You can ignore this message. Since you are connecting to your organization's private network using an existing certificate profile, you are not interacting with the Entrust PKI. If you see this message, click OK to continue.

  3. After completing the Entrust Login window, click OK.

    You may receive a security warning message from Entrust. This warning occurs, for example, when an application attempts to access your Entelligence profile for the first time or when you are logging in after a VPN Client software update. The message happens because Entrust wants to verify that it is acceptable for the VPN Client to access your Entrust profile.

  4. At the warning message, click Yes to continue.

    You can now use your Entrust certificate for authenticating your new connection entry.

Entrust Inactivity Timeout

If you have a secure connection and you see a padlock next to the Entelligence icon in the Windows system tray, Entelligence has timed out. However, you have not lost your connection. If you see the Entelligence icon with an X next to it, you are logged out of Entrust, and you did not have a secure connection initially. To make a new connection, start from the beginning (see "<paranum><paratext>").

Using Entrust SignOn and Start Before Logon Together

Entrust SignOn is an optional Entrust application that lets you use one login and password to access Microsoft Windows and Entrust applications. This application is similar to start before logon, which is a VPN Client feature that enables you to dial in before logging on to Windows NT. For information about start before logon, see "<paranum><paratext>".

If you want to use these two features together, you should make sure you have installed Entrust Entelligence with the Entrust SignOn module before installing the VPN Client. For information about installing Entrust SignOn, refer to Entrust documentation and the VPN Client Administrator Guide, Chapter 1.

To use these two features together, follow these steps:

  1. Start your system.

    When the SignOn option is installed, Entrust displays its own Ctrl Alt Delete window.

  2. Click Ctrl Alt Delete.

    The Entrust Options window and the VPN Client login window both pop up. The VPN Client window is active.

  3. To start your VPN connection, click Connect on the VPN Client main window.

    The Entrust login window becomes active.

  4. To log in to your Entrust profile, enter your Entrust password.

    The VPN Client password prompt window becomes active.

  5. Enter your VPN dialer username and password.

    The VPN Client authenticates your credentials and optionally displays a banner and/or a notification. Respond to the banner or notification as required. Then the Windows NT logon window is active.

  6. To complete the connection, enter your Windows NT logon credentials in the Windows logon window, then you are done.



Copyright © 1998-2004, Cisco Systems, Inc. All rights reserved.