Live Chat Software by Kayako |
Error “Invalid flags specified” at the issuance, errors at deleting and initializing eToken cards when SAC 10.5.175.0 or higher is used
Posted by Ilya Solovyev, Last modified by Ilya Solovyev on 28 March 2022 03:55 PM
|
|
Error “Invalid flags specified” at the issuance, errors at deleting and initializing eToken cards when SAC 10.5.175.0 or higher is used. Description: Errors when eToken cards used with SafeNet Authentication Client 10.5.175.0 or higher:
Cause: After installing SafeNet Authentication Client 10.5.175.0 or higher, by default options are enabled:
Solution: All restrictions can be removed in two ways, through GPO or registry editing. In the case of registry editing, there are examples where changes will only affect Indeed CM components and will not be distribute to other software: 1. Verify the quality of the administrator's PIN. The administrator PIN must have at least three character groups and be at least 8 characters long. Character groups: Lowercase letters, uppercase letters, numbers, and special characters.
Registry: Use default settings: 2. Restriction on weak key generation. The following algorithms and features are prohibited or not recommended for use in SAC 10.5: MD5, RC2, RC4, DES, 2DES, GenericSecret<112, RSA-RAW, RSA<2048, ECC<224, ECB, Sign-SHA1. GPO:
Registry: [HKEY_LOCAL_MACHINE\SOFTWARE\SafeNet\Authentication\SAC\Crypto\IndeedCM.Client.Server.exe] [HKEY_LOCAL_MACHINE/SOFTWARE/SafeNet\Authentication\SAC\Crypto\IndeedCM.Agent.Client.exe] Use default settings: 3. Prohibit the generation of exportable keys. By default in SAC 10.5, exportable keys are not allowed to be generated on the device. GPO:
Registry: [HKEY_LOCAL_MACHINE\SOFTWARE\SafeNet\Authentication\SAC\Crypto\IndeedCM.Client.Server.exe] Use default settings: All ADMX group policy files and registry file attached.
| |
|