Skip to main content
Version: Axidian CertiFlow 7.2

Client Tools

With Axidian CertiFlow Client Tools you can unlock cards that are used for Windows OS authentication in online and offline modes, as well as cards not used for OS logon.

Install Client Tools

To install Axidian CertiFlow Client Tools on user workstations, run the AxidianCertiFlow.Client.Tools-<version number>.en-us.msi file from the AxidianCertiFlow.Client catalog and follow the wizard instructions.

Card unlock modes

You can unlock a card using two modes: online and offline. For more information, see Administrator guide.

Online mode requires a connection between the user's workstation (where the locked card is connected) and the Axidian CertiFlow server. This connection is used to authenticate the user by verifying their answers to security questions.

We recommend using a secure HTTPS connection for communication between user workstations and the Axidian CertiFlow server for online unlock.

Configure online card unlock

Configure card unlock using Windows Group Policies or the Windows Registry (for workstations outside a Windows domain).

To enable the online card unlock feature, configure a Group Policy Object (GPO). This procedure installs the necessary administrative templates and applies the policy to the user workstations.

  1. Copy the contents of the AxidianCertiFlow.Client\Misc\ catalog to your central ADMX file store. The standard location on a domain controller is C:\Windows\SYSVOL\domain\Policies\PolicyDefinitions.

    info

    If you use a local ADMX store instead, copy the files to C:\Windows\PolicyDefinitions.

  2. Open the Group Policy Management console.

  3. In the console tree, create a new GPO or select an existing GPO that applies to the target user workstations.

  4. Right-click the GPO and select Edit.

  5. In the Group Policy Management Editor, go to Computer ConfigurationPoliciesAdministrative TemplatesAxidian CertiFlowClient.

  6. Enable the Smart card unlocking server policy and configure the following parameters:

  • In the Service URL parameter, specify the link to the credprovapi component hosted on the Axidian CertiFlow server: https://<Server FQDN>/certiflow/credprovapi.
  • In the Verify server certificate parameter, set the value to Yes if server certificate authentication is required. Set it to No (default) if no authentication is required.
  1. Link the edited GPO to the Organizational Unit (OU) or security group that contains the workstations of the Axidian CertiFlow users.

  2. Select Apply.

  3. Force a policy update on the target workstations or wait for the next refresh cycle.

Optional settings of the smart card unlocking service
PolicyDescription
Set explanations for offline unlockingThis policy applies to user workstations.
If the policy is disabled or not defined, the explanation text for offline card unlock is not displayed in the Credential Provider.
This text could provide the contact phone number of the Axidian CertiFlow administrator.
Credential Providers: Disable smart card standard provider wrappingThis policy applies to user workstations.
If the policy is disabled or not defined, the user can unlock the smart card using the standard Windows OS smart card logon interface.
If the policy is enabled, a separate smart card unlock option appears on the OS logon screen. This setting is useful when third-party software is installed on the workstation that prevents card unlock using the standard Credential Provider.
Credential Providers: Hide the "Disable the smart card" optionThis policy applies to user workstations.
If the policy is disabled or not defined, the user can disable the smart card from the Windows OS logon interface.
If the policy is enabled, the option to disable the smart card is hidden on the OS logon screen.