This method is necessary for those who want to minimize the amount of software installed on the server.
Installation of the minidriver
The minidriver is a software component between the built-in encryption provider Microsoft Smart Card Base Cryptographic Service Provider and the Rutoken, it is designed to work with smart cards (and tokens) in the system. In most operating systems* the minidriver is installed automatically from Windows Update. To check whether the "minidriver" is installed on your computer, you can connect the Rutoken to it and open the "Device Manager". If the minidriver could not be installed **, we suggest using the instructions below.
*On Windows XP, the minidriver is installed only manually.
**There are problems getting updates or the OS is damaged.
To install the minidriver:
- Follow the link:
http://www.catalog.update.microsoft.com/Search.aspx?q=Rutoken - In the table, find the line that has "Windows 10 and later drivers,Windows 10 S and Later Servicing Drivers,Windows Server Drivers" written in the Products column.
- In this line, click on the Download button. The installation window will open.
- Click on the link to the archive with the minidriver.
- Save this archive on your computer.
- Close the installation window.
- Find the saved archive and extract its contents to the current folder.
- Right-click on the name of the rtMiniDrv.inf file and select Install.
- In the window that opens, click on the Yes button to confirm the changes. As a result, the minidriver will be installed.
- Next, make sure that it is really installed.
To check it out:
- Connect the Rutoken EDS device to the computer.
- Open Device Manager.
- Double-click on the Smart cards line. As a result, the line Aktiv Co. Rutoken Minidriver should be displayed.
- If this line is displayed, the minidriver is installed.
- If not, repeat the installation process.
Remote access to VPN networks
For the configuration you need a computer with the Windows 10 operating system and Rutoken drivers installed.
When establishing a remote connection to a remote access server, the client is authenticated by the server, and, vice versa, the client verifies that the connection is made to the needed server. However, it is possible to disable the verification of the server by the client, which will negatively affect the security of the connection, so it is recommended to validate the server.
To create and configure the remote connection to a remote access server:
- Open the Control panel.
- Click on the name Network and Internet.
- Click on the name Network and Sharing Management Center.
- Click on the name Creating and configuring new connection or network.
- Click on the name Connection to the workplace. Click on the Next button.
- If the system already has configured connections, then set the switch to No, create a new connection. Click on the Next button.
- Click on the line Use my Internet connection (VPN).
- Enter the address of the server (in the field Internet Address) to which the remote connection will be made.
- Enter the name of the remote connection you are creating (in the field Name of the destination object).
- Check the box Use the smart card and click on the Create button. The remote connection has been created.
To connect to the server:
- On the Desktop, click on the Network icon in the lower right corner.
- Click on the link Network parameters.
- On the left side of the window Settings select VPN.
- Click on the name of the VPN connection and click Connect.
- Wait for the operating system to access the Rutoken device.
- Enter the PIN code of the Rutoken Device User. Click on the OK button.
- Wait until the correctness of the secret information stored on the Rutoken device is verified.
- When you connect for the first, you will receive a request to trust the server. To continue connecting, click on Connect. As a result, the connection will be established.
Connecting to a secure Website
For the configuration you need a computer with the Windows 10 operating system and Rutoken drivers installed.
The settings will be carried out with the rights of the Admin account.
The Admin user was previously issued a certificate of the User with a smart card type (any certificate that allows client authentication will do).
Description of configuring browser settings for authentication using a digital certificate stored on the Rutoken device.
To connect to a secure website:
- Open the Internet Explorer browser.
- Click on the Service icon.
- Select the Browser properties item.
- In the window Browser Properties go to the tab Content.
- Click on the [Certificates] button.
- In the window Certificates check that the required certificate is registered in the local storage (in our example, this is a certificate of the User with a smart card type issued to the Admin user).
- Click on the certificates line and click on [View].
- Check the certificate details and click on the [OK] button.
- In the window Certificates click on the [Close] button.
- Connect the Rutoken device to the computer (the device must have an Admin user certificate).
- Enter the resource address. This example shows the possibility of issuing a certificate via a web form through a secure communication channel with hardware authentication.
- In the window for entering the User's PIN code, enter the PIN code and click on the [OK] button.
- Wait for the connection setup process to finish. As a result, the connection will be established.