
TPM as a Virtual Smart Card | Wave Systems Corp. 2012
ESC 2.9.5 Client Manual
5. TPM as a Virtual Smart Card
If you have a Certificate Authority available, your TPM can give you equivalent functionality to a smart
card using the TPM. Your smart card travels with your computer, and becomes a token to authenticate
to remote services and the local computer. Compared to password authentication, Virtual Smart Card
(VSC) makes it harder for an attacker to use your credentials because your credentials are tied to the
TPM chip on your computer. It can also be configured as a credential used for remote desktop. The TPM
Virtual Smart card is not supported on Windows XP; and requires additional installation files (minidriver
and .vbs script) that ship with the ERAS server.
While TPM Virtual Smart Card is a flexible tool that can be configured for a number of purposes, the
following are supported:
• Microsoft Remote Desktop (Windows Terminal Services may be running)
• Website login (The website must be configured for smart card login)
• Microsoft VPN
• Cisco VPN
• CheckPoint VPN
• Windows desktop and domain logon using Wave Credential Provider
• Windows desktop and domain logon using the Microsoft Credential Provider
Other applications are not supported yet, but may work.
You cannot enroll TPM Virtual Smart Card certificates created on the ERAS-
CCA.
Komentáře k této Příručce