Administrator Guide

Table Of Contents
The following scenarios are allowed without need of using INI parameters:
Upgrade from 8.3.x firmware to 8.4 firmware.
Upgrade or Downgrade between 8.3.x and/or earlier firmware.
Upgrade or Downgrade between 8.4 and later firmware.
Transport Layer Security
Transport Layer Security (TLS) is a protocol that provides communication security between the client and server applications.
Upgrade to Transport Layer Security (TLS) In the ThinOS 8.2 release, the TLS is upgraded from version 1.0 to version 1.2.
By default, the ThinOS client uses TLS 1.2 to secure any communication protocols, connections, or applications upon SSL/ TLS
in general and falls back to the previous SSL/ TLS version when negotiating with the server.
Smart cards and smart card readers
A smart card is a security token that has embedded integrated circuits. Smart cards allow you to store and transact data.
A smart card reader is an input device that reads data from a smart card.
Gemalto smart card IDPrime MD840Gemalto smart card IDPrime MD830 and MD840 are supported. IDGo 800 version
1.2.1 - 01 for the Windows middleware is required for supporting Gemalto smart card IDPrime MD840.
The Secure Messaging feature is supported to enable the usage of latest MD830 Rev B cards.
Known issue for Prime MD 840 smart card: If first container is used, then Xen broker logon fails.
OMNIKEY smart card readersThe following OMNIKEY smart card readers are supported:
Omnikey 5427 CK (0x5427, 0x076b) reader supports iclass15693, 14443a, 125k card
Omnikey 5422
Omnikey 5326 DFR (0x5326, 0x076b) reader supports iclass15693 card
Omnikey 5025 CL (0x502a, 0x076b) reader supports 125k card
Ominkey 5325 CL, 5125 (0x5125, 0x076b) reader supports 125k card
Omnikey 5321 V2 CLi (0x532a, 0x076b) reader supports 13.56 MHz card
Omnikey 5321 V2 (076b, 5321) reader supports 13.56 MHZ card
Omnikey 5021 CL (0x5340, 0x076b) reader supports 13.56 MHZ card
Omnikey 5321 V2 Cl Sam (0x5341, 0x076b) reader supports 13.56 MHz card
Omnikey 5421 (0x5421, 0x076b), reader supports 13.56 MHz card
Omnikey 5321 CR (0x5320, 0x076b)
Omnikey 5022 CL
On-board smart card readerOn-board smart card reader works with regular smart cards. The functionality is similar to
other external USB smart card readers and on-board smart card readers such as Dell KB-813.
TicTok smart cardsThinOS supports TicTok smart cards.
ThinOS supports Cryptovision smart card driver cv_act_scinterface_7.1.5 from this release.
For information about the complete list of the tested smart cards and smart card readers, see the latest Release Notes.
Rutoken smart card reader
Rutoken is a USB smart card that is used for two-factor authentication. You can generate and store encryption keys for
electronic signatures, use it to encrypt keys, and perform electronic signature. You can also use this device to encrypt store
digital certificates and other data.
ThinOS 8.6 MR3 supports Rutoken 2151 and Rutoken ECP 2.0 (2100).
214
Security