Using Smart Card Authentication with SBM Composer

In addition to browser users, you can enable Smart Card authentication in SBM Composer. This enables designers to log in to the repository using a Smart Card instead of an SBM user name and password.

Configuring SBM Composer

You configure Smart Card authentication for SBM Composer users on a machine-by-machine basis.

To enable Smart Card authentication in SBM Composer:

  1. Open SBM Composer on a client machine, click File, select Composer Options, and then select Repository | Connection. Alternatively, navigate to the directory that contains the SBM Composer executable, and launch SBM Composer using the following command:
    Serena.Studio.Shell.Application /AdvancedSecuritySetup
    The Advanced Security Setup for SBM Composer dialog box appears. The Client Certificate Administration tab lists all self-signed certificates that currently reside in the user's personal certificate store that contain both a private and public key.
  2. Click the Smart Card Authentication tab.
  3. Select the Enable smart card authentication check box.
  4. Optionally, if you want to make the Smart Card certificate available for use in client certificate authentication from SBM Composer, select the Make available as client certificate check box. This enables you to use the Smart Card certificate on the Client Certificate Administration tab. Follow the steps in Client Certificate Authentication with SBM Composer to use this certificate for client certificate authentication.
    Note: This does not require you to use the Smart Card certificate for client certificate authentication. You can still use separate certificates for client certificate authentication and Smart Card authentication from SBM Composer. However, if you would like to use the Smart Card certificate for client certificate authentication, this option enables you to do so.
  5. Click Done to finish. The SBM Composer user can now select the Use smart card check box and select a Smart Card certificate on the Repository tab in the SBM Composer Options dialog box.

Logging in with Smart Card Authentication

After you have configured each client machine that requires Smart Card authentication, SBM Composer users will perform the following steps to log in and access the repository.

Prerequisites:

Smart Card authentication must be configured in SBM. Review the configuration steps in Custom Authentication Settings before designers attempt to log in with Smart Card authentication.

To log in with Smart Card authentication from SBM Composer:

  1. Insert your Smart Card into the reader that is connected to your machine.
  2. Launch SBM Composer, and then open the Repository tab in the SBM Composer Options dialog box.
  3. Select the Work online option.
  4. Enter the Machine name and Port number of the SBM Application Repository server.
  5. Select the Use smart card check box. The User name and password fields are replaced by the Smart card certificate field.
  6. Click the Select button. The Windows Security dialog box appears and lists the available certificates.
  7. Select the certificate that is associated with your Smart Card, and then click OK. The certificate appears in the Smart card certificate field.
  8. Click Test connection to verify that you can connect to the repository. The ActivClient middleware is invoked and prompts you to enter your PIN.
  9. Enter the PIN that is assigned to your Smart Card, and then click OK.
  10. Click OK to close the SBM Composer Options dialog box. You are now connected to the repository.
The certificate that you used will remain selected in the Smart card certificate field, which means you should only need to provide the PIN to connect to the repository again.