<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>“Geneva” Team Blog : provisioning</title><link>http://blogs.msdn.com/card/archive/tags/provisioning/default.aspx</link><description>Tags: provisioning</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Silent Information Card Provisioning</title><link>http://blogs.msdn.com/card/archive/2009/06/15/silent-information-card-provisioning.aspx</link><pubDate>Mon, 15 Jun 2009 20:51:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9754242</guid><dc:creator>CardSpaceBlog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/card/comments/9754242.aspx</comments><wfw:commentRss>http://blogs.msdn.com/card/commentrss.aspx?PostID=9754242</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;One obstacle that administrators looking to deploy information cards in an enterprise will inevitably face is getting information cards to their users.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Nobody wants to have to send an email to their users saying that in order to access a web service, they’ll need to go to an issuance website and download an information card.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Things should just work.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;With that in mind, the “Geneva” Server and CardSpace teams created Silent Card Provisioning, a feature that uses &lt;/FONT&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc725828.aspx" mce_href="http://technet.microsoft.com/en-us/library/cc725828.aspx"&gt;&lt;FONT size=3 face=Calibri&gt;Group Policy&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; to deploy information cards to domain users automatically.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 13pt"&gt;&lt;FONT face=Calibri&gt;Step by Step&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Setting up Silent Card Provisioning is very simple.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;In the “Geneva” Server UI, select your information card and choose “Save Group Policy Template Files.”&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;This will save group policy files called IdentitySelectorBaseGPTemplate and AutoCardProvisioningGPTemplate.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;The .adm versions of these files are needed for Windows Server 2003 domain controllers, while the .admx and .adml are for use in Windows Server 2008.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;For more details and a step-by-step guide to setting up silent card provisioning, see &lt;/FONT&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd807091(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/dd807091(WS.10).aspx"&gt;&lt;FONT size=3 face=Calibri&gt;this link&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="PAGE-BREAK-AFTER: avoid; TEXT-ALIGN: center; MARGIN: 0in 0in 10pt" class=MsoNormal align=center&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-ALIGN: center; MARGIN: 0in 0in 10pt" class=MsoCaption align=center&gt;&lt;SPAN style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;&lt;FONT color=#4f81bd&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-ALIGN: center; MARGIN: 0in 0in 10pt" class=MsoCaption align=center&gt;&lt;SPAN style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;&lt;FONT color=#4f81bd&gt;&lt;FONT face=Calibri&gt;&lt;IMG style="WIDTH: 539px; HEIGHT: 388px" title="Silent Provisioning image" alt="Silent Provisioning image" src="http://blogs.msdn.com/photos/card/images/9754236/original.aspx" width=539 height=388 mce_src="http://blogs.msdn.com/photos/card/images/9754236/original.aspx"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-ALIGN: center; MARGIN: 0in 0in 10pt" class=MsoCaption align=center&gt;&lt;SPAN style="FONT-SIZE: 11pt"&gt;&lt;STRONG&gt;&lt;FONT color=#4f81bd&gt;&lt;FONT face=Calibri&gt;“Geneva” Server creates the necessary group policy templates for you.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Once the group policy is set on the domain controller, domain users with CardSpace “Geneva” will automatically connect to the server, download and install the card.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;This process happens silently and the user doesn’t have to know or worry about it.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;If anything about the card, such as the image or authentication types, is changed on the Server, CardSpace will automatically pick up those changes.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;If the card is disabled on the Server, CardSpace will delete it from client machines.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;This means that once CardSpace is installed, the user doesn’t have to do anything to get the cards they need.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 13pt"&gt;&lt;FONT face=Calibri&gt;Tips and tricks&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;&lt;SPAN&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;This feature integrates well with &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/card/archive/2009/06/09/enterprise-policy-for-zero-click-sign-in-using-information-cards.aspx" mce_href="http://blogs.msdn.com/card/archive/2009/06/09/enterprise-policy-for-zero-click-sign-in-using-information-cards.aspx"&gt;&lt;FONT size=3 face=Calibri&gt;Card Usage Policy&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;. &lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;By setting a card to be silently provisioned and automatically used, administrators can really streamline their user experience.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;&lt;SPAN&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;The group policy template files specify the location of the Geneva Server, the issuer name, and the time interval to check for card updates.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;This interval is set to two days by default but can be made longer or shorter if necessary.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;In addition to updating at this interval, users will have their cards updated each time they log on.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;&lt;SPAN&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;The easiest way to ensure that a client machine gets its group policy and cards updated right away is to log off and log back on.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;For testing, the following commands run from an administrative command prompt will also update a client’s card(s):&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;&lt;SPAN&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;GpUpdate /force&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 1in" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;&lt;SPAN&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;FONT size=3 face=Calibri&gt;"&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;%PROGRAMFILES%\Windows CardSpace\bin\CSHelper.exe" /provision&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Hopefully this feature will streamline your experience with Geneva in the enterprise and we look forward to hearing your feedback.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Oren Melzer&lt;BR&gt;Software Development Engineer&lt;BR&gt;“Geneva” Team&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9754242" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/card/archive/tags/CardSpace/default.aspx">CardSpace</category><category domain="http://blogs.msdn.com/card/archive/tags/managed+card/default.aspx">managed card</category><category domain="http://blogs.msdn.com/card/archive/tags/Geneva/default.aspx">Geneva</category><category domain="http://blogs.msdn.com/card/archive/tags/CardSpace+_2600_quot_3B00_Geneva_2600_quot_3B00_/default.aspx">CardSpace &amp;quot;Geneva&amp;quot;</category><category domain="http://blogs.msdn.com/card/archive/tags/policy/default.aspx">policy</category><category domain="http://blogs.msdn.com/card/archive/tags/provisioning/default.aspx">provisioning</category></item></channel></rss>