Configuring a Terminal Viewers Session for use with Smart Cards and Express Logon

A separate session must be configured for each user who will use a smart card or Express Logon, alone or in combination. There are several ways to accomplish this:

To use Express Logon, the user must have a separate TN3270 session for each host application he or she will use. The host application ID is referenced in the start-up macro that you'll create in the next step.

To configure a standalone TN3270 session for use with smart cards and Express Logon
  1. From the Start menu or shortcut, choose Attachmate EXTRA! Terminal Viewers.

  2. From the Create/Open Session screen, select Create.

  3. From the Configure New Session screen, specify the following, and then click Next:

    For this option
    Do this
    Session Name Type a name for this session.
    Description Type a description of this session.
    Type of session Select Display.
    Host type Select IBM Mainframe.
    Host Address Type the address or alias for the host to which this session will connect.
  4. From the Configure New Session - Advanced Settings screen, specify the following:
    For this option
    Do this
    SSL Enabled Select Security.
    Client Authentication Select Provide Client Identity, and then choose Select.
    If you are using
    Do this
    Express Logon without smart cards
    1. Under System Certificate Store, select Retrieve Certification from "My" Store.

    2. Specify a location from which to retrieve an authentication certificate.
    Smart cards, with or without Express Logon
    1. Under Smart Card, select Retrieve Certificate from Smart Card.

    2. Select from the available Cryptographic Service Providers and Certificate Labels.
      Note Some smart card readers are slower than others, so the lists of Cryptographic Service Providers and Certificate Labels may take a few moments to load.
    Port Type a port number.
    Resource Name Type your resource name.

    This allows you to connect to a particular LU on the host. If no resource name is entered, the server connects to any available LU at that port.

    How Often to Send KeepAlive Command (Sec) Set the number of seconds the client should wait before sending the next command.

    The Telnet IAC NOP (No Operation) command allows timely notification of the loss of a 3270 session. As soon as a connection is established between the server and a client, a communication is sent from the client to the server. The server is a passive participant that responds to the keep-alive commands it receives. If a session is idle, you can control whether to keep it alive by setting the number of seconds between transmissions of the command to the server.

    Support HLLAPI Select for HLLAPI support. To use HLLAPI with a Terminal Viewer, you must first launch a HLLAPI-enabled session, then start your HLLAPI application.
    Rollover Host Addresses Type the host address in the text field and choose the ADD button.

    Host address rollover support allows you to enter multiple IP addresses into a list. At connection time, a session will attempt to connect to each address consecutively until a successful connection is made or the list is exhausted.

  5. Click Finish.

If you want to use smart card access without Express Logon, you're ready to connect; if you want to use Express Logon, you need to go to the next step and create a start-up macro for your session.

To configure a managed Terminal Viewers TN3270 session with local caching
  1. Using MCS, configure a 3270 Terminal session.

    When you finish the configuration, a message box with instructions on assigning users is displayed.

  2. Click OK.

  3. In the MCS right pane, highlight the configuration you just created.

  4. To allow the users of this configuration to set their personal security options, choose Permissions.

  5. Highlight Connection and click Configure.

  6. In the Directory pane, click the users who will be assigned this configuration, and then click Add.

  7. When you are done, click Save, and then click Close.

  8. In the MCS left pane, point to Products and then click Presentation Manager.

  9. Assign users or groups to the configuration, and then click Activate.

    The status of the highlighted configuration changes to Active.

If you want to use smart card access without Express Logon, you're ready to connect; if you want to use Express Logon, you need to go to the next step and create a start-up macro for your session.

Because a managed Terminal Viewers TN3270 session with local caching is saved to users' local machines, each user will need to configure his or her personal security options when running a session for the first time. For more information, see Configuring Personal Security Options.

  Attachmate