AusweisApp2 Manual Release

Similar documents
BLUEPRINT TEAM REPOSITORY. For Requirements Center & Requirements Center Test Definition

Connect to Wireless, certificate install and setup Citrix Receiver

Guide Installation and User Guide - Windows

Guide Installation and User Guide - Mac

Storage Security Software (Version )

Document Signing Certificate Getting Started Guide

Sync User Guide. Powered by Axient Anchor

GRS Enterprise Synchronization Tool

Sabre Customer Virtual Private Network Launcher (SCVPNLauncher)

Anchor User Guide. Presented by: Last Revised: August 07, 2017

GfK Digital Trends App. Installation Guide & User Manual for Microsoft Internet Explorer users

Apptix Online Backup by Mozy User Guide

End User Manual. December 2014 V1.0

Introduction. Introduction

Perceptive Process Design Personal - Installation Guide

Avira Ultimate Protection Suite. Short guide

DBT-120 Bluetooth USB Adapter

IMPORTANT. Installing your EASE Scan Tool Software

Configuring the WebDAV Folder for Adding Multiple Files to the Content Collection and Editing Them

Deltek Touch Expense for Ajera. Touch 1.0 Technical Installation Guide

Corona SDK Device Build Guide

DSS User Guide. End User Guide. - i -

VISO WEB Server Application. Operating manual

GfK Digital Trends App. Installation Guide & User Manual for Google Chrome users

Remote Support 19.1 Web Rep Console

CityVault Client Manual

Top Producer for Palm Handhelds

CADS Detailing FAQ s ENGINEERING SOFTWARE 004 Network Licence File - Installation Guide. 004 Network Licence File Installation Guide

Cambium Wireless Manager

Horizon Launcher Configuration Guide

Testing and Restoring the Nasuni Filer in a Disaster Recovery Scenario

VMware Horizon Client for Chrome OS User Guide. 04 JAN 2018 VMware Horizon Client for Chrome OS 4.7

Remote Support Web Rep Console

Funasset Limited Foundry House Foundry Road Taunton Somerset TA1 1JJ. Tel: +44 (0) Fax: +44 (0) mailmarkup.com funasset.

Security Task Manager User Guide

Installation and Licensing Guide for the IAR Embedded Workbench

IPEmotion PlugIn CAN Protocols User manual

Installation Manual. Fleet Maintenance Software. Version 6.4

Tenant Administration. vrealize Automation 6.2

Document authored by: Native Instruments GmbH Software version: (02/2013)

AGENT TRAINING USER GUIDE. Instant Chime for Microsoft Lync

Dell Connections License Manager Version 1.1 Installation Guide

Installing and Configuring vcenter Multi-Hypervisor Manager

Guide Installation and User Guide - Linux

Top Producer 7i Remote

Installation Guide Worksoft Analyze

owncloud Android App Manual

KYOCERA Net Viewer User Guide

Wavecrest Certificate SHA-512

Xifin Client Portal User s Guide Version 1.0. January 2018

Relativity Designer Installation Guide

Galileo Desktop SM 2.1. Installation Guide

Avira Premium Security Suite User Manual

Sophos Mobile Control startup guide. Product version: 7

USER GUIDE. CTERA Agent for Windows. June 2016 Version 5.5

Installing Intellicus DotNet Client on Windows. Version: 16.0

Install and upgrade Qlik Sense. Qlik Sense 3.0 Copyright QlikTech International AB. All rights reserved.

Software Manual R Index 1

Schneider Electric License Manager

Secure Single Sign On with FingerTec OFIS

Connected to the FP World

TeamDrive Outlook-Plugin for Windows

INSTALLATION GUIDE. Trimble AllTrak Software

Installation Guide - Windows

Scribe Insight Installation Guide. Version August 10, 2011

Troubleshooting. Participants List Displays Multiple Entries for the Same User

Deployment User Guide

Oracle Cloud. Using the Google Calendar Adapter Release 16.3 E

VMware AirWatch - Workspace ONE, Single Sign-on and VMware Identity Manager

IPEmotion M.A.L.- PlugIn IPETRONIK CAN

Installation Guide. CompanyCRYPT v1.4.5

BNA INCOME TAX PLANNER INSTALLATION GUIDE CD

Aspera Connect Windows XP, 2003, Vista, 2008, 7. Document Version: 1

Connectware Manager Getting Started Guide

MyCardUpdate User Guide Triple E Technologies, LLC

Isograph Software Products

Schneider Electric Floating License Manager

Sage Installation and System Administrator s Guide. March 2019

IBM Workplace TM Collaboration Services

Amazon AppStream 2.0: SOLIDWORKS Deployment Guide

Oracle Cloud Using the Google Calendar Adapter with Oracle Integration

ipass Open Mobile 3.0.x for Android Quick Start Guide

Wireless Bluetooth USB Dongle User s Guide

Equitrac Integrated for Konica Minolta. Setup Guide Equitrac Corporation

Legal Notes. Regarding Trademarks KYOCERA MITA Corporation

HP QuickTest Professional

Professional. User Guide. Professional. User Guide MN-PCMPRO-EN-06 (REV. 07/2010)

Icare CLINIC Icare EXPORT Icare PATIENT app INSTRUCTION MANUAL FOR HEALTHCARE PROFESSIONALS ENGLISH

Quick Start Guide Red Box Call Recording v5 18/08/2016

SICAT SUITE VERSION 1.1. Instructions for use English

Centrify Infrastructure Services

Sophos SafeGuard File Encryption for Mac Quick startup guide. Product version: 7

Visual Nexus Version 4.0

Creative USB Adapter CB2431 with Bluetooth Wireless Technology. User s Guide

Kaspersky Security Center 10 Web Console. User Guide

Avalanche Remote Control User Guide. Version 4.1

NetIQ SecureLogin 8.5 enhances the product capability and resolves several previous issues.

CLIQ Web Manager. User Manual. The global leader in door opening solutions V 6.1

LifeSize Control Installation Guide

Abila MIP. Human Resource Management Installation Guide

Transcription:

AusweisApp2 Manual Release 1.14.0 Governikus GmbH & Co. KG 20.12.2017 Contents 1 Installation of AusweisApp2 on a Windows operating system 1 1.1 Dialog page Welcome - Step 1 of 5............................. 1 1.2 Accept license agreement - Step 2 of 5........................... 1 1.3 Installation options - Step 3 of 5.............................. 2 1.4 Start installation - Step 4 of 5................................ 3 1.5 Finish - Step 5 of 5..................................... 6 2 Start AusweisApp2 7 3 Setup assistant 11 4 > Identify using the online identification 12 4.1 Process of online identification............................... 12 5 > Provider of online identification 13 5.1 Open website of service provider with the Internet browser................ 13 5.2 Search table of service providers.............................. 14 6 > History dialog page with sample content 15 6.1 Show certificate of service provider............................ 15 7 > Change Settings 16 7.1 Software updates...................................... 17 7.2 History........................................... 17 7.3 Start AusweisApp2 automatically............................. 17 7.4 Close window of AusweisApp2 automatically....................... 17 7.5 On-screen keyboard..................................... 18 8 > PIN management 18 8.1 Requirements for changing your PIN............................ 19 9 > Install Card Readers 20 9.1 Configuration of a smartphone as card reader....................... 20 9.2 Configuration of a card reader............................... 23 9.3 Install driver for card reader................................ 25

10 > Developer Mode 26 10.1 Activate Developer Mode.................................. 26 10.2 Excluded Safety Tests.................................... 26 10.3 Deactivate Developer Mode................................. 27 11 Uninstall AusweisApp2 27 12 Information resources and support 31 13 Legal information and other advice 32

1 Installation of AusweisApp2 on a Windows operating system The installation of AusweisApp2 is divided into several steps and can be cancelled at any time using the button Abbrechen. 1.1 Dialog page Welcome - Step 1 of 5 The installation program starts with the dialog page Welcome. Fig. 1: Dialog page Welcome 1.2 Accept license agreement - Step 2 of 5 Um mit der Installation fortzufahren, müssen Sie den Lizenzbedingungen zustimmen. Klicken Sie hierfür in das Kästchen links neben dem Text Ich stimme den Bedingungen der Lizenzvereinbarungen zu. und dann auf Weiter. 1

Fig. 2: Accept license agreement Note: The button Weiter is only activated once you have checked the box for license agreements. The button Drucken allows you to print the text of the license agreement. 1.3 Installation options - Step 3 of 5 Here you can define the directory in which AusweisApp2 will be installed on your computer and adapt the Windows Firewall settings. If you want to keep the default settings click Weiter. 2

Fig. 3: Choose installation options and directory Attention: Register AusweisApp2 in your system (Firewall and browser settings): We recommend to keep this box checked, otherwise service providers may not be able to communicate with AusweisApp2. Firewall: A rule is added to Windows Firewall allowing service providers to address the AusweisApp2. If you deselect this option, you must create a corresponding rule yourself in the inbound Windows Firewall rules. Browser settings: The Internet Explorer allows for Trusted sites. If you register the AusweisApp2 in the system, it is added to these trusted sites. Find out how to add the AusweisApp2 manually here. 1.4 Start installation - Step 4 of 5 You can start the installation process by clicking on Installieren. 3

Fig. 4: Start installation Note: Installing AusweisApp2 requires administrator rights. Your operating system will prompt you to grant AusweisApp2 the right to make changes to your system. Click on Ja to continue the installing process. 4

Fig. 5: User account control The following dialog shows the progress of the installation. 5

Fig. 6: Progress status of installation 1.5 Finish - Step 5 of 5 Installation was successful. Close the installation process by clicking Fertig stellen. 6

Fig. 7: Finish installation process Note: Option Start AusweisApp2 : This option is selected by default in the last step of the installation. AusweisApp2 is started immediately after completion of the installation. Related topics: Start AusweisApp2. Uninstall AusweisApp2 (page 27) 2 Start AusweisApp2 Click on the Windows icon at the bottom on the left. 7

Fig. 8: Start AusweisApp2 using the Windows start menu Navigate to folder AusweisApp2 in the WIndows start menu. Click to open folder and select Ausweis- App2. 8

Fig. 9: Start AusweisApp2 using the Windows start menu Once you have started AusweisApp2, its icon is displayed in the Windows system tray as shown in the next figure. Hint: The* Windows system tray* is at the bottom on the right of your monitor. There you will also find the clock and information about your system as well as program icons to access programs currently not displayed separately. Fig. 10: Start AusweisApp2 using the Windows start menu 9

Once AusweisApp2 is started, the following screen appears. Fig. 11: Start screen of AusweisApp2 You can choose from the following menu items. Identify Provider History Settings Zudem kann die Sprache durch die zwei Icons oben Links umgestellt werden, dies ist in allen Bereichen der AusweisApp2 möglich. Es werden nur die Sprachen Deutsch und Englisch unterstützt. Beim ersten Start erkennt die AusweisApp2 die Systemsprache automatisch, anhand dies wird bei deutschen Betriebssystemen die AusweisApp2 auf Deutsch gestellt, bei allen anderen Sprachen wird Englisch gewählt. Nachdem der Nutzer das erste Mal die Sprache selbst gesetzt hat, wird die automatische Umstellung deaktiviert. Hint: The AusweisApp2 icon is missing. What can I do? 10

If the AusweisApp2 icon is not displayed in the Windows system tray, use startup-icon-missing Related topics: startup-icon-missing startup-show-aa2 Close AusweisApp2 3 Setup assistant The setup assistant is displayed during the initial installation process and assists with both the configuration of the software and the installation of card readers. The wizard-howto-open is available via Help in the menue bar of AusweisApp2 at all times. Fig. 12: Welcome page of the setup assistant Note: In case you use the Firefox extension NoScript an additional step wizard-noscript is displayed. Steps in the setup assistant: wizard-step1 wizard-cardreader wizard-last-step 11

wizard-noscript 4 > Identify using the online identification The feature Identify offers two functions 1. The feature Identify is used when a service provider requires you to identify yourself using the online identification. Details can be found in section identify-service. 2. You can select the feature See my personal data now. The following figure shows AusweisApp2 after Identify was selected. Fig. 13: Start dialog of the Identify feature 4.1 Process of online identification Usually the online identification follows this pattern: 1. The holder of the ID card wants to use a web service that requires an online identification. 2. AusweisApp2 verifies the security requirements for the online identification and displays the authorization certificate of the service provider as well as the requested set of data. 3. By entering the PIN, the card holder releases the transmission of data. 12

Attention: The online identification can be cancelled at the beginning with the following error messages: identify-eid-deactivated identify-pin-disabled Related topics: identify-service identify-about-me 5 > Provider of online identification The dialog Provider lists names and addresses of service providers where the online identification function can be used. 5.1 Open website of service provider with the Internet browser Click on the blue address in the right column to open the respective website in your Internet browser. Fig. 14: Dialog page provider 13

5.2 Search table of service providers You can search the table for entries as follows: 1. Click right to the text Search. 2. Enter your search term on your computer s keyboard. Note: The search is not case-sensitive. It is also possible to enter parts of a word, such as gov for Governikus. Fig. 15: Use the search function to filter the provider list Examples: Entering https detects all rows in which the address starts with this protocol. Entering stelle detects all names and addresses featuring these characters, e.f. Meldestelle or Zulassungsstelle. Related topics: identify-service > History dialog page with sample content (page 15) 14

6 > History dialog page with sample content If you have selected the option Create history, the History feature creates a list of service providers on whose web pages you have used the online identification function. Fig. 16: List of your online identifications in the dialog History Hint: What happens, if the option Create history is disabled? In this case, no information regarding the performed identification processes is stored. 6.1 Show certificate of service provider When you click on the service provider, the content of the authorization certificate is displayed on a separat dialog page. 15

Fig. 17: Authorization certificate of the service provider Note: You have to close the window with the authorization certificate before you can resume using AusweisApp2. Related topics: history-activate history-browse history-export history-clean 7 > Change Settings Use Settings to configure AusweisApp2, change your PIN, unblock your ID card and view the connected card readers. 16

Fig. 18: Dialog Settings of AusweisApp2 7.1 Software updates Check at startup: Choose this option to check AusweisApp2 automatically at every startup for software updates. In case an update is available, a notification is displayed in dialog window. Check for updates: This option allows you to check for updates manually. 7.2 History Save: This option is deselected by default. When you select this option, a list of service providers where you used the online identification function is stored in History. When you deselect this option, no more entries are added to the history. The existing history remains. You can activate or deactivate the storing of the history. 7.3 Start AusweisApp2 automatically At startup: If selected, AusweisApp2 is started automatically at your computer s startup. If not, you have to start AusweisApp2 prior to the identification process manually. 7.4 Close window of AusweisApp2 automatically After successful identification: If selected, the user interface of AusweisApp2 is closed automatically after the use of the online identification. 17

Hint: This closes the user interface. You can still Call AusweisApp2 using the icon in the Windows system tray. 7.5 On-screen keyboard Use: If selected, the icon for the on-screen keyboard is displayed in the PIN management at the right-hand side of the PIN entry field. Fig. 19: PIN entry dialog with icon for on-screen keyboard Note: Click on the icon next to the entry field to enter your PIN using the on-screen keyboard. A new dialog page opens showing the on-screen keyboard. Reasons as to why the use of the on-screen keyboard is beneficial for your security and more details on how to handle it can be found here: display-keyboard Related topics: > PIN management (page 18) display-keyboard 8 > PIN management You can change or unblock the PIN of your ID card in the PIN management. 18

Fig. 20: Tab PIN management with detected ID card 8.1 Requirements for changing your PIN In order to change your PIN, you need an installed, certified card reader and an ID card with enabled eid function. Hint: Do only certified card readers work? It is possible that other, non-certified card readers also work. However, those card readers are not tested. Information on card readers can be found on Personalausweisportal 1. Please note that changing the PIN through a remote device (smartphone as card reader) is not supported. However, you can change the PIN by using the AusweisApp2 directly on your smartphone. Note: I cannot change the PIN, what can I do? In case you do not meet the requirements, you receive feedback regarding your next steps: settings-pin-management-no-reader settings-pin-management-no-card settings-pin-management-card-disabled settings-pin-management-eid-deactivated 1 http://www.personalausweisportal.de/de/buergerinnen-und-buerger/online-ausweisen/das-brauchen-sie/ Kartenlesegeraete/Kartenlesegeraete.html 19

If you meet all requirements, you can start the process settings-pin-change. Related topics: settings-pin-change settings-pin-management-card-disabled pin-letter 9 > Install Card Readers Using the online identification function of your ID card requires a card reader. You can either use a separately available card reader or connect a suitable smartphone to your computer. The Card Readers page assists you with the installation. 9.1 Configuration of a smartphone as card reader In the upper part of the tab Card Readers you can configure a smartphone as card reader. Fig. 21: Card Reader Tab In order to make a remote device (smartphone) available, you have to make sure that it is in the same network and that the remote service function is enabled. 20

Hint: If available, the function AP / Client Isolation of your wireless network must be disabled, so that different devices can communicate with each other. Please note that in many public wireless networks the AP isolation function is enabled and therefore you cannot use your smartphone as card reader in those networks. As soon as a remote device with enabled remote service function is found, it is listed here. Fig. 22: Not-paired remote device A remote device must be paired before it can be used as a card reader. You can find detailed information on how to pair a remote device in Section settings-pairing-with-remote-reader. A paired and available remote device is displayed as follows: 21

Fig. 23: Paired and available remote device You can now use this device as a card reader. If a paired remote device is unavailable, it will be marked as Paired and not available. 22

Fig. 24: Paired, unavailable remote device You can remove a paired remote device by clicking on the Forget button. 9.2 Configuration of a card reader In the lower part of the tab Card Readers you can configure a card reader. As soon as at least one card reader is connected, this device will be listed. The column state reveals whether the driver for this particular card reader is installed correctly. In case the driver is installed correctly, the state is given as Connected w/ driver ; additionally the availability of the card reader is signalled by a green hook next to the card reader s picture. 23

Fig. 25: Card reader with correctly installed driver In case that a card reader is connected yet no driver installed, the state is given as Connected w/o driver. In addition, the URL to the manufacturer s website is displayed to download the driver. 24

Fig. 26: Card reader without installed driver Hint: It is possible that your card reader is ready-to-use although it is not listed here. 9.3 Install driver for card reader 1. Choose your card reader from the list. 2. Click on the link below the card reader s picture on the right. This opens the manufacturer s website in your browser. 3. Download and install the driver for your card reader. 4. Upon successful installation, the state for the connected card reader changes to Connected w/ driver. Hint: After connecting the card reader, your PC may indicate that the device is ready to be used. However, most card readers largely work properly when the appropriate driver software has been downloaded and installed directly from the manufacturer. Attention: We recommend to restart your computer once the driver software has been installed to make sure that the card reader functions correctly. Related topics: 25

> Identify using the online identification (page 12) > PIN management (page 18) 10 > Developer Mode The developer mode is aimed at integrators / developers for new service applications. For this reason, the developer mode works only in the test PKI. By activating the developer mode, some safety tests are deactivated. This means that the authentication process continues although the AusweisApp2 would usually abort the process with an error message when used in normal operation mode. Information on the disregarded error in the developer mode is displayed in the attached window below the AusweisApp2. 10.1 Activate Developer Mode In order to activate the developer mode, choose Help in the menu bar and click on About Ausweis- App2. Tick the box next to Developer mode and press OK. 10.2 Excluded Safety Tests If the developer mode is activated some safety tests are deactivated. A message is added to the developer mode protocol if one of the disabled safety tests would fail during normal operation. The following safety tests are disabled in developer mode: The used TLS keys and ephemeral TLS keys have the necessary minimum length. The URL of the TLS certificate description of the eid server and the TcToken URL must fulfill the same-origin policy. 26

The used TLS certificates must be entwined with the authorization certificate. The RefreshAddress URL and possible redirect URLs must conform to the HTTPS schema. 10.3 Deactivate Developer Mode You can disable the developer mode by following a similar procedure as for the activation. Open the dialog About AusweisApp2. Untick the option Developer mode and press OK. Alternatively, click on the button labelled Disable in the upper right-hand corner of the developer mode protocol. 11 Uninstall AusweisApp2 Proceed as follows to uninstall AusweisApp2 from your system: Right-click with your mouse on the Windows start symbol at the bottom on the left of your monitor. 27

Select System control. 28

Choose entry Uninstall program in the new dialog window. Double-click on list entry AusweisApp2. 29

A dialog appears, prompting you to confirm deleting AusweisApp2. Click on Yes. Note: Uninstalling AusweisApp2 requires administrator rights. Your operating system will prompt you to grant AusweisApp2 the right to make changes to your system. Click on Yes to continue the uninstalling process. 30

Fig. 27: User account control AusweisApp2 will be uninstalled from your computer. Note: Delete AusweisApp2 residue-free The uninstalling process deletes all files and the desktop icon of AusweisApp2 from your computer. Entries to the registry are not deleted. These are progam settings and - if saved - the history of your online identifications. In case you want to delete those as well, follow these steps. Related topics: Installation of AusweisApp2 on a Windows operating system (page 1) uninstall-complete 12 Information resources and support General information about the national ID card and the electronic residence permit: 31

National ID card: The Bundesministerium des Innern (Federal Ministry of the Interior) provides an information portal for the national ID card that is available here: 2 Electronic residence permit: The Bundesamt für Migration und Flüchtlinge (Federal Office for Migration and Refugees) provides information about the electronic residence permit here: 3 Information about AusweisApp2 and support Questions and suggestions: Do you need support in using AusweisApp2? If you have any questions or problems, please read the section Oft gestellte Fragen (Frequently Asked Questions FAQ) that is available here: 4 AusweisApp2: Portal of AusweisApp2: 5 You can also contact the Support team directly: Telephone: +49 1805 348 743 (standard network charges 14 ct per minute apply, other network charges may vary) Fax: +49 421 204 95-11 E-Mail: support@ausweisapp.de 13 Legal information and other advice Although this product documentation was written to the best of our knowledge and with reasonable care, errors and inaccuracies cannot be totally excluded. Legal or other liability for inaccurate information and their consequences cannot be assumed. The information given in this product documentation reflects the current state of development and can be changed without further notice. Future editions can contain additional information. Technical and typographic errors are corrected in subsequent editions. This user guide as well as all materials protected by copyright that are sold along with this product are copyright protected. All rights are reserved by Governikus GmbH & Co. KG (Governikus KG). It is prohibited to copy or otherwise reproduce materials protected by copyright without previous agreement. For legitimate users of this product this right is granted within the contractual terms. All copies of this user manual must bear the same notice of copyrights, as does the original, regardless whether the complete text or only parts of it are used. Governikus is a registered trademark of the Governikus GmbH & Co. KG. Other products and technologies that are listed within this product information are potentially trademarks of further owners and must be obeyed respectively. 2 http://www.personalausweisportal.de/ 3 http://www.bamf.de/de/willkommen/aufenthalt/eaufenthaltstitel/e-aufenthaltstitel-node.html 4 https://www.ausweisapp.bund.de/service/haeufig-gestellte-fragen/ 5 https://www.ausweisapp.bund.de/ 32