EMBASSY Security Center - NEC Professional Edition  						(Build   02.10.01.392)
Copyright (c) 2003-2013, Wave Systems Corp. All rights reserved.	Readme Version [2100002]

======================================================================================================

EMBASSY Security Center - NEC Professional Edition allows one to enable and use the security features of the Trusted Platform 
Module (TPM). ESC provides the Wave CSP, which enables advanced authentication features of the TPM.

======================================================================================================
	

	Hardware:
	-	PC with a Pentium or newer microprocessor, 800 MHz or greater
	-	Trusted Platform Module (TPM) v 1.2 
	-	(OPTIONAL) Biometric sensor for Fingerprint support
	
	Operating Systems:
	-	Microsoft Windows 8, 32/64 bit
	-	Microsoft Windows 7, 32/64 bit Professional, Enterprise, or Ultimate

	*NOTE: Either Microsoft .Net Framework 3.5 SP1 or 4.0 are required.
	*Visual C++ 2008 Redistributable is required, and is installed automatically by the ESC 
	installer

	
	Other Requirements:
	-	Microsoft(R) Internet Explorer version 8 (or above)

	Recommendations For TPM Management
	--	The WaveTSS is recommended for TPM management, and will install if no TSS is
		present. 
	-	Up-to-date TPM Firmware is required. When in doubt, it is best to install the 
		latest TPM firmware provided by the manufacturer.
 

	Optional:
	Biometric sensor for Fingerprint support. Supported sensors include:
			AuthenTec AES3500 (TruePrint and 3500 ClipDriveBio)
			AuthenTec AES3400 (Targus and biometric mouse)
			AuthenTec AES4000 (Targus)
			AuthenTec AES2501 Swipe Sensor
			AuthenTec AES2550
			AuthenTec AES2810
			AuthenTec AES1610
			AuthenTec AES1660



Installation Procedure:

	User must have administrative privileges to install.
	1.	Run the "WaveSetup.exe" file in the root directory of this package.
	2.	The installation wizard will guide you through the installation
		and setup of the EMBASSY Security Center.
	3.	You will be prompted to restart the computer following the installation.
	Refer to the user manual for more details and additional installation options.

SCCM Installation Requirement:
	SCCM installations must run the command line option: WaveSetup.exe -silent -install	

Command Line Installation Options:

	Silent Installation
	User Account Control (UAC) must be disabled, or the installer must be run as 
	administrator. Run the following command from the command prompt:
	WaveSetup.exe  -silent -install

	Silent uninstallation
	WaveSetup.exe  -silent -uninstall

	Show(Hide) icons on desktop
	WaveSetup.exe  -icon(-nicon)

	Hide from Add/Remove Programs (useful to help prevent users from uninstalling it)
	WaveSetup.exe -hide

	-headless is an option for installation that will not create any desktop or start menu 
	short cuts.  This may be used for client endpoint machines that will be managed 
	remotely with EMBASSY Remote Administration Server (ERAS).	

	You must restart the computer to complete the installation.

Uninstallation of ESC and TPM.msc
	
	Following uninstallation of ESC, selecting "Prepare the TPM..." in Microsoft TPM.msc will
	display that the TPM needs to be taken out of Legacy Mode before it can continue. To remove
	Legacy Mode, follow these steps:

	1) Run gpedit.msc. One way to run this is:
		a) Press the'Windows Key' & 'r' simultaneously
		b) Type 'gpedit.msc' in the 'Open:' field
		b) Select "OK"
	2) Navigate to the policies found at:
	'Computer Configuration\Administrative Templates\System\Trusted Platform Module Services'
	3) Change 'Configure the level of TPM owner authorization information available to the 
	operating system" from "Enabled" to "Not Configured".

	

======================================================================================================


Limitations and Known Issues:

	General
	1.	If the TPM is powered off, ESC will not open.
	2.	After installing ESC on Windows 8, it is REQUIRED that you restart the 
		computer before running ESC. Note that a power down is not sufficient.
	3.	In the Japanese version of Windows 7, the font in the ESC user interface may be 
		too large. Installing Service Pack 1 for Windows 7 corrects this issue.

	Upgrades
	1.	Upgrades are not supported with this package.


	EMBASSY Security Center
	1.	Some personal Firewall products may block access to the network/internet during 
		installation and execution of applications.  If you have a firewall configured to 
		block access then you must add the following list of applications to the list of 
		applications that are authorized access.  Failure to grant access to the following 
		applications may prevent ESC from installing or executing properly.  
		- Microsoft Windows Installer - %WINDIR%\system32\MSIExec.exe
		- ESC - %PROGRAMFILES%\Wave Systems Corp\EMBASSY Security Center\
			EmbassySecurityCenter.exe

	Archive and Restore
	1.	Attempting to Archive immediately after taking TPM ownership will result
		in a "The Archive was not created successfully" message.  This occurs because 
		there are not yet TPM keys available to archive.  Please click on 'Ok' to clear 
		the error message.  This message will occur in every case where there are no TPM 
		secured keys in existence.  After TPM keys have been created, future archive 
		operations will succeed.


	Document Manager
	1.	The Windows Explorer view launched when opening a vault in the Document Manager 
		tab displays behind the ESC application window.


	Scrambls	
	1.	The scrambls tab will not display correctly unless the minimum version of 
		Microsoft(R) Internet Explorer (version 8) is installed. 


======================================================================================================

Technical Support:

	For technical support questions, please contact your PC manufacturer.
