diff --git a/README.md b/README.md index dd2c98c..8839f37 100644 --- a/README.md +++ b/README.md @@ -24,14 +24,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do 1. Update source files in domain/ -2. Build PDF document +2. Build the PDF document from the repository root ```bash # Export English version -pandoc domain/index.md -L kramdown-toc.lua -o eID_Auth_Guide_EN.pdf +pandoc domain/index.md --resource-path=domain -L kramdown-toc.lua -o eID_Auth_Guide_EN.pdf # Export Estonian version -pandoc domain/index.et.md -L kramdown-toc.lua -o eID_Auth_Guide_ET.pdf +pandoc domain/index.et.md --resource-path=domain -L kramdown-toc.lua -o eID_Auth_Guide_ET.pdf ``` ## Editing and building "Apache2 SSL Configuration" @@ -40,14 +40,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do 1. Update source files in apache/ -2. Build PDF document +2. Build the PDF document from the repository root ```bash # Export English version -pandoc apache/index.md -L kramdown-toc.lua -o apache_SSL_EN.pdf +pandoc apache/index.md --resource-path=apache -L kramdown-toc.lua -o apache_SSL_EN.pdf # Export Estonian version -pandoc apache/index.et.md -L kramdown-toc.lua -o apache_SSL_ET.pdf +pandoc apache/index.et.md --resource-path=apache -L kramdown-toc.lua -o apache_SSL_ET.pdf ``` ## Editing and building "Nginx SSL Configuration" @@ -56,14 +56,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do 1. Update source files in nginx/ -2. Build PDF document +2. Build the PDF document from the repository root ```bash # Export English version -pandoc nginx/index.md -L kramdown-toc.lua -o nginx_SSL_EN.pdf +pandoc nginx/index.md --resource-path=nginx -L kramdown-toc.lua -o nginx_SSL_EN.pdf # Export Estonian version -pandoc nginx/index.et.md -L kramdown-toc.lua -o nginx_SSL_ET.pdf +pandoc nginx/index.et.md --resource-path=nginx -L kramdown-toc.lua -o nginx_SSL_ET.pdf ``` ## Editing and building "IIS SSL Configuration" @@ -72,14 +72,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do 1. Update source files in iis/ -2. Build PDF document +2. Build the PDF document from the repository root ```bash # Export English version -pandoc iis/index.md -L kramdown-toc.lua -o iis_SSL_EN.pdf +pandoc iis/index.md --resource-path=iis -L kramdown-toc.lua -o iis_SSL_EN.pdf # Export Estonian version -pandoc iis/index.et.md -L kramdown-toc.lua -o iis_SSL_ET.pdf +pandoc iis/index.et.md --resource-path=iis -L kramdown-toc.lua -o iis_SSL_ET.pdf ``` ## Editing and building "ID-software Administrator View" @@ -88,14 +88,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do 1. Update source files in admin/ -2. Build PDF document +2. Build the PDF document from the repository root ```bash # Export English version -pandoc admin/index.md -L kramdown-toc.lua -o admin_view_EN.pdf +pandoc admin/index.md --resource-path=admin -L kramdown-toc.lua -o admin_view_EN.pdf # Export Estonian version -pandoc admin/index.et.md -L kramdown-toc.lua -o admin_view_ET.pdf +pandoc admin/index.et.md --resource-path=admin -L kramdown-toc.lua -o admin_view_ET.pdf ``` ## Support diff --git a/admin/img/image10.png b/admin/img/image10.png index 8339083..d11fab2 100644 Binary files a/admin/img/image10.png and b/admin/img/image10.png differ diff --git a/admin/img/image11.png b/admin/img/image11.png index ac4a9c0..4e206b2 100644 Binary files a/admin/img/image11.png and b/admin/img/image11.png differ diff --git a/admin/img/image5.png b/admin/img/image5.png index 2148de6..446a85f 100644 Binary files a/admin/img/image5.png and b/admin/img/image5.png differ diff --git a/admin/img/image6.png b/admin/img/image6.png deleted file mode 100644 index bf0a05d..0000000 Binary files a/admin/img/image6.png and /dev/null differ diff --git a/admin/img/image7.png b/admin/img/image7.png index 7bfff85..78223d1 100644 Binary files a/admin/img/image7.png and b/admin/img/image7.png differ diff --git a/admin/img/image8.png b/admin/img/image8.png deleted file mode 100644 index 905e2b9..0000000 Binary files a/admin/img/image8.png and /dev/null differ diff --git a/admin/img/image9.png b/admin/img/image9.png deleted file mode 100644 index 820be7f..0000000 Binary files a/admin/img/image9.png and /dev/null differ diff --git a/admin/index.et.md b/admin/index.et.md index 7b2ce1d..26de05c 100644 --- a/admin/index.et.md +++ b/admin/index.et.md @@ -2,7 +2,7 @@ **[In English](index.md)** -**Versioon:** 26.04/1 +**Versioon:** 26.06/1 **Väljaandja:** [RIA](https://www.ria.ee/) @@ -30,6 +30,7 @@ | 16.06.2025 | 25.06/1 | AWP asendatud IDPlug-iga. — Muutja: Raul Metsma | 31.10.2025 | 25.10/1 | Lisatud SmartCard Client. — Muutja: Raul Kaidro | 19.05.2026 | 26.04/1 | Avaldatud veebidokumentatsioonina. Lisatud Edge NativeMessagingAllowlist konfiguratsioon. — Muutja: Raul Metsma +| 11.06.2026 | 26.06/1 | Uuendatud GPO-MSI levitamise juhiseid ja kuvatõmmiseid. — Muutja: Raul Metsma --- @@ -79,15 +80,15 @@ Selle paigaldamisel kustutakse kaardi lugejast eemaldamisel Windowsi kasutaja se #### Digidoc_ShellExt -See komponent lisab võimaluse alustada hiire paremklikiga kiiresti ja mugavalt dokumendi allkirjastamist ning krüpteerimist DigiDoc4 rakenduses. +See komponent paigaldab klassikalise (*legacy*) Windows Exploreri kontekstimenüü laienduse, mis võimaldab alustada faili paremklõpsuga dokumendi allkirjastamist või krüpteerimist DigiDoc4 rakenduses. Windows 11-s kuvatakse selle laienduse käsud menüü *Show more options* all. Kui laiendus on Windows Explorerisse juba laaditud, võib selle paigaldamine või uuendamine nõuda Exploreri või arvuti taaskäivitamist. #### DigiDoc4 -DigiDoc4 on rakendus, mis võimaldab dokumente allkirjastada ja digiallkirjastatud dokumente valideerida, dokumente krüpteerida ja dekrüpteerida, saada ülevaadet ID-kaardi sertifikaatidest ning ID-kaardi PIN- ja PUK-koode hallata. +DigiDoc4 on rakendus, mis võimaldab dokumente allkirjastada ja digiallkirjastatud dokumente valideerida, dokumente krüpteerida ja dekrüpteerida, saada ülevaadet ID-kaardi sertifikaatidest ning ID-kaardi PIN- ja PUK-koode hallata. Nii DigiDoc4 MSI kui ka Microsoft Store'i rakendus paigaldavad Windows Exploreri moodsa kontekstimenüü laienduse; MSI teeb seda AppX-põhise lahenduse kaudu. #### ID-updater -ID-updater on kohustuslik komponent, mis sisaldab teiste ID-tarkvara komponentide jaoks vajalikke kolmanda osapoole teeke (Qt, OpenSSL jms). Installatsiooni käigus luuakse ka *Task Scheduleri* käsk `id updater task`, mis vaikimisi kontrollib uue tarkvara saadavust kord nädalas ja uuenduse leidmisel pakub selle kasutajale välja. +ID-tarkvara EXE-paigaldus paigaldab alati komponendi ID-updater, mis sisaldab teiste ID-tarkvara komponentide jaoks vajalikke kolmanda osapoole teeke (Qt, OpenSSL jms). Vaikimisi loob EXE-paigaldus ka *Task Scheduleri* käsu `id updater task`, mis kontrollib kord nädalas uue tarkvara saadavust ja pakub leitud uuenduse kasutajale. Automaatkorralduse loomise saab keelata parameetriga `AutoUpdate=0`, kuid ID-updater paigaldatakse ka sel juhul. Kui ID-tarkvara komponendid paigaldatakse eraldi MSI-pakkidena, ei ole ID-updater vajalik. ![Näide: ID-updater leidis uuema versiooni tarkvarast (EST)](./img/image3.png) @@ -103,11 +104,11 @@ Keskmistes ja suuremates ettevõtetes paigaldatakse tarkvara tavapäraselt mõne Lisaks interaktiivse installatsiooni puhul saadaolevatele konfiguratsioonivõimalustele on automaatsete installatsioonide puhul võimalik kasutada EXE-installatsioonidel järgmiseid võtmeid: -1. `ChromeSupport=0` — ei lisata Chrome laiendust, vaikimisi 1. -2. `EdgeSupport=0` — ei lisata Edge laiendust, vaikimisi 1. +1. `ChromeSupport=0` — ei paigaldata Chrome laiendust, registri kirjeid ega native messaging manifesti, vaikimisi 1. +2. `EdgeSupport=0` — ei paigaldata Edge laiendust, registri kirjeid ega native messaging manifesti, vaikimisi 1. 3. `ForceChromeExtensionActivation2=1` — Chrome laiendus aktiveeritakse automaatselt, vaikimisi 1. 4. `ForceEdgeExtensionActivation2=1` — Edge laiendus aktiveeritakse automaatselt, vaikimisi 1. -5. `FirefoxSupport=0` — ei lisata Firefox laiendust, vaikimisi 1. +5. `FirefoxSupport=0` — ei paigaldata Firefox laiendust, registri kirjeid ega native messaging manifesti, vaikimisi 1. 6. `InstallCertSynchronizer=1` — installeeritakse vaikimisi `OTCertSynchronizer`, vaikimisi 0[^3]. 7. `MinidriverInstall=0` — ei installeerita minidraiverit, vaikimisi 1. 8. `Qdigidoc4Install=0` — ei installeerita DigiDoc tarkvara, vaikimisi 1. @@ -116,6 +117,8 @@ Lisaks interaktiivse installatsiooni puhul saadaolevatele konfiguratsioonivõima > **Märkus:** Ülaltoodud installivõtmed on tõusutundlikud. +> **Märkus:** Kui `ChromeSupport`, `EdgeSupport` ja `FirefoxSupport` on kõik seatud väärtusele 0, ei paigaldata ka native messaging rakendust. + Näiteks käsurida `Open-EID-.exe /q AutoUpdate=0 IconsDesktop=0` installeerib ID-tarkvara vaikimisi režiimil, ei aktiveeri automaatset uuenduste otsimist ega paigalda ID-tarkvara ikoone töölauale. Vaikimisi piisab tarkvara installeerimiseks EXE käivitamisest, mis paigaldab tarkvara vaikimisi seadetega. @@ -144,15 +147,7 @@ Juhendis järgnevalt kirjeldatavad MST failid on allalaetavad asukohast **Märkus:** Võrreldes juhendi varasemate versioonidega ei ole GPO-MSI paigalduste puhul enam vaja paigaldada komponenti `ID-updater` ning komponendid ei vaja enam transformfaile, mis sunnivad tarkvara paigaldamist samasse kausta `PROGRAMMIFAILID\Open-EID`. ##### IDPlug @@ -179,26 +174,19 @@ Vajalik, kui soovitakse paksu kliendiga sertifikaate hallata, allkirjastada ja k Kohandused: -- GPO-MSI installatsioonide puhul on vaja kasutada transformfaili `2410-DD-Location.mst`. Sellisel juhul installeeritakse tarkvara vajalike draiveritega samasse kausta `PROGRAMMIFAILID\Open-EID`. - Vaikimisi MSI installatsioon töölauale vajalikke ikoone ei paigalda. Kui on soov seda teha, tuleb installatsioonile lisada ka transformfail `2410-DD-Shortcut`. -![Näide transformfaili lisamisest GPO-MSI installile](./img/image7.png) - -##### Windows-ile paremklikiga allkirjastamise ja krüpteerimise lisamine - -Windows paremklikiga allkirjastamise ja krüpteerimise lubamine. +DigiDoc4 MSI paigaldab Windows Exploreri moodsa kontekstimenüü laienduse AppX-põhise lahenduse kaudu. -Kohandused: +![Näide transformfaili lisamisest GPO-MSI installile](./img/image7.png) -- GPO-MSI installatsioonide puhul on vaja kasutada transformfaili `2410-DD-Shell-Location.mst`. Sellisel juhul installeeritakse tarkvara vajalike draiveritega samasse kausta `PROGRAMMIFAILID\Open-EID`. +##### Windowsile klassikalise paremkliki-laienduse lisamine -![Näide transformfaili lisamisest GPO-MSI installile](./img/image8.png) +`Digidoc_ShellExt` MSI paigaldab Windows Exploreri klassikalise kontekstimenüü laienduse. Windows 11-s kuvatakse selle laienduse käsud menüü *Show more options* all. Kasuta seda ainult siis, kui moodsa, DigiDoc4 MSI-ga kaasneva laienduse asemel on vaja klassikalist laiendust. Kui klassikaline laiendus on Explorerisse juba laaditud, võib selle paigaldamine või uuendamine nõuda Exploreri või arvuti taaskäivitamist. ##### Web eID -Brauserite laiendused ja omarakendus (*native app*). GPO-MSI installatsioonide puhul on vaja kasutada transformfaili `2410-Web-Location.mst`. Sellisel juhul installeeritakse tarkvara vajalike draiveritega samasse kausta `PROGRAMMIFAILID\Open-EID`. - -![Näide transformfaili lisamisest GPO-MSI installile](./img/image9.png) +Brauserite laiendused ja omarakendus (*native app*). MSI kohandatud pakkide loend näeb GPMC halduskonsoolis välja nii: @@ -208,7 +196,7 @@ GPO-MSI installatsioonide puhul ilmuvad kõik installeeritud programmid ka progr ![MSI installatsioonid programmide loendis](./img/image11.png) -> **Märkus:** MSI-de installatsioonide järjestus ei ole oluline, ent kõik sõltuvad MSI-st „OpenEID Updater". Samuti on oluline minidraiver, millest samuti teised komponendid sõltuvad. +> **Märkus:** MSI-de installatsioonide järjestus ei ole oluline, kuid vajalik minidraiver peab olema paigaldatud, sest teised komponendid sõltuvad sellest. > **Märkus:** MST failid on allalaetavad asukohast . diff --git a/admin/index.md b/admin/index.md index fee94e5..a90ab95 100644 --- a/admin/index.md +++ b/admin/index.md @@ -2,7 +2,7 @@ **[Eesti keeles (In Estonian)](index.et.md)** -**Version:** 26.04/1 +**Version:** 26.06/1 **Published by:** [RIA](https://www.ria.ee/) @@ -30,6 +30,7 @@ | 16/06/2025 | 25.06/1 | Replaced AWP with IDPlug. — Changed by: Raul Metsma | 31/10/2025 | 25.10/1 | Added SmartCard Client. — Changed by: Raul Kaidro | 19/05/2026 | 26.04/1 | Published as online documentation. Added Edge NativeMessagingAllowlist configuration. — Changed by: Raul Metsma +| 11/06/2026 | 26.06/1 | Updated GPO-MSI distribution guidance and screenshots. — Changed by: Raul Metsma --- @@ -79,15 +80,15 @@ When it is installed and the smart card is removed from the card reader, all ID- #### Digidoc_ShellExt -This component allows starting signing and encryption in DigiDoc4 by right-clicking on the file. +This component installs the legacy Windows Explorer context-menu extension, which allows signing or encryption to be started in DigiDoc4 by right-clicking a file. On Windows 11, commands provided by this extension appear under *Show more options*. If the extension has already been loaded into Windows Explorer, installing or updating it may require restarting Explorer or the computer. #### DigiDoc4 -DigiDoc4 is an application that enables the signing, validation, encryption, and decryption of documents as well as managing the PINs and PUKs of ID-cards. +DigiDoc4 is an application that enables the signing, validation, encryption, and decryption of documents as well as managing the PINs and PUKs of ID-cards. Both the DigiDoc4 MSI and the Microsoft Store app install the modern Windows Explorer context-menu extension; the MSI does so through an AppX-based solution. #### ID-updater -ID-updater is a mandatory component that bundles shared third-party libraries (Qt, OpenSSL, etc.) required by other ID-software components. During installation, the task scheduler task `id updater task` is created, which checks the availability of new software once per week and suggests any identified updates to the user. +The ID-software EXE installer always installs ID-updater, which bundles shared third-party libraries (Qt, OpenSSL, etc.) required by other ID-software components. By default, the EXE installer also creates the scheduled task `id updater task`, which checks for new software once per week and offers any available update to the user. Creating the scheduled task can be disabled with `AutoUpdate=0`, but ID-updater is still installed. ID-updater is not required when the ID-software components are installed as separate MSI packages. ![Example: ID-updater found a newer version of the software (EST)](./img/image3.png) @@ -103,11 +104,11 @@ In large and medium enterprises, the ID-software is usually installed and contro In addition to the configuration options available in the GUI, the following command-line parameters can be used for unattended installations: -1. `ChromeSupport=0` — the Chrome extension is not added, 1 by default. -2. `EdgeSupport=0` — the Edge extension is not added, 1 by default. +1. `ChromeSupport=0` — the Chrome extension, registry entries, and native messaging manifest are not installed, 1 by default. +2. `EdgeSupport=0` — the Edge extension, registry entries, and native messaging manifest are not installed, 1 by default. 3. `ForceChromeExtensionActivation2=1` — the Chrome extension is activated automatically, 1 by default. 4. `ForceEdgeExtensionActivation2=1` — the Edge extension is activated automatically, 1 by default. -5. `FirefoxSupport=0` — the Firefox extension is not added, 1 by default. +5. `FirefoxSupport=0` — the Firefox extension, registry entries, and native messaging manifest are not installed, 1 by default. 6. `InstallCertSynchronizer=1` — installs the component `OTCertSynchronizer`, 0 by default[^3]. 7. `MinidriverInstall=0` — the minidriver is not installed, 1 by default. 8. `Qdigidoc4Install=0` — the DigiDoc software is not installed, 1 by default. @@ -116,6 +117,8 @@ In addition to the configuration options available in the GUI, the following com > **Note:** The installation keys shown above are case sensitive. +> **Note:** If `ChromeSupport`, `EdgeSupport`, and `FirefoxSupport` are all set to 0, the native messaging application is not installed either. + For example, the command line `Open-EID-.exe /quiet AutoUpdate=0 IconsDesktop=0` installs the ID-software in unattended mode, does not activate automatic updates, and does not add the ID-software icons to the desktop. By default, running the EXE installs the software with default settings. @@ -146,15 +149,7 @@ The MST files described below in the manual can be downloaded from the location Below is a brief overview about how to configure GPO-MSI installations. -##### ID-updater - -ID-updater is a mandatory component. It is recommended to install it first. - -Options: - -- If you do not want to activate the automatic software update functionality (deferred `id updater task`), use the transform file `2410-no_autoupdate.mst` with this MSI installation. And it probably makes sense to disable it, since MSI installations don't support software update checking in this way. - -![Sample about adding a transform file to the MSI installation](./img/image6.png) +> **Note:** Compared to earlier versions of this guide, `ID-updater` no longer needs to be installed for GPO-MSI deployments, and components no longer need transform files that force installation into the same `PROGRAM FILES\Open-EID` folder. ##### IDPlug @@ -181,26 +176,19 @@ DigiDoc4 is a necessary component if you want to sign and encrypt documents as w Options: -- For GPO-MSI installations, it is necessary to use the transform file `2410-DD-Location.mst`. In this case, the software is installed in the same folder `PROGRAM FILES\Open-EID` as the necessary drivers. - The default MSI installation does not install the necessary icons on the desktop. However, if desktop icons are required, the transform file `2410-DD-Shortcut` must also be added to the installation. -![Adding transform files for MSI installation](./img/image7.png) - -##### Adding right-click signing and encryption to Windows - -Enables right-click signing and encryption of files in Windows Explorer. +The DigiDoc4 MSI installs the modern Windows Explorer context-menu extension through an AppX-based solution. -Options: +![Adding transform files for MSI installation](./img/image7.png) -- For GPO-MSI installations, it is necessary to use the transform file `2410-DD-Shell-Location.mst`. In this case, the software is installed in the same folder `PROGRAM FILES\Open-EID` as the necessary drivers. +##### Adding the legacy right-click extension to Windows -![Sample of adding a transform file to a GPO-MSI installation](./img/image8.png) +The `Digidoc_ShellExt` MSI installs the legacy Windows Explorer context-menu extension. On Windows 11, commands provided by this extension appear under *Show more options*. Use it only when the legacy extension is required instead of the modern extension included with the DigiDoc4 MSI. If the legacy extension has already been loaded into Explorer, installing or updating it may require restarting Explorer or the computer. ##### Web eID -Browser extensions and native app. For GPO-MSI installations, it is necessary to use the transform file `2410-Web-Location.mst`. In this case, the software is installed in the same folder `PROGRAM FILES\Open-EID` as the necessary drivers. - -![Sample of adding a transform file to a GPO-MSI installation](./img/image9.png) +Browser extensions and native app. The list of MSI custom packages in the GPMC management console looks like this: @@ -210,7 +198,7 @@ For GPO-MSI installations, all installed programs also appear in the software li ![MSI installations in the program list of the Control Panel](./img/image11.png) -> **Note:** The order of MSI installation components is not important, but all components depend on the MSI `Open-EID updater`. The minidriver is also important, as other components depend on it. +> **Note:** The order of MSI installation components is not important, but the required minidriver must be installed because other components depend on it. > **Note:** MST files can be downloaded from .