diff --git a/README.md b/README.md index dd2c98c..8839f37 100644 --- a/README.md +++ b/README.md @@ -24,14 +24,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do 1. Update source files in domain/ -2. Build PDF document +2. Build the PDF document from the repository root ```bash # Export English version -pandoc domain/index.md -L kramdown-toc.lua -o eID_Auth_Guide_EN.pdf +pandoc domain/index.md --resource-path=domain -L kramdown-toc.lua -o eID_Auth_Guide_EN.pdf # Export Estonian version -pandoc domain/index.et.md -L kramdown-toc.lua -o eID_Auth_Guide_ET.pdf +pandoc domain/index.et.md --resource-path=domain -L kramdown-toc.lua -o eID_Auth_Guide_ET.pdf ``` ## Editing and building "Apache2 SSL Configuration" @@ -40,14 +40,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do 1. Update source files in apache/ -2. Build PDF document +2. Build the PDF document from the repository root ```bash # Export English version -pandoc apache/index.md -L kramdown-toc.lua -o apache_SSL_EN.pdf +pandoc apache/index.md --resource-path=apache -L kramdown-toc.lua -o apache_SSL_EN.pdf # Export Estonian version -pandoc apache/index.et.md -L kramdown-toc.lua -o apache_SSL_ET.pdf +pandoc apache/index.et.md --resource-path=apache -L kramdown-toc.lua -o apache_SSL_ET.pdf ``` ## Editing and building "Nginx SSL Configuration" @@ -56,14 +56,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do 1. Update source files in nginx/ -2. Build PDF document +2. Build the PDF document from the repository root ```bash # Export English version -pandoc nginx/index.md -L kramdown-toc.lua -o nginx_SSL_EN.pdf +pandoc nginx/index.md --resource-path=nginx -L kramdown-toc.lua -o nginx_SSL_EN.pdf # Export Estonian version -pandoc nginx/index.et.md -L kramdown-toc.lua -o nginx_SSL_ET.pdf +pandoc nginx/index.et.md --resource-path=nginx -L kramdown-toc.lua -o nginx_SSL_ET.pdf ``` ## Editing and building "IIS SSL Configuration" @@ -72,14 +72,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do 1. Update source files in iis/ -2. Build PDF document +2. Build the PDF document from the repository root ```bash # Export English version -pandoc iis/index.md -L kramdown-toc.lua -o iis_SSL_EN.pdf +pandoc iis/index.md --resource-path=iis -L kramdown-toc.lua -o iis_SSL_EN.pdf # Export Estonian version -pandoc iis/index.et.md -L kramdown-toc.lua -o iis_SSL_ET.pdf +pandoc iis/index.et.md --resource-path=iis -L kramdown-toc.lua -o iis_SSL_ET.pdf ``` ## Editing and building "ID-software Administrator View" @@ -88,14 +88,14 @@ Uses https://jekyllrb.com and https://just-the-docs.com styles for generating do 1. Update source files in admin/ -2. Build PDF document +2. Build the PDF document from the repository root ```bash # Export English version -pandoc admin/index.md -L kramdown-toc.lua -o admin_view_EN.pdf +pandoc admin/index.md --resource-path=admin -L kramdown-toc.lua -o admin_view_EN.pdf # Export Estonian version -pandoc admin/index.et.md -L kramdown-toc.lua -o admin_view_ET.pdf +pandoc admin/index.et.md --resource-path=admin -L kramdown-toc.lua -o admin_view_ET.pdf ``` ## Support diff --git a/admin/img/image10.png b/admin/img/image10.png index 8339083..d11fab2 100644 Binary files a/admin/img/image10.png and b/admin/img/image10.png differ diff --git a/admin/img/image11.png b/admin/img/image11.png index ac4a9c0..4e206b2 100644 Binary files a/admin/img/image11.png and b/admin/img/image11.png differ diff --git a/admin/img/image19.png b/admin/img/image19.png deleted file mode 100644 index 2b33126..0000000 Binary files a/admin/img/image19.png and /dev/null differ diff --git a/admin/img/image21.png b/admin/img/image21.png deleted file mode 100644 index 1e104a3..0000000 Binary files a/admin/img/image21.png and /dev/null differ diff --git a/admin/img/image5.png b/admin/img/image5.png index 2148de6..446a85f 100644 Binary files a/admin/img/image5.png and b/admin/img/image5.png differ diff --git a/admin/img/image6.png b/admin/img/image6.png deleted file mode 100644 index bf0a05d..0000000 Binary files a/admin/img/image6.png and /dev/null differ diff --git a/admin/img/image7.png b/admin/img/image7.png index 7bfff85..78223d1 100644 Binary files a/admin/img/image7.png and b/admin/img/image7.png differ diff --git a/admin/img/image8.png b/admin/img/image8.png deleted file mode 100644 index 905e2b9..0000000 Binary files a/admin/img/image8.png and /dev/null differ diff --git a/admin/img/image9.png b/admin/img/image9.png deleted file mode 100644 index 820be7f..0000000 Binary files a/admin/img/image9.png and /dev/null differ diff --git a/admin/index.et.md b/admin/index.et.md index 7b2ce1d..6b009e7 100644 --- a/admin/index.et.md +++ b/admin/index.et.md @@ -2,7 +2,7 @@ **[In English](index.md)** -**Versioon:** 26.04/1 +**Versioon:** 26.07/1 **Väljaandja:** [RIA](https://www.ria.ee/) @@ -20,16 +20,18 @@ | 29.03.2022 | 22.03/1 | Laiendite keskse levitamise peatükis parandatud Chrome Web eID laienduse väärtus. — Muutja: Urmas Vanem | 13.04.2022 | 22.04/1 | Lisatud Web eID laienduste paigaldamise vaikekoha muutmine. — Muutja: Tarmo Nurmela | 21.04.2022 | 22.04/2 | Lisatud MSI pakiga Idemia minidraiveri automaatinstallatsiooni kirjeldus (ilma kaardita/lugejata, RDP juhtum). — Muutja: Urmas Vanem -| 13.06.2022 | 22.06/1 | Lisatud peatükk „Tarkvara uuenduste loogika" ja Chrome „Configure native messaging blocklist/allowlist" poliitikate kirjeldus. — Muutja: Urmas Vanem +| 13.06.2022 | 22.06/1 | Lisatud peatükk „Tarkvara uuenduste loogika“ ja Chrome „Configure native messaging blocklist/allowlist“ poliitikate kirjeldus. — Muutja: Urmas Vanem | 29.07.2022 | 22.07/1 | Dokumendis kirjeldatava tarkvara baasversioon on uuendatud versioonile 22.06.0.1930, kirjeldatud on uue versiooniga seotud muudatused, eemaldatud aegunud info, lisatud Firefox kesksete poliitikate kirjeldus. — Muutjad: Kristel Merilain, Urmas Vanem | 11.08.2022 | 22.08/1 | Lisatud ID-tarkvara uuenduste protsessi kirjeldus. — Muutja: Urmas Vanem -| 31.08.2022 | 22.08/2 | Parandatud „Veebilehitsejate käitumisest laiendite vaates installatsiooni ajal" peatükis olevate tabelite informatsioon. — Muutja: Kristel Merilain +| 31.08.2022 | 22.08/2 | Parandatud „Veebilehitsejate käitumisest laiendite vaates installatsiooni ajal“ peatükis olevate tabelite informatsioon. — Muutja: Kristel Merilain | 14.12.2022 | 22.12/1 | Muudetud laiendite käitumise kirjeldust Edge ja Chrome veebilehitsejates installatsiooni ajal ning tarkvara on kaasajastatud versioonile 22.11. — Muutja: Kristjan Vaikla | 29.12.2022 | 22.12/1 | Uuendatud transform failide info `AWP`, `Digidoc_ShellExt` ja Web eID peatükkides. — Muutja: Märt Hirtentreu | 24.10.2024 | 24.10/1 | Eemaldatud Gemalto minidraiver, uuendatud installatsiooniloogikat, muudetud veebilehitsejatesse suhtumist installatsiooni ajal jpm. — Muutja: Urmas Vanem | 16.06.2025 | 25.06/1 | AWP asendatud IDPlug-iga. — Muutja: Raul Metsma | 31.10.2025 | 25.10/1 | Lisatud SmartCard Client. — Muutja: Raul Kaidro | 19.05.2026 | 26.04/1 | Avaldatud veebidokumentatsioonina. Lisatud Edge NativeMessagingAllowlist konfiguratsioon. — Muutja: Raul Metsma +| 11.06.2026 | 26.06/1 | Uuendatud GPO-MSI levitamise juhiseid ja kuvatõmmiseid. — Muutja: Raul Metsma +| 29.07.2026 | 26.07/1 | Lisatud Microsoft Intune paigaldusjuhised ID-tarkvarale ning laienduste keskseks haldamiseks. — Muutja: Raul Metsma --- @@ -79,15 +81,15 @@ Selle paigaldamisel kustutakse kaardi lugejast eemaldamisel Windowsi kasutaja se #### Digidoc_ShellExt -See komponent lisab võimaluse alustada hiire paremklikiga kiiresti ja mugavalt dokumendi allkirjastamist ning krüpteerimist DigiDoc4 rakenduses. +See komponent paigaldab klassikalise (*legacy*) Windows Exploreri kontekstimenüü laienduse, mis võimaldab alustada faili paremklõpsuga dokumendi allkirjastamist või krüpteerimist DigiDoc4 rakenduses. Windows 11-s kuvatakse selle laienduse käsud menüü *Show more options* all. Kui laiendus on Windows Explorerisse juba laaditud, võib selle paigaldamine või uuendamine nõuda Exploreri või arvuti taaskäivitamist. #### DigiDoc4 -DigiDoc4 on rakendus, mis võimaldab dokumente allkirjastada ja digiallkirjastatud dokumente valideerida, dokumente krüpteerida ja dekrüpteerida, saada ülevaadet ID-kaardi sertifikaatidest ning ID-kaardi PIN- ja PUK-koode hallata. +DigiDoc4 on rakendus, mis võimaldab dokumente allkirjastada ja digiallkirjastatud dokumente valideerida, dokumente krüpteerida ja dekrüpteerida, saada ülevaadet ID-kaardi sertifikaatidest ning ID-kaardi PIN- ja PUK-koode hallata. Nii DigiDoc4 MSI kui ka Microsoft Store'i rakendus paigaldavad Windows Exploreri moodsa kontekstimenüü laienduse; MSI teeb seda AppX-põhise lahenduse kaudu. #### ID-updater -ID-updater on kohustuslik komponent, mis sisaldab teiste ID-tarkvara komponentide jaoks vajalikke kolmanda osapoole teeke (Qt, OpenSSL jms). Installatsiooni käigus luuakse ka *Task Scheduleri* käsk `id updater task`, mis vaikimisi kontrollib uue tarkvara saadavust kord nädalas ja uuenduse leidmisel pakub selle kasutajale välja. +ID-tarkvara EXE-paigaldus paigaldab alati komponendi ID-updater, mis sisaldab teiste ID-tarkvara komponentide jaoks vajalikke kolmanda osapoole teeke (Qt, OpenSSL jms). Vaikimisi loob EXE-paigaldus ka *Task Scheduleri* käsu `id updater task`, mis kontrollib kord nädalas uue tarkvara saadavust ja pakub leitud uuenduse kasutajale. Automaatkorralduse loomise saab keelata parameetriga `AutoUpdate=0`, kuid ID-updater paigaldatakse ka sel juhul. Kui ID-tarkvara komponendid paigaldatakse eraldi MSI-pakkidena, ei ole ID-updater vajalik. ![Näide: ID-updater leidis uuema versiooni tarkvarast (EST)](./img/image3.png) @@ -97,18 +99,18 @@ Web eID võimaldab Eesti ID-kaarte kasutada veebis autentimiseks ja allkirjastam ### Ettevõttes -Keskmistes ja suuremates ettevõtetes paigaldatakse tarkvara tavapäraselt mõne keskse halduslahenduse abil. Enim on levinud SCCM[^1] ja AD/GP[^2] lahendused. +Keskmistes ja suurtes organisatsioonides paigaldatakse ja hallatakse ID-tarkvara tavaliselt keskselt. Levinud lahendused on Microsoft Intune, Microsoft Configuration Manager (SCCM) ja Active Directory rühmapoliitikad (AD/GPO). #### SCCM Lisaks interaktiivse installatsiooni puhul saadaolevatele konfiguratsioonivõimalustele on automaatsete installatsioonide puhul võimalik kasutada EXE-installatsioonidel järgmiseid võtmeid: -1. `ChromeSupport=0` — ei lisata Chrome laiendust, vaikimisi 1. -2. `EdgeSupport=0` — ei lisata Edge laiendust, vaikimisi 1. +1. `ChromeSupport=0` — ei paigaldata Chrome laiendust, registri kirjeid ega native messaging manifesti, vaikimisi 1. +2. `EdgeSupport=0` — ei paigaldata Edge laiendust, registri kirjeid ega native messaging manifesti, vaikimisi 1. 3. `ForceChromeExtensionActivation2=1` — Chrome laiendus aktiveeritakse automaatselt, vaikimisi 1. 4. `ForceEdgeExtensionActivation2=1` — Edge laiendus aktiveeritakse automaatselt, vaikimisi 1. -5. `FirefoxSupport=0` — ei lisata Firefox laiendust, vaikimisi 1. -6. `InstallCertSynchronizer=1` — installeeritakse vaikimisi `OTCertSynchronizer`, vaikimisi 0[^3]. +5. `FirefoxSupport=0` — ei paigaldata Firefox laiendust, registri kirjeid ega native messaging manifesti, vaikimisi 1. +6. `InstallCertSynchronizer=1` — installeeritakse vaikimisi `OTCertSynchronizer`, vaikimisi 0[^1]. 7. `MinidriverInstall=0` — ei installeerita minidraiverit, vaikimisi 1. 8. `Qdigidoc4Install=0` — ei installeerita DigiDoc tarkvara, vaikimisi 1. 9. `IconsDesktop=0` — ei paigutata DigiDoc ikooni desktopile, vaikimisi 1. @@ -116,6 +118,8 @@ Lisaks interaktiivse installatsiooni puhul saadaolevatele konfiguratsioonivõima > **Märkus:** Ülaltoodud installivõtmed on tõusutundlikud. +> **Märkus:** Kui `ChromeSupport`, `EdgeSupport` ja `FirefoxSupport` on kõik seatud väärtusele 0, ei paigaldata ka native messaging rakendust. + Näiteks käsurida `Open-EID-.exe /q AutoUpdate=0 IconsDesktop=0` installeerib ID-tarkvara vaikimisi režiimil, ei aktiveeri automaatset uuenduste otsimist ega paigalda ID-tarkvara ikoone töölauale. Vaikimisi piisab tarkvara installeerimiseks EXE käivitamisest, mis paigaldab tarkvara vaikimisi seadetega. @@ -130,9 +134,9 @@ Selle tavapärase installatsiooni tulemusena on ID-tarkvara tavapäraselt näha Juhul, kui keskne süsteemihaldusvahend on ettevõttes puudu, küll aga on võimalik kasutada rühmapoliitikate (GPO) võimalusi, on võimalik kasutada ka MSI tüüpi installatsioone. Soovitatav on GPO installatsioonid teha arvutipõhised. -> **Märkus:** Vaikimisi on MSI installatsioonid mõeldud vaid uute installatsioonide tegemiseks. Ükski eID tarkvara MSI komponent vanemaid, exe põhiselt installeeritud tarkvara versioone ei eemalda. +> **Märkus:** MSI-pakke saab kasutada nii esmaseks paigalduseks kui ka keskselt hallatud uuendusteks. Need ei eemalda ega vii olemasolevat EXE-põhist paigaldust automaatselt MSI-põhisele haldusele. EXE-lt MSI-põhisele haldusele üleminekul eemalda EXE-põhine paigaldus eraldi. Järgnevate MSI-uuenduste puhul levita uuemaid komponendipakke keskhalduslahenduse kaudu ja testi enne juurutamist konkreetse versiooni uuenduskäitumist. -Milleks erinevad komponendid on vajalikud, leiad peatükist „[Lühidalt erinevatest komponentidest](#lühidalt-erinevatest-id-tarkvara-komponentidest)", allpool tuleb ülevaade GPO-MSI installatsioonide konfigureerimise kohta. +Milleks erinevad komponendid on vajalikud, leiad peatükist „[Lühidalt erinevatest komponentidest](#lühidalt-erinevatest-id-tarkvara-komponentidest)“, allpool tuleb ülevaade GPO-MSI installatsioonide konfigureerimise kohta. MSI pakid on EXE-sse sisse pakitud, kuid neid ei saa sealt lahti pakkida. Küll aga on need eraldi allalaetavad aadressilt . @@ -144,15 +148,7 @@ Juhendis järgnevalt kirjeldatavad MST failid on allalaetavad asukohast **Märkus:** Võrreldes juhendi varasemate versioonidega ei ole GPO-MSI paigalduste puhul enam vaja paigaldada komponenti `ID-updater` ning komponendid ei vaja enam transformfaile, mis sunnivad tarkvara paigaldamist samasse kausta `PROGRAMMIFAILID\Open-EID`. ##### IDPlug @@ -179,26 +175,19 @@ Vajalik, kui soovitakse paksu kliendiga sertifikaate hallata, allkirjastada ja k Kohandused: -- GPO-MSI installatsioonide puhul on vaja kasutada transformfaili `2410-DD-Location.mst`. Sellisel juhul installeeritakse tarkvara vajalike draiveritega samasse kausta `PROGRAMMIFAILID\Open-EID`. - Vaikimisi MSI installatsioon töölauale vajalikke ikoone ei paigalda. Kui on soov seda teha, tuleb installatsioonile lisada ka transformfail `2410-DD-Shortcut`. -![Näide transformfaili lisamisest GPO-MSI installile](./img/image7.png) - -##### Windows-ile paremklikiga allkirjastamise ja krüpteerimise lisamine +DigiDoc4 MSI paigaldab Windows Exploreri moodsa kontekstimenüü laienduse AppX-põhise lahenduse kaudu. -Windows paremklikiga allkirjastamise ja krüpteerimise lubamine. - -Kohandused: +![Näide transformfaili lisamisest GPO-MSI installile](./img/image7.png) -- GPO-MSI installatsioonide puhul on vaja kasutada transformfaili `2410-DD-Shell-Location.mst`. Sellisel juhul installeeritakse tarkvara vajalike draiveritega samasse kausta `PROGRAMMIFAILID\Open-EID`. +##### Windowsile klassikalise paremkliki-laienduse lisamine -![Näide transformfaili lisamisest GPO-MSI installile](./img/image8.png) +`Digidoc_ShellExt` MSI paigaldab Windows Exploreri klassikalise kontekstimenüü laienduse. Windows 11-s kuvatakse selle laienduse käsud menüü *Show more options* all. Kasuta seda ainult siis, kui moodsa, DigiDoc4 MSI-ga kaasneva laienduse asemel on vaja klassikalist laiendust. Kui klassikaline laiendus on Explorerisse juba laaditud, võib selle paigaldamine või uuendamine nõuda Exploreri või arvuti taaskäivitamist. ##### Web eID -Brauserite laiendused ja omarakendus (*native app*). GPO-MSI installatsioonide puhul on vaja kasutada transformfaili `2410-Web-Location.mst`. Sellisel juhul installeeritakse tarkvara vajalike draiveritega samasse kausta `PROGRAMMIFAILID\Open-EID`. - -![Näide transformfaili lisamisest GPO-MSI installile](./img/image9.png) +Brauserite laiendused ja omarakendus (*native app*). MSI kohandatud pakkide loend näeb GPMC halduskonsoolis välja nii: @@ -208,23 +197,101 @@ GPO-MSI installatsioonide puhul ilmuvad kõik installeeritud programmid ka progr ![MSI installatsioonid programmide loendis](./img/image11.png) -> **Märkus:** MSI-de installatsioonide järjestus ei ole oluline, ent kõik sõltuvad MSI-st „OpenEID Updater". Samuti on oluline minidraiver, millest samuti teised komponendid sõltuvad. +> **Märkus:** MSI-de installatsioonide järjestus ei ole oluline, kuid vajalik minidraiver peab olema paigaldatud, sest teised komponendid sõltuvad sellest. > **Märkus:** MST failid on allalaetavad asukohast . > **Märkus:** Skoobis olevad juur- ja kesktaseme sertifikaadid on soovitatav domeenis publitseerida rühmapoliitikate abil kõikidele serveritele ja tööjaamadele. +#### Microsoft Intune'i rakenduste levitamine + +Kui seadmeid hallatakse Microsoft Intune'iga, levita eespool kirjeldatud eraldi MSI pakke Win32 rakendustena. MSI paigalduste puhul ei ole `ID-updater` vajalik. + +MSI komponendi Intune'i jaoks pakkimiseks: + +1. Laadi alla *Microsoft Win32 Content Prep Tool* (`IntuneWinAppUtil.exe`) aadressilt . +2. Pane komponendi MSI ja kõik vajalikud MST failid eraldi lähtekausta. +3. Pakenda MSI tööriista abil `.intunewin` failiks. +4. Ava Intune halduskeskuses *Apps > All apps > Create*, vali rakenduse tüübiks *Windows app (Win32)* ja laadi üles tekkinud `.intunewin` fail. + +Ilma käsureaparameetriteta käivitamisel küsib `IntuneWinAppUtil.exe` lähtekausta, installifaili ja väljundkausta. Tööriist toetab ka käsureaparameetreid, mis on kasulikud pakkimise sammu skriptimiseks: + +``` +IntuneWinAppUtil.exe -c Source -s "" -o Out -q +``` + +- `-c` — lähtekaust (kõik installatsiooniks vajalikud failid) +- `-s` — paigaldatava komponendi MSI fail +- `-o` — väljundkaust, kuhu tekib `.intunewin` fail +- `-q` — vaikne režiim, mis jätab ära interaktiivsed küsimused (nt kinnituse küsimise olemasoleva väljundfaili ülekirjutamiseks) + +Installatsiooni käsk, eemaldamise käsk ja tuvastusreegel (*detection rule*) sisestatakse Intune halduskeskuse rakenduse loomise juhendatud protsessis. Alltoodud failinimed on kohatäitjad; asenda need allalaaditud `Open-EID.zip` failis olevate tegelike versioonipõhiste failinimedega: + +- *Program* vahekaart: + - Installatsiooni käsk, näiteks: `msiexec /i "" /quiet` + - Eemaldamise käsk: `msiexec /x "{PRODUCT-CODE}" /quiet` + - Installatsiooni käituskontekst (*Install behavior*): *System* +- *Detection rules* vahekaart — vali *Manually configure detection rules*, lisa *MSI* reegel, sisesta vastava versiooni MSI tootekood ja luba MSI tooteversiooni kontroll. +- *Assignments* vahekaart — rakenduse automaatseks paigaldamiseks määra see soovitud seadme- või kasutajagruppidele profiiliga *Required*. + +> **Märkus:** `{PRODUCT-CODE}` on kohatäitja. Kui Content Prep Tooli installifailiks (`-s`) valida MSI, loeb tööriist selle metaandmed ning Intune saab tootekoodi MSI tuvastusreeglis kasutada. Kontrolli Intune'is kuvatud väärtust ning kasuta sama GUID-i eemaldamiskäsus. Enne pakkimist saab väärtust vaadata ka [Orcaga](https://learn.microsoft.com/en-us/windows/win32/msi/orca-exe): ava MSI, vali tabel `Property` ning loe rea `ProductCode` veerust `Value` vajalik GUID. Tootekood võib versiooni, arhitektuuri ja keelepaketi lõikes erineda, seetõttu ei ole selles juhendis konkreetseid GUID-e loetletud. + +Transformfailid antakse MSI käsureal kaasa `TRANSFORMS` parameetriga, näiteks: + +``` +msiexec /i "" TRANSFORMS=DisableIDPlugServices.mst /quiet +``` + +Kui MSI komponendid levitatakse eraldi Win32 rakendustena, määra vajalik minidraiver seda vajavate komponentide sõltuvuseks. + +> **Märkus:** MSI komponendid ja transformfailid on samad, mis eespool kirjeldatud peatükis [AD/GPO](#adgpo). + +##### DigiDoc4 levitusviisi valimine + +DigiDoc4 saab levitada kas Microsoft Store'ist või MSI-põhise Win32 rakendusena. Kasuta ühe seadmegrupi jaoks ainult ühte neist meetoditest. + +###### Valik 1: Microsoft Store + +DigiDoc4 on saadaval [Microsoft Store'is](https://apps.microsoft.com/detail/9pfpfk4dj1s6). Selle Intune'i kaudu levitamiseks ava *Apps > All apps > Create*, vali *Microsoft Store app (new)* ning otsi rakendust nimega `DigiDoc4` või Store'i tootetunnusega `9PFPFK4DJ1S6`. Rakenduse saab seejärel määrata profiiliga *Required* või *Available for enrolled devices*. + +Store'i rakendus sisaldab DigiDoc4 rakendust koos failiseoste ja Windows Exploreri moodsa kontekstimenüü laiendusega. See ei asenda ID-kaardi minidraiverit ega Web eID omarakendust ja brauserilaiendusi. Levita need vajalikud komponendid eraldi eespool kirjeldatud MSI pakkidega. + +Intune'i kaudu Microsoft Store'ist levitatud rakendusi uuendatakse automaatselt. Kasuta seda võimalust, kui DigiDoc4 uusima versiooni automaatne vastuvõtmine on sobiv; kui iga DigiDoc4 versioon peab enne levitamist olema testitud ja heaks kiidetud, kasuta eespool kirjeldatud MSI-põhist Win32 paigaldust. + +###### Valik 2: MSI-põhine Win32 rakendus + +Pakenda DigiDoc4 MSI eespool kirjeldatud viisil. MSI paigaldab Windows Exploreri moodsa kontekstimenüü laienduse AppX-põhise lahenduse kaudu. Töölaua otseteede lisamiseks pane `2410-DD-Shortcut.mst` lähtekausta ja kasuta käsku: + +``` +msiexec /i "" TRANSFORMS=2410-DD-Shortcut.mst /quiet +``` + +`Digidoc_ShellExt` MSI-d ei ole moodsa kontekstimenüü laienduse jaoks vaja. Levita see eraldi ainult siis, kui vaja on Windows Exploreri klassikalist kontekstimenüü laiendust. Windows 11-s kuvatakse selle laienduse käsud menüü *Show more options* all. Kui klassikaline laiendus on Explorerisse juba laaditud, võib selle paigaldamine või uuendamine nõuda Exploreri või arvuti taaskäivitamist. MSI-põhine valik võimaldab organisatsioonil iga DigiDoc4 versiooni enne levitamist testida ja heaks kiita, kuid uuendusi tuleb hallata Intune'is. + +##### Intune'i paigalduse uuendamine + +Store'i valiku puhul uuendab Microsoft Store DigiDoc4 rakendust automaatselt. MSI-põhiste Win32 rakenduste puhul levita iga heakskiidetud komponendiuuendus Intune'i kaudu: + +1. Loo uue komponendi MSI-st uus `.intunewin` pakk. +2. Uuenda installatsiooni- ja eemaldamiskäske, MSI tootekoodi ning tooteversiooni tuvastust. +3. Loo uus Win32 rakendus või uuenda olemasoleva rakenduse sisu. Uue rakenduse loomisel määra see eelmise versiooni asendajaks (*supersedence*). Kui testimine kinnitab, et uus MSI uuendab olemasoleva paigalduse, määra *Uninstall previous version* väärtuseks *No*. Kasuta väärtust *Yes* ainult siis, kui eelmine pakk tuleb enne uue paigaldamist eemaldada. +4. Testi paigaldust ja määra uus versioon seejärel vajalikele gruppidele. + +Kõigi MSI-põhiste ID-tarkvara komponentide järgnevate versioonide levitamise eest vastutab Intune. + ### Laienduste levitamine keskselt -Veebilehitsejate laiendusi on võimalik levitada ka keskselt kasutades GPO meetodeid. +Veebilehitsejate laiendusi saab keskselt levitada rühmapoliitika või Microsoft Intune'i kaudu. Alltoodud konfiguratsioonid tuleb kindlasti enne reaalset rakendamist kohalikes oludes testida. -#### Chromium Edge +#### Brauserilaienduste poliitikad AD/GPO kaudu + +##### Chromium Edge Edge puhul tuleb alla laadida värskeim Edge poliitikate raamistik aadressilt ja siduda see enda domeeni lahendusega. -Pärast poliitikate keskkonnale tutvustamist saab teha uue poliitika, millega muudetakse Web eID laienduse kasutamine domeenis automaatseks. Selleks tuleb määrata välja `CC/Administrative Templates/Microsoft Edge/Extensions — „Control which extensions are installed silently"` väärtuseks `gnmckgbandlkacikdndelhfghdejfido`. +Pärast poliitikate keskkonnale tutvustamist saab teha uue poliitika, millega muudetakse Web eID laienduse kasutamine domeenis automaatseks. Selleks tuleb määrata välja `Computer Configuration/Policies/Administrative Templates/Microsoft Edge/Extensions — Control which extensions are installed silently` väärtuseks `gnmckgbandlkacikdndelhfghdejfido`. ![Edge laienduse ID on gnmckgbandlkacikdndelhfghdejfido](./img/image12.png) @@ -232,11 +299,11 @@ Pärast poliitikate keskkonnale tutvustamist saab teha uue poliitika, millega mu ![Poliitika informatsioon registris](./img/image14.png) -##### Vajalik lisakonfiguratsioon „native messaging" vaates +###### Vajalik lisakonfiguratsioon `native messaging` jaoks Vaikimisi on kõik native messaging hostid Edge'is lubatud. Kui aga `NativeMessagingBlocklist` poliitika väärtuseks on määratud `*`, siis Web eID allkirjastamine ei toimi. Lahenduseks tuleb `eu.webeid` lisada `NativeMessagingAllowlist` poliitikasse. Lisainfo: Edge poliitika dokumentatsioon [NativeMessagingAllowlist](https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/nativemessagingallowlist). -#### Google Chrome +##### Google Chrome Chrome poliitika pannakse paika juba ID-tarkvara installeerimise käigus. Registrisse kirjutatakse info, millega lubatakse Web eID laiendus Chrome's automaatselt: @@ -246,7 +313,7 @@ Kui on soov Chrome poliitikaid ettevõttes keskselt hallata, võib abi olla allj Chrome puhul tuleb kesksete poliitikate kasutamiseks alla laadida värskeimad Chrome haldusmallid aadressilt ja siduda need domeeni lahendusega. -Pärast poliitikate keskkonnale tutvustamist saab teha uue poliitika, millega muudetakse Web eID laienduse kasutamine domeenis automaatseks. Selleks tuleb määrata loendi `CC/Administrative Templates/Google/Google Chrome/Extensions — „Configure the list of force-installed apps and extensions"` üheks väärtuseks `ncibgoaomkmdpilpocfeponihegamlic`. +Pärast poliitikate keskkonnale tutvustamist saab teha uue poliitika, millega muudetakse Web eID laienduse kasutamine domeenis automaatseks. Selleks tuleb määrata loendi `Computer Configuration/Policies/Administrative Templates/Google/Google Chrome/Extensions — Configure the list of force-installed apps and extensions` üheks väärtuseks `ncibgoaomkmdpilpocfeponihegamlic`. ![Chrome Web eID laienduse ID on ncibgoaomkmdpilpocfeponihegamlic](./img/image16.png) @@ -254,11 +321,14 @@ Pärast poliitikate keskkonnale tutvustamist saab teha uue poliitika, millega mu ![Poliitika informatsioon registris](./img/image18.png) -##### Vajalik lisakonfiguratsioon „native messaging" vaates +###### Vajalik lisakonfiguratsioon `native messaging` jaoks -Juhul, kui Chrome poliitikatega on konfigureeritud omadus `Configure native messaging blocklist` ja määratud seal väärtuseks `*`, siis kasutades ülalkirjeldatud Chrome veebilehitseja laiendust allkirjastamine ei toimi. Näiteks testlehel allkirjastamisel kuvatakse tulemuseks `getCertificate() failed: Error: technical_error`. +Juhul, kui Chrome poliitikatega on konfigureeritud omadus `Configure native messaging blocklist` ja määratud seal väärtuseks `*`, siis kasutades ülalkirjeldatud Chrome veebilehitseja laiendust allkirjastamine ei toimi. Näiteks testlehel allkirjastamisel kuvatakse: -![Allkirjastamise katsel saadud viga](./img/image19.png) +``` +Debug: hwcrypto.js 0.0.13 with failing backend Chrome native messaging extension +getCertificate() failed: Error: technical_error +``` Lubamaks sellises situatsioonis veebis siiski allkirjastamist, tuleb lubada host `eu.webeid` poliitikas `Configure native messaging allowlist`: @@ -266,9 +336,14 @@ Lubamaks sellises situatsioonis veebis siiski allkirjastamist, tuleb lubada host Pärast poliitika rakendamist allkirjastamine õnnestub. -![Allkirjastamine veebilehel õnnestub](./img/image21.png) +``` +Debug: hwcrypto.js 0.0.13 with Chrome native messaging extension 2.0.1/2.0.0.552 +Using certificate: +-----BEGIN CERTIFICATE----- +... +``` -#### Mozilla Firefox +##### Mozilla Firefox Firefox poliitika määratakse juba ID-tarkvara installeerimise käigus, registrisse kirjutatakse järgneval pildil kajastatud info. Eelnimetatud poliitika abil installeeritakse Web eID laiendus Firefoxile automaatselt: @@ -278,7 +353,7 @@ Kui on soov Firefox poliitikaid ettevõttes keskselt hallata, võib abi olla all Firefox puhul tuleb kesksete poliitikate kasutamiseks alla laadida Firefox värskeimad haldusmallid aadressilt ja siduda need domeeni lahendusega. -Pärast poliitikate keskkonnale tutvustamist saab teha uue poliitika, millega muudetakse Web eID laienduse kasutamine domeenis automaatseks. Selleks on mitmeid võimalusi, ent soovitav on üle kirjutada juba installatsiooni käigus kirjeldatud poliitika. Selleks määratakse välja `CC/Administrative Templates/Mozilla/Firefox/Extensions — 'Extension Management'` väärtuseks järgnev tekst: +Pärast poliitikate keskkonnale tutvustamist saab teha uue poliitika, millega muudetakse Web eID laienduse kasutamine domeenis automaatseks. Selleks on mitmeid võimalusi, ent soovitav on üle kirjutada juba installatsiooni käigus kirjeldatud poliitika. Selleks määratakse välja `Computer Configuration/Policies/Administrative Templates/Mozilla/Firefox/Extensions — Extension Management` väärtuseks järgnev tekst: ```json { @@ -298,7 +373,7 @@ Registris paigaldatakse vastav info samasse kohta, kuhu ka installatsiooni ajal. Kui on soov, et kasutaja ei saaks iseseisvalt Web eID laiendust välja lülitada, tuleb: 1. Asendada ülaltoodud välja väärtuses tekst `normal_installed` tekstiga `force_installed`; -2. Lisada rida `{e68418bc-f2b0-4459-a9ea-3e72b6751b07}` loendisse `CC/Administrative Templates/Mozilla/Firefox/Extensions — 'Prevent extensions from being disabled or removed'`. +2. Lisada rida `{e68418bc-f2b0-4459-a9ea-3e72b6751b07}` loendisse `Computer Configuration/Policies/Administrative Templates/Mozilla/Firefox/Extensions — Prevent extensions from being disabled or removed`. ![Firefox Web eID poliitika keelamine](./img/image25.png) @@ -306,7 +381,30 @@ Pärast kummagi poliitika rakendamist ei saa kasutaja enda Firefoxis Web eID lai ![Web eID laiendus on alati sees](./img/image26.png) -Lisaks on võimalik laiendus installida ka loendi `CC/Administrative Templates/Mozilla/Firefox/Extensions — 'Extensions to install'` abil, ent praeguse konfiguratsiooni puhul on pigem soovitav olemasoleva väärtuse ülekirjutamine. +Lisaks on võimalik laiendus installida ka loendi `Computer Configuration/Policies/Administrative Templates/Mozilla/Firefox/Extensions — Extensions to install` abil, ent praeguse konfiguratsiooni puhul on pigem soovitav olemasoleva väärtuse ülekirjutamine. + +#### Brauserilaienduste poliitikad Microsoft Intune'i kaudu + +Veebilehitsejate laienduste poliitikaid saab levitada ka Microsoft Intune seadme konfiguratsiooniprofiilide abil, mitte ainult GPO kaudu. + +##### Google Chrome ja Microsoft Edge + +Chrome ja Edge poliitikad põhinevad samadel ADMX mallidel, millele viidati eespool ([Chromium Edge](#chromium-edge), [Google Chrome](#google-chrome)): + +1. Ava Intune halduskeskuses *Devices > Manage devices > Configuration > Create > New policy*. Vali platvormiks *Windows 10 and later* ja profiili tüübiks *Settings catalog*. Chrome'i ja Edge'i sätted on kataloogis olemas ning nende ADMX malle ei ole vaja importida. +2. Seadista laienduse sundinstalli lubav säte (Chrome puhul `Configure the list of force-installed apps and extensions`, Edge puhul `Control which extensions are installed silently`) Web eID laienduse ID-ga: Chrome'i puhul `ncibgoaomkmdpilpocfeponihegamlic`, Edge'i puhul `gnmckgbandlkacikdndelhfghdejfido`. +3. Kui native messaging on piiratud blocklist-poliitikaga, lisa ka `eu.webeid` vastavasse allowlist-sättesse, samamoodi nagu eespool kirjeldatud peatükkides [Chromium Edge](#chromium-edge) ja [Google Chrome](#google-chrome). +4. Määra profiil vajalikele seadme- või kasutajagruppidele. + +##### Mozilla Firefox + +Firefoxi poliitikad ei ole Intune'i sisseehitatud *settings catalog*'i osa: + +1. Laadi alla Firefoxi ADMX mallid (vt [Mozilla Firefox](#mozilla-firefox) eespool). Impordi asukohas *Devices > Manage devices > Configuration > Import ADMX* esmalt `mozilla.admx` koos vastava `mozilla.adml` failiga. Kui nende olek on *Available*, impordi `firefox.admx` koos vastava `firefox.adml` failiga. +2. Loo uus profiil, valides platvormiks *Windows 10 and later* ja profiili tüübiks *Templates > Imported Administrative templates (Preview)*. Seadista `Extension Management` sama JSON väärtusega, mis on kirjeldatud eespool peatükis [Mozilla Firefox](#mozilla-firefox). +3. Määra profiil vajalikele seadme- või kasutajagruppidele. + +> **Märkus:** Nagu GPO puhulgi, testi eespool kirjeldatud konfiguratsioone kindlasti enda keskkonna(s) enne rakendamist. ## Tarkvara uuendamine @@ -316,7 +414,7 @@ ID-tarkvara uuenduste kontrollimisel on kasutusel keskne konfiguratsioon, mille 2. DigiDoc4 programmi startimisel; 3. Käsitsi tarkvarauuenduste otsimine DigiDoc4 rakenduse käivitamisel. -### Automaatkorraldus „id updater task" +### Automaatkorraldus `id updater task` > **Märkus:** See meetod töötab vaid EXE-installatsioonidega — allkirjeldatud registriväärtuseid MSI installatsiooniga ei teki. @@ -328,7 +426,7 @@ ID-tarkvara versiooni 26.4.20.8412 puhul on arvutis olev versioon kirjas registr ![ID-tarkvara versiooni 26.4.20.8412 informatsioon arvuti registris](./img/image28.png) -Genereeritud unikaalne võti (siin: `{DF5112B3-AAE7-44E3-8F9B-B9F33CDE0DC9}`) on iga ID-tarkvara versiooni puhul erinev. Automaatkorralduse `id updater task` käivitamisel laaditakse keskne konfiguratsioon arvuti mällu, loetakse sealt parameeter `WIN-LATEST` ja võrreldakse seda registris oleva parameetriga *DisplayVersion*. Juhul, kui `WIN-LATEST` on suurem kui registris asuva *DisplayVersion* välja väärtus, pakutakse kasutajale tarkvara uuendust. +Genereeritud unikaalne võti (siin: `{5FBF3885-332F-4E02-B7C8-589775D00818}`) on iga ID-tarkvara versiooni puhul erinev. Automaatkorralduse `id updater task` käivitamisel laaditakse keskne konfiguratsioon arvuti mällu, loetakse sealt parameeter `WIN-LATEST` ja võrreldakse seda registris oleva parameetriga *DisplayVersion*. Juhul, kui `WIN-LATEST` on suurem kui registris asuva *DisplayVersion* välja väärtus, pakutakse kasutajale tarkvara uuendust. ### DigiDoc4 käivitamine @@ -344,11 +442,11 @@ Juhul, kui DigiDoc4 versioon kasutaja registriosas väljal *LastVersion* on väi #### Uuem versioon tarkvarast -Juhul, kui DigiDoc4 versioon kasutaja registriosas väljal *LastVersion* on väiksem konfiguratsioonifailis real `QDIGIDOC4-LATEST` kirjeldatud, teavitatakse sellest kasutajat DigiDoc4 programmi käivitamisel: *Saadaval on ID-tarkvara uuendus, mille saad paigaldada veebilehelt id.ee ...*. Kasutajat teavitatakse uuendusest esimesel korral pärast versioonide erinevuse leidmist ja järgnevad teavitused tulevad alles siis, kui keskses konfiguratsioonifailis on tehtud mõni muudatus[^4]. +Juhul, kui DigiDoc4 versioon kasutaja registriosas väljal *LastVersion* on väiksem konfiguratsioonifailis real `QDIGIDOC4-LATEST` kirjeldatud, teavitatakse sellest kasutajat DigiDoc4 programmi käivitamisel: *Saadaval on ID-tarkvara uuendus, mille saad paigaldada veebilehelt id.ee ...*. Kasutajat teavitatakse uuendusest esimesel korral pärast versioonide erinevuse leidmist ja järgnevad teavitused tulevad alles siis, kui keskses konfiguratsioonifailis on tehtud mõni muudatus[^2]. ### Käsitsi uuenduste otsing -Käsitsi ID-tarkvara uuenduste otsinguks tuleb DigiDoc4 programmis avada seaded ja klikkida all ääres oleval tekstil „Kontrolli värskendusi". Selle tulemusena kontrollitakse alati uue konfiguratsioonifaili olemasolu, vajadusel laaditakse see alla ja seejärel võrreldakse seal olevat versiooni arvutis oleva tarkvara versiooniga. Arvuti versioon loetakse analoogselt automaatkorraldusele `id updater task` registri väljast *DisplayVersion* võtme `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5FBF3885-332F-4E02-B7C8-589775D00818}` alt. +Käsitsi ID-tarkvara uuenduste otsinguks tuleb DigiDoc4 programmis avada seaded ja klikkida all ääres oleval tekstil „Kontrolli värskendusi“. Selle tulemusena kontrollitakse alati uue konfiguratsioonifaili olemasolu, vajadusel laaditakse see alla ja seejärel võrreldakse seal olevat versiooni arvutis oleva tarkvara versiooniga. Arvuti versioon loetakse analoogselt automaatkorraldusele `id updater task` registri väljast *DisplayVersion* võtme `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5FBF3885-332F-4E02-B7C8-589775D00818}` alt. ![Värskenduste kontroll DigiDoc4 seadetes](./img/image30.png) @@ -358,7 +456,5 @@ Kui tarkvara uuendus on olemas, pakutakse see kasutajale välja. Kasutajat teavi > **Märkus:** Ka see meetod töötab korrektselt vaid EXE installide puhul. -[^1]: System Center Configuration Manager -[^2]: Active Directory / Group Policy -[^3]: Selle määrangu lubamisel eemaldatakse kasutaja sertifikaadid EID kaardi eemaldamisel Windows sertifikaadihoidlast. -[^4]: Reeglina tehakse keskses konfiguratsioonifailis muudatus kord kuus. +[^1]: Selle määrangu lubamisel eemaldatakse kasutaja sertifikaadid EID kaardi eemaldamisel Windows sertifikaadihoidlast. +[^2]: Reeglina tehakse keskses konfiguratsioonifailis muudatus kord kuus. diff --git a/admin/index.md b/admin/index.md index fee94e5..7f5f48a 100644 --- a/admin/index.md +++ b/admin/index.md @@ -2,7 +2,7 @@ **[Eesti keeles (In Estonian)](index.et.md)** -**Version:** 26.04/1 +**Version:** 26.07/1 **Published by:** [RIA](https://www.ria.ee/) @@ -30,6 +30,8 @@ | 16/06/2025 | 25.06/1 | Replaced AWP with IDPlug. — Changed by: Raul Metsma | 31/10/2025 | 25.10/1 | Added SmartCard Client. — Changed by: Raul Kaidro | 19/05/2026 | 26.04/1 | Published as online documentation. Added Edge NativeMessagingAllowlist configuration. — Changed by: Raul Metsma +| 11/06/2026 | 26.06/1 | Updated GPO-MSI distribution guidance and screenshots. — Changed by: Raul Metsma +| 29/07/2026 | 26.07/1 | Added Microsoft Intune deployment guidance for the ID-software and for central extension management. — Changed by: Raul Metsma --- @@ -79,15 +81,15 @@ When it is installed and the smart card is removed from the card reader, all ID- #### Digidoc_ShellExt -This component allows starting signing and encryption in DigiDoc4 by right-clicking on the file. +This component installs the legacy Windows Explorer context-menu extension, which allows signing or encryption to be started in DigiDoc4 by right-clicking a file. On Windows 11, commands provided by this extension appear under *Show more options*. If the extension has already been loaded into Windows Explorer, installing or updating it may require restarting Explorer or the computer. #### DigiDoc4 -DigiDoc4 is an application that enables the signing, validation, encryption, and decryption of documents as well as managing the PINs and PUKs of ID-cards. +DigiDoc4 is an application that enables the signing, validation, encryption, and decryption of documents as well as managing the PINs and PUKs of ID-cards. Both the DigiDoc4 MSI and the Microsoft Store app install the modern Windows Explorer context-menu extension; the MSI does so through an AppX-based solution. #### ID-updater -ID-updater is a mandatory component that bundles shared third-party libraries (Qt, OpenSSL, etc.) required by other ID-software components. During installation, the task scheduler task `id updater task` is created, which checks the availability of new software once per week and suggests any identified updates to the user. +The ID-software EXE installer always installs ID-updater, which bundles shared third-party libraries (Qt, OpenSSL, etc.) required by other ID-software components. By default, the EXE installer also creates the scheduled task `id updater task`, which checks for new software once per week and offers any available update to the user. Creating the scheduled task can be disabled with `AutoUpdate=0`, but ID-updater is still installed. ID-updater is not required when the ID-software components are installed as separate MSI packages. ![Example: ID-updater found a newer version of the software (EST)](./img/image3.png) @@ -97,18 +99,18 @@ Web eID allows Estonian ID-cards to be used for online authentication and signin ### In enterprises -In large and medium enterprises, the ID-software is usually installed and controlled centrally by a central management solution. SCCM[^1] and AD/GP[^2] are most common. +In medium and large organizations, ID-software is usually deployed and managed centrally. Common solutions include Microsoft Intune, Microsoft Configuration Manager (SCCM), and Active Directory Group Policy (AD/GPO). #### SCCM In addition to the configuration options available in the GUI, the following command-line parameters can be used for unattended installations: -1. `ChromeSupport=0` — the Chrome extension is not added, 1 by default. -2. `EdgeSupport=0` — the Edge extension is not added, 1 by default. +1. `ChromeSupport=0` — the Chrome extension, registry entries, and native messaging manifest are not installed, 1 by default. +2. `EdgeSupport=0` — the Edge extension, registry entries, and native messaging manifest are not installed, 1 by default. 3. `ForceChromeExtensionActivation2=1` — the Chrome extension is activated automatically, 1 by default. 4. `ForceEdgeExtensionActivation2=1` — the Edge extension is activated automatically, 1 by default. -5. `FirefoxSupport=0` — the Firefox extension is not added, 1 by default. -6. `InstallCertSynchronizer=1` — installs the component `OTCertSynchronizer`, 0 by default[^3]. +5. `FirefoxSupport=0` — the Firefox extension, registry entries, and native messaging manifest are not installed, 1 by default. +6. `InstallCertSynchronizer=1` — installs the component `OTCertSynchronizer`, 0 by default[^1]. 7. `MinidriverInstall=0` — the minidriver is not installed, 1 by default. 8. `Qdigidoc4Install=0` — the DigiDoc software is not installed, 1 by default. 9. `IconsDesktop=0` — the DigiDoc icon is not put on the desktop, 1 by default. @@ -116,6 +118,8 @@ In addition to the configuration options available in the GUI, the following com > **Note:** The installation keys shown above are case sensitive. +> **Note:** If `ChromeSupport`, `EdgeSupport`, and `FirefoxSupport` are all set to 0, the native messaging application is not installed either. + For example, the command line `Open-EID-.exe /quiet AutoUpdate=0 IconsDesktop=0` installs the ID-software in unattended mode, does not activate automatic updates, and does not add the ID-software icons to the desktop. By default, running the EXE installs the software with default settings. @@ -130,7 +134,7 @@ As a result of this normal installation, the ID-software appears as usual in the If you do not have a central software management system in the enterprise, but you can use the *Group Policy* functionality, you can also use MSI-based installations. It is recommended to make GPO installations computer-based. -> **Note:** By default, MSI installations are intended only for new installations. MSI components do not remove any previous (or current) versions of EXE installations. +> **Note:** MSI packages can be used for both initial deployment and centrally managed updates. They do not automatically remove or migrate an existing EXE-based installation to MSI-based management. When moving from an EXE-based installation to MSI-based management, uninstall the EXE-based installation separately. For subsequent MSI updates, deploy the newer component packages through the central management solution and test the release-specific upgrade behavior before rollout. For an overview of the MSI components, see [Brief overview of the components](#brief-overview-of-the-components) above. @@ -146,15 +150,7 @@ The MST files described below in the manual can be downloaded from the location Below is a brief overview about how to configure GPO-MSI installations. -##### ID-updater - -ID-updater is a mandatory component. It is recommended to install it first. - -Options: - -- If you do not want to activate the automatic software update functionality (deferred `id updater task`), use the transform file `2410-no_autoupdate.mst` with this MSI installation. And it probably makes sense to disable it, since MSI installations don't support software update checking in this way. - -![Sample about adding a transform file to the MSI installation](./img/image6.png) +> **Note:** Compared to earlier versions of this guide, `ID-updater` no longer needs to be installed for GPO-MSI deployments, and components no longer need transform files that force installation into the same `PROGRAM FILES\Open-EID` folder. ##### IDPlug @@ -181,26 +177,19 @@ DigiDoc4 is a necessary component if you want to sign and encrypt documents as w Options: -- For GPO-MSI installations, it is necessary to use the transform file `2410-DD-Location.mst`. In this case, the software is installed in the same folder `PROGRAM FILES\Open-EID` as the necessary drivers. - The default MSI installation does not install the necessary icons on the desktop. However, if desktop icons are required, the transform file `2410-DD-Shortcut` must also be added to the installation. -![Adding transform files for MSI installation](./img/image7.png) - -##### Adding right-click signing and encryption to Windows +The DigiDoc4 MSI installs the modern Windows Explorer context-menu extension through an AppX-based solution. -Enables right-click signing and encryption of files in Windows Explorer. - -Options: +![Adding transform files for MSI installation](./img/image7.png) -- For GPO-MSI installations, it is necessary to use the transform file `2410-DD-Shell-Location.mst`. In this case, the software is installed in the same folder `PROGRAM FILES\Open-EID` as the necessary drivers. +##### Adding the legacy right-click extension to Windows -![Sample of adding a transform file to a GPO-MSI installation](./img/image8.png) +The `Digidoc_ShellExt` MSI installs the legacy Windows Explorer context-menu extension. On Windows 11, commands provided by this extension appear under *Show more options*. Use it only when the legacy extension is required instead of the modern extension included with the DigiDoc4 MSI. If the legacy extension has already been loaded into Explorer, installing or updating it may require restarting Explorer or the computer. ##### Web eID -Browser extensions and native app. For GPO-MSI installations, it is necessary to use the transform file `2410-Web-Location.mst`. In this case, the software is installed in the same folder `PROGRAM FILES\Open-EID` as the necessary drivers. - -![Sample of adding a transform file to a GPO-MSI installation](./img/image9.png) +Browser extensions and native app. The list of MSI custom packages in the GPMC management console looks like this: @@ -210,23 +199,101 @@ For GPO-MSI installations, all installed programs also appear in the software li ![MSI installations in the program list of the Control Panel](./img/image11.png) -> **Note:** The order of MSI installation components is not important, but all components depend on the MSI `Open-EID updater`. The minidriver is also important, as other components depend on it. +> **Note:** The order of MSI installation components is not important, but the required minidriver must be installed because other components depend on it. > **Note:** MST files can be downloaded from . > **Note:** It is also recommended to publish the related root and intermediate certificates in the domain to all servers and workstations automatically through the group policies. +#### Microsoft Intune application deployment + +If you manage devices with Microsoft Intune, deploy the individual MSI packages described above as Win32 apps. `ID-updater` is not required for MSI deployments. + +To package an MSI component for Intune deployment: + +1. Download the *Microsoft Win32 Content Prep Tool* (`IntuneWinAppUtil.exe`) from . +2. Put the component MSI and any required MST files in a separate source folder. +3. Package the MSI into a `.intunewin` file using the tool. +4. In the Intune admin center, go to *Apps > All apps > Create*, choose the app type *Windows app (Win32)*, and upload the resulting `.intunewin` file. + +When run without command-line arguments, `IntuneWinAppUtil.exe` prompts for the source folder, setup file, and output folder. It also accepts command-line arguments, which are useful for scripting the packaging step: + +``` +IntuneWinAppUtil.exe -c Source -s "" -o Out -q +``` + +- `-c` — source folder (all files needed for installation) +- `-s` — component MSI file to install +- `-o` — output folder for the resulting `.intunewin` file +- `-q` — quiet mode, suppresses the interactive prompts (e.g. no confirmation is asked before overwriting an existing output file) + +The install command, uninstall command, and detection rule are entered in the app creation wizard in the Intune admin center. The filenames below are placeholders; replace them with the actual versioned filenames from the downloaded `Open-EID.zip`: + +- *Program* tab: + - Install command, for example: `msiexec /i "" /quiet` + - Uninstall command: `msiexec /x "{PRODUCT-CODE}" /quiet` + - Install behavior: *System* +- *Detection rules* tab — choose *Manually configure detection rules*, add an *MSI* rule, enter the release-specific MSI product code, and enable the MSI product version check. +- *Assignments* tab — assign the app to the desired device or user groups as *Required* to have it install automatically. + +> **Note:** `{PRODUCT-CODE}` is a placeholder. When an MSI is selected as the setup file (`-s`), the Content Prep Tool reads its metadata and Intune can use the product code in an MSI detection rule. Verify the value shown in Intune and use the same GUID in the uninstall command. To inspect it before packaging, open the MSI in [Orca](https://learn.microsoft.com/en-us/windows/win32/msi/orca-exe), select the `Property` table, and read the `Value` in the `ProductCode` row. Product codes can differ between versions, architectures, and language packages, so concrete GUIDs are not listed in this guide. + +Transform files are passed to MSI using the `TRANSFORMS` property, for example: + +``` +msiexec /i "" TRANSFORMS=DisableIDPlugServices.mst /quiet +``` + +If MSI components are deployed as separate Win32 apps, configure the required minidriver app as a dependency of the components that need it. + +> **Note:** The MSI components and transform files are the same as described in [AD/GPO](#adgpo) above. + +##### Choosing how to deploy DigiDoc4 + +DigiDoc4 can be deployed either from Microsoft Store or as an MSI-based Win32 app. Use only one of these methods for a device group. + +###### Option 1: Microsoft Store + +DigiDoc4 is available from [Microsoft Store](https://apps.microsoft.com/detail/9pfpfk4dj1s6). To deploy it through Intune, go to *Apps > All apps > Create*, choose *Microsoft Store app (new)*, and search for `DigiDoc4` or Store product ID `9PFPFK4DJ1S6`. The app can then be assigned as *Required* or *Available for enrolled devices*. + +The Store app provides DigiDoc4, including its file associations and the modern Windows Explorer context-menu extension. It does not replace the ID-card minidriver or the Web eID native application and browser extensions. Deploy these required components separately using the MSI packages described above. + +Apps deployed from Microsoft Store through Intune are kept up to date automatically. Use this option when automatically receiving the latest DigiDoc4 release is acceptable; use the MSI-based Win32 deployment described above when each DigiDoc4 version must be tested and approved before rollout. + +###### Option 2: MSI-based Win32 app + +Package the DigiDoc4 MSI as described above. The MSI installs the modern Windows Explorer context-menu extension through an AppX-based solution. To add desktop shortcuts, include the `2410-DD-Shortcut.mst` file in the source folder and use: + +``` +msiexec /i "" TRANSFORMS=2410-DD-Shortcut.mst /quiet +``` + +The `Digidoc_ShellExt` MSI is not required for the modern context-menu extension. Deploy it separately only when the legacy Windows Explorer context-menu extension is required. On Windows 11, commands provided by this extension appear under *Show more options*. If the legacy extension has already been loaded into Explorer, installing or updating it may require restarting Explorer or the computer. The MSI-based option lets the organization test and approve each DigiDoc4 version before rollout, but updates must be managed in Intune. + +##### Updating an Intune deployment + +Microsoft Store updates DigiDoc4 automatically when the Store option is used. For MSI-based Win32 apps, publish each approved component update through Intune: + +1. Create a new `.intunewin` package from the new component MSI. +2. Update the install and uninstall commands, MSI product code, and product version detection. +3. Create a new Win32 app or update the existing app content. When creating a new app, configure it to supersede the previous version. If testing confirms that the new MSI upgrades the installed version in place, set *Uninstall previous version* to *No*; use *Yes* only when the previous package must be removed before installing the new one. +4. Test the deployment and then assign the new version to the required groups. + +Intune is responsible for deploying subsequent releases of all MSI-based ID-software components. + ### Deploying extensions centrally -Browser extensions can also be deployed centrally via Group Policy. +Browser extensions can be deployed centrally via Group Policy or Microsoft Intune. Please test configurations described below in your specific environment(s) before deployment. -#### Chromium Edge +#### Browser extension policies via AD/GPO + +##### Chromium Edge For Edge, you need to download the newest Edge policy framework from and integrate it into your environment. -After enabling policies, you can create a new policy that makes the use of the Web eID extension automatic in the domain. For that, set the value of the field `CC/Administrative Templates/Microsoft Edge/Extensions — 'Control which extensions are installed silently'` to `gnmckgbandlkacikdndelhfghdejfido`. +After enabling policies, you can create a new policy that makes the use of the Web eID extension automatic in the domain. For that, set the value of the field `Computer Configuration/Policies/Administrative Templates/Microsoft Edge/Extensions — Control which extensions are installed silently` to `gnmckgbandlkacikdndelhfghdejfido`. ![The Edge extension ID is gnmckgbandlkacikdndelhfghdejfido](./img/image12.png) @@ -234,11 +301,11 @@ After enabling policies, you can create a new policy that makes the use of the W ![Policy information in the registry](./img/image14.png) -##### Additional possible configuration in the 'native messaging' view +###### Additional configuration for `native messaging` By default, all native messaging hosts are allowed in Edge. However, if the `NativeMessagingBlocklist` policy is set to `*`, Web eID signing will not work. To resolve this, `eu.webeid` must be added to the `NativeMessagingAllowlist` policy. For more information, see the [NativeMessagingAllowlist](https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/nativemessagingallowlist) Edge policy documentation. -#### Google Chrome +##### Google Chrome The Chrome policy is set during the installation of the ID-software. The following information written to the registry enables the Web eID extension in Chrome automatically: @@ -248,7 +315,7 @@ However, if you want to centrally manage policies in Chrome, the following instr To enable the Chrome extensions policies centrally, you need to download the newest template files from and integrate those into the domain solution. -After enabling policies, you can create a new policy that makes the use of the Web eID extension automatic in the domain. For that, set the value of the field `CC/Administrative Templates/Google/Google Chrome/Extensions — 'Configure the list of force-installed apps and extensions'` to `ncibgoaomkmdpilpocfeponihegamlic`. +After enabling policies, you can create a new policy that makes the use of the Web eID extension automatic in the domain. For that, set the value of the field `Computer Configuration/Policies/Administrative Templates/Google/Google Chrome/Extensions — Configure the list of force-installed apps and extensions` to `ncibgoaomkmdpilpocfeponihegamlic`. ![Chrome Web eID extension ID is ncibgoaomkmdpilpocfeponihegamlic](./img/image16.png) @@ -256,11 +323,14 @@ After enabling policies, you can create a new policy that makes the use of the W ![Policy information in the registry](./img/image18.png) -##### Additional possible configuration in the 'native messaging' view +###### Additional configuration for `native messaging` -If the `Configure native messaging blocklist` property is set to `*` with Chrome policies, signing using the Chrome extension described above will not work. For example, on the test page , the result when attempting to sign is the error `getCertificate() failed: Error: technical_error`. +If the `Configure native messaging blocklist` property is set to `*` with Chrome policies, signing using the Chrome extension described above will not work. For example, attempting to sign on the test page produces the following output: -![Error while attempting to sign](./img/image19.png) +``` +Debug: hwcrypto.js 0.0.13 with failing backend Chrome native messaging extension +getCertificate() failed: Error: technical_error +``` To overcome this problem, the host `eu.webeid` must be allowed in the Chrome policy `Configure native messaging allowlist`: @@ -268,9 +338,14 @@ To overcome this problem, the host `eu.webeid` must be allowed in the Chrome pol After applying the policy, signing on the webpage succeeds. -![Signing on the page succeeds](./img/image21.png) +``` +Debug: hwcrypto.js 0.0.13 with Chrome native messaging extension 2.0.1/2.0.0.552 +Using certificate: +-----BEGIN CERTIFICATE----- +... +``` -#### Mozilla Firefox +##### Mozilla Firefox The Firefox policy is already set during the installation of the ID-software; the information reflected in the following image is written into the Windows registry. Using the aforementioned policy, the Web eID extension is automatically installed on Firefox: @@ -280,7 +355,7 @@ However, if you want to centrally manage policies for Firefox, the information b To use central policies for Firefox, you need to download the newest Firefox administrative templates from and integrate them to the domain solution. -After introducing the policies to the domain environment, you can create a new policy that makes the use of the Web eID extension for Firefox automatic in the domain. There are several options for this, but it is perhaps advisable to overwrite the policy already described during the installation. To do this, set the value of the field `CC/Administrative Templates/Mozilla/Firefox/Extensions — 'Extension Management'` to the following text: +After introducing the policies to the domain environment, you can create a new policy that makes the use of the Web eID extension for Firefox automatic in the domain. There are several options for this, but it is perhaps advisable to overwrite the policy already described during the installation. To do this, set the value of the field `Computer Configuration/Policies/Administrative Templates/Mozilla/Firefox/Extensions — Extension Management` to the following text: ```json { @@ -300,7 +375,7 @@ The corresponding information is written into the registry in the same place as If you want to prevent the user from turning off the Web eID extension independently, one of the actions from the following list must be performed: 1. Replace the text `normal_installed` with the text `force_installed` in the value of the field described above; -2. Add the line `{e68418bc-f2b0-4459-a9ea-3e72b6751b07}` to the list `CC/Administrative Templates/Mozilla/Firefox/Extensions — 'Prevent extensions from being disabled or removed'`. +2. Add the line `{e68418bc-f2b0-4459-a9ea-3e72b6751b07}` to the list `Computer Configuration/Policies/Administrative Templates/Mozilla/Firefox/Extensions — Prevent extensions from being disabled or removed`. ![Preventing the Firefox Web eID extension from being disabled](./img/image25.png) @@ -308,7 +383,30 @@ After applying either of these policies, the user can no longer disable the Fire ![The Web eID extension is always on](./img/image26.png) -In addition, you can install the extension using the list `CC/Administrative Templates/Mozilla/Firefox/Extensions — 'Extensions to install'`, but for the current configuration, it is preferred to overwrite the existing value. +In addition, you can install the extension using the list `Computer Configuration/Policies/Administrative Templates/Mozilla/Firefox/Extensions — Extensions to install`, but for the current configuration, it is preferred to overwrite the existing value. + +#### Microsoft Intune browser extension policies + +Browser extension policies can also be pushed through Microsoft Intune device configuration profiles instead of Group Policy. + +##### Google Chrome and Microsoft Edge + +Chrome and Edge policies are backed by the same ADMX templates referenced above ([Chromium Edge](#chromium-edge), [Google Chrome](#google-chrome)): + +1. In the Intune admin center, go to *Devices > Manage devices > Configuration > Create > New policy*. Select *Windows 10 and later* as the platform and *Settings catalog* as the profile type. Chrome and Edge settings are built into the catalog, so their ADMX templates do not need to be imported. +2. Configure the force-install extension setting (`Configure the list of force-installed apps and extensions` for Chrome, `Control which extensions are installed silently` for Edge) with the Web eID extension ID: `ncibgoaomkmdpilpocfeponihegamlic` for Chrome, `gnmckgbandlkacikdndelhfghdejfido` for Edge. +3. If native messaging is restricted with a blocklist policy, also add `eu.webeid` to the corresponding allowlist setting, the same as described above for [Chromium Edge](#chromium-edge) and [Google Chrome](#google-chrome). +4. Assign the profile to the required device or user groups. + +##### Mozilla Firefox + +Firefox policies are not part of the built-in Intune settings catalog: + +1. Download the Firefox ADMX templates (see [Mozilla Firefox](#mozilla-firefox) above). In *Devices > Manage devices > Configuration > Import ADMX*, first import `mozilla.admx` with the matching `mozilla.adml`. After their status is *Available*, import `firefox.admx` with the matching `firefox.adml`. +2. Create a new profile with the platform *Windows 10 and later* and profile type *Templates > Imported Administrative templates (Preview)*. Configure `Extension Management` with the same JSON value described in the [Mozilla Firefox](#mozilla-firefox) section above. +3. Assign the profile to the required device or user groups. + +> **Note:** As with GPO, test the configurations described above in your specific environment(s) before deployment. ## Updating the software @@ -318,7 +416,7 @@ Central configuration is used for checking ID-software updates. The process comp 2. Starting the DigiDoc4 program; 3. Running a manual search for software updates when launching the DigiDoc4 application. -### Scheduled task 'id updater task' +### Scheduled task `id updater task` > **Note:** This method only works with EXE installations — the registry values described below are not created with an MSI installation. @@ -330,7 +428,7 @@ For ID-software version 26.4.20.8412, the version of the software can be found i ![ID-software version 26.4.20.8412 in the registry](./img/image28.png) -The generated unique key (here: `{DF5112B3-AAE7-44E3-8F9B-B9F33CDE0DC9}`) is different for each ID-software version. When the scheduled task `id updater task` is started, the central configuration is loaded into the computer's memory, the `WIN-LATEST` parameter is read from there and compared with the `DisplayVersion` parameter in the registry. If the `WIN-LATEST` is greater than the value of the `DisplayVersion` field in the registry, the user is offered a software update. +The generated unique key (here: `{5FBF3885-332F-4E02-B7C8-589775D00818}`) is different for each ID-software version. When the scheduled task `id updater task` is started, the central configuration is loaded into the computer's memory, the `WIN-LATEST` parameter is read from there and compared with the `DisplayVersion` parameter in the registry. If the `WIN-LATEST` is greater than the value of the `DisplayVersion` field in the registry, the user is offered a software update. ### Starting DigiDoc4 @@ -346,7 +444,7 @@ If the DigiDoc4 version in the *LastVersion* field in the user's registry sectio #### Newer version of software -If the DigiDoc4 version in the *LastVersion* field of the user's registry section is smaller than the one described in the `QDIGIDOC4-LATEST` line of the central configuration file, the user will be informed of this after starting the DigiDoc4 program: *An ID-software update has been found. To download the update, go to ...*. The user is notified of the update the first time a version difference is found, and subsequent notifications are only sent when changes have been made to the central configuration file.[^4] +If the DigiDoc4 version in the *LastVersion* field of the user's registry section is smaller than the one described in the `QDIGIDOC4-LATEST` line of the central configuration file, the user will be informed of this after starting the DigiDoc4 program: *An ID-software update has been found. To download the update, go to ...*. The user is notified of the update the first time a version difference is found, and subsequent notifications are only sent when changes have been made to the central configuration file.[^2] ### Manual update search @@ -360,7 +458,5 @@ If a software update is available, it will be offered to the user. The user will > **Note:** This method also works correctly only for EXE installations. -[^1]: System Center Configuration Manager -[^2]: Active Directory / Group Policy -[^3]: If this setting is enabled, the user's certificates are removed from the Windows certificate store when the EID card is removed. -[^4]: Usually, changes are made to the central configuration file once a month. +[^1]: If this setting is enabled, the user's certificates are removed from the Windows certificate store when the EID card is removed. +[^2]: Usually, changes are made to the central configuration file once a month.