A setup program performs the installation of the Client Software quickly and smoothly. The installation procedures for all versions of NCP Client Software are the same. The following text describes the procedures for installing the Client Software under Windows XP, Vista, Windows 7 and Windows 8.
Prior to executing installation, make sure that the following prerequisites are fulfilled.
Starting with version 8.31 the Client will be installed in the program directory of the operating system (programs\NCP\SecureClient) for a new installation.
Old path: %Windows%\ncple
New path: %Programs%\NCP\SecureClient
For an update the path which was entered for the last installation will continue to be used.
UninstallIf you uninstalled the client, you have the option to keep the configuration and profile settings in the client directory. If at a later date, a newer client version is installed in the same directory, all personal data can be used again. If you want to delete the personal data in the client, you have to confirm this specifically. In such a case all data and directories of the client are removed irretrievably.
Registry repair (RegRep)The setup program checks the registry entries for each new installation of the client, i.e. even when an older version was uninstalled. If problematic entries are found, they will be altered as necessary. The setup program then generates a message requesting a restart of the PC.
Microsoft Windows XP, Windows Vista, Windows 7 or Windows 8 must be installed on your PC (min. 128 MB RAM). Before starting the installation, ensure that the operating system installation disks are available, as these may be needed for updating your PC's driver database files; insert these disks when prompted to do so.
Important: when updating from Windows 7 to Windows 8
When updating from Microsoft Windows 7 to Microsoft Windows 8, it is vital that the NCP Secure Client be de-installed before starting the update. It is also recommended that backup copies be made of any configuration files and certificates used. When the update to Windows 8 is complete, the latest version of the NCP Secure Client should then be downloaded from the NCP website and installed. Failure to de-install the NCP Secure Client before updating to Windows 8 could subsequently lead to having to carry out a new install of Windows 8.
Remote Destination:The remote destination has to support one of the following communication media: ISDN, PSTN (analog modem), GSM, GPRS/3G, LAN over IP, Wi-Fi or PPP over Ethernet (PPPoE).
Local System:One of the following communication devices must be properly installed
ISDN adapter (ISDN)The secure client can be used in public key infrastructures as of X.509. V.3 standard and supports the following interfaces/formats:
- Smartcards, USB-Tokens: PKCS#11, TCOS 1.2 and 2.0, CSP
- Soft Certificates: PKCS#12-file
- PC/SC conform chip card reader: The client software supports all chip card readers which conform with PC/SC. The chip card readers are included in a list of the client once the reader is connected and the corresponding driver software has been installed.
- Automatic recognition of connected PC/SC readers: If the use of a PC/SC chip card reader is configured on the client for the PKI environment, the client recognizes and automatically uses the connected one.
- PKCS#11 module: Drivers in form of a PKCS#11 library (DLL) are supplied with the software for smartcards or tokens. This driver software has to be installed initially. Then the relevant PKSC#11 module can be selected via a wizard.
The administrator of the company network determines which certificate issuers can be trusted. This happens by importing the CA certificate of his choice into the installation directory under
Retrospectively, issuer certificates can be distributed automatically via the Secure Management Server (only to Enterprise Clients) or the user can save them himself as long as he has the appropriate write rights in the respective directory.
Currently the formats *.pem and *.crt are supported for issuer certificates. They can be viewed in the monitor under the main menu item "Connection / Certificates / Display CA Certificates".
If the secure client receives the certificate of a remote station, then the NCP client will determine the issuer by searching for the issuer certificate initially on smartcard or USB token or in the PKCS#12 file and finally in the installation directory under
If soft certificates are created with the PKI plug-in of the management server, the issuer certificate is saved in the PKCS#12 file.
The secure client can have access to the corresponding CRL (certificate revocation list) for each issuer certificate. It is applied to the installation directory under
If revocation lists are used, then usually there is no notification if the client has no revocation list for incoming certificates on his PC. If a notification is required in such cases then the file NCPPKI.CONF needs to be edited. It is saved in the installation directory. The default entry in the section [General] is:
Enablecrlinfo = 0
This means that no notifications are displayed if, on the client at the remote station, no revocation list was found for the certificate. If a notification has to be displayed, then this setting has to be changed to:
Enablecrlinfo = 1
First the NCP Secure Entry Client is always installed as a test version. If you possess a license, you can enter the license data after a reboot of the software by selecting the monitor menu option "Help/ License Data and Activation". The test version is valid for 30 days. Without software activation or licensing it will no longer be possible to setup a connection after this 30-day period expires. When 10-days validity remain, a message box will be displayed to remind you that the software has not yet been licensed. For licensing the software please refer to the chapter "License Data and Activation" in the handbook.
Save the ZIP file you have downloaded onto your PC. The filename of the ZIP file displays the number of the version and the build number of the software, e. g.:
SecEntryClientWinx_xx_yyy.ZIP
(x_xx = Release, yyy = Build)
Extract the ZIP file. After that in the directory SecEntryClientWinx_xx_yyy you can start NCP_EntryCl_Win_xxx_yyy.exe.
Once you have installed the Client Software and rebooted your PC, the Client Monitor will be automatically started on your PC. The "Initial Configuration Assistant" will also be displayed, provided that you have installed the Client Software for the first time on your PC or you have deleted the profile settings. They are located in the installation directory.
If you do not use the assistant for creating such a test profile, then no entries will be added to the profile list. In this case you will have to create your own profiles, as described in the chapter "Client Monitor" fo the manual. If you use the assistant, click on "Next". Then an IPsec test profile will be added to the client's profiles and the assistant will guide you through the definition of generic parameters. The following access data are created automatically: VPN protocol is IPsec, the Tunnel Endpoint of the VPN gateway is: vpntest.ncp-e.com, XAUTH user ID and password is "ncpIPsecnative". The IP address of the DNS server is 172.16.12.100. The communication medium is LAN. If a connection via an ISP should be established, the parameters for dial-up must be configured in the profil settings of the test connection. Setting up the variant with strong security you can use the test certificate enclosed. The PIN of the test certificate is "1234" and has to be entered when establishing the connection. Once you have saved the test configuration, you can set up immediately a test connection (in LAN mode) by clicking the "Test" button. For further configuration of a profil refer the description under "Client Monitor, Profil Settings" and "Configuration Parameters, IPsec Settings".Network Tests are an option the Client Monitor's Help Menu and these can be used to test Internet availability. They support both PING to an IP Address in the Internet as well as resolution of an Internet Domain Name to an IP address. Domain names should be of the form "ncp-e.com".
Enter the address and press the corresponding Test button. The test results are displayed via a symbol (success: green tick, failure: red cross). More details are displayed in a clear text log. The tests are particularly useful for testing firewall rules for DNS requests and outgoing connections to the Internet.After the test connection and the tunnel to the VPN gateway has been established you can execute the following tests.
The "Help" Monitor menu item shows the software version, and possibly the licensed version with serial number under the menu option "License Data and Activation".
The client software is always installed as a test version if the client software has not yet been installed, or if there is a previously installed older version, which has not yet been activated. This also applies if an older version has already been licensed - then this older version will be reset to the status of a test version, and the license data must be re-entered within 30 days using the activation dialog. The time remaining until software activation, i.e. the validity period of the test version, is displayed in the message bar of the monitor next to the activation button. In order to use a full version with no time limitations the software must be released in the activation dialog with the license key and the serial number that you have received. With activation you accept the license conditions that you can view in the activation dialog after clicking on the appropriate button. The activation dialog can be opened using the activation button in the message bar of the monitor, as well as using the the monitor menu "Help / License Data and Activation". The license data can be entered either online or offline using a wizard. In the offline version, a file that is generated after entering the license key and serial number has to be sent to the NCP authentication server, and the activation key that will be displayed on the web site has to be recorded. This activation key can be entered in the licensing window of the Monitor menu at a later point in time. In the online version, a wizard forwards the licensing data to the web server immediately after entry and in this way the software is released immediately.The test version is valid for 30 days. Without software activation or licensing it will no longer be possible to set up a connection after this 30-day period expires.
After installation, each time the software is started the validity period will be shown in the pop-up window. Moreover in a footer of the monitor the system will display how long the test version can still be used, and when 10-days validity remain, a message box will be displayed to remind you that the software has not yet been licensed. This message box will appear once a day. When the trial period has expired, only those connections can be setup with the Entry Client software that are used for software activation/licensing. Thus one of the profiles of the Entry Client can be used to set-up an Internet connection for licensing purposes. Or a connection to the NCP Secure Enterprise Management can be established in order to download a licensed version of the software. Important:Activation of the Client Software under Windows Vista requires a license key of version 9.0 at least. If you are entitled to a free-of-charge update to version 9.0, you receive the affiliated license key when carrying out software activation. In order to purchase the update to version 9.0 please contact your reseller.
When the test phase has expired the software must be either activated or de-installed.
To activate, select the menu option "License data and Activation" in the monitor menu "Help".Here you can see which software version you have and how the software is licensed, i.e. you can see that the test version has expired and that the software has not yet been activated/licensed. Click on the license conditions to display the license agreement text. By activating/ licensing the software you accept the license conditions. Click on the "Activation" button to license the software. In the window that appears, select whether you wish to activate the client online or offline by selecting "Online Activation" or "Offline Activation". In the offline version, a file that is generated after entering the license key and serial number has to be sent to the NCP activation server, and the activation key that is then displayed on the web site must be noted. In the online version, a wizard forwards the licensing data to the web server immediately after entry and in this way the software is released immediately. After selecting the type of activation the license data is to be entered in the appropriate fields. Click on "Next"!With the online version the license data will be transmitted to the NCP Activation Server via an internet connection. This Internet connection can either be established via the Data Communications Dialer, via DSL, or via the Entry Client.
If the Internet connection is not set up via the Entry Client, the connection must first be established in order to then start the activation wizard via the Monitor menu option, "Help" / License Data and Activation". If the Entry Client is used to set up the connection to the internet, a suitable profile must first be established for the Entry Client. Ensure that port 80 is released (for HTTP) if the firewall is activated. (If a proxy server has been configured in the operating system, then these settings can be transferred.) After the profile has been selected, click on "Next" to continue. The internet connection via the Entry Client does not have to be set up prior to activation. It is set up automatically after the desired existing profile has been selected in the assistant for software activation, and after clicking on the "Next" button. The software is activated automatically in the specified sequence: As soon as the activation server detects that you are entitled to a newer software license and that the license key agrees with the installed software, then with online activation the new license key will be transferred automatically (license update), and in this way the new features of the software will be released. Please see the section "Updates" at the end of this section for more information. After concluding the activation process, in the window for the license data you can see that you now have a correctly activated full version. The number of the software version and of the licensed version should not differ. If they do, the license has to be updated with a newer license key. To do this click on the "Licensing" button. For more information see the description at the end of the offline version.The offline version is executed in two steps. In the first step a file is generated after entering the license key and serial number, and is sent to the NCP activation server. The URL is:
http://www.ncp-e.com/en/support/software-activation.html
An activation key will be shown on the web site, and you have to write down this number in order to enter the license key in the licensing window of the monitor menu in a second step. This can also be executed at a later point in time.
If the menu item "Search for Updates" is called, a new dialog is displayed via which the search cycle (never, daily, weekly, monthly) can be configured. In addition there is a new button "Search now".
Under the menu option "Check for Updates" in the Monitor menu under "Help" you can check whether a version of the software that is newer than the version you have installed is available at NCP. This is also possible if a test installation has been installed. If a newer version is available at NCP, then a software update is always possible.
The software update has to be purchased if the newer version is a major release, which is indicated by the change on the first decimal place. For example: If a version 8.26 is installed and the next software version has the number 8.3 then a software update from 8.26 to 8.3, as well as use of the new features, has to be purchased. The new features can only be used if the new license key was activated as described above under software activation. The new license key is generated by entering the serial number and the update key that can be purchased locally from the reseller, on the following web site: http://www.ncp-e.com/en/support/update-key.html The software update always available free of charge if the newer version is a service release, which is indicated by the change of the second decimal place. For example: If version 8.26 is installed and the next software version has the number 8.27, then a software update from 8.26 to 8.27, as well as use of the new features, is free of charge. The new features can be used without activation with 8.2x license key, as soon as the new software has been installed. A service release contains bug fixes, an extension of hardware support and compatibility extensions.After you have selected the menu option "Check for Updates" the software update wizard opens, which helps you to search for available updates. You need an internet connection in order to do so. If the Entry Client is be used to set up the internet connection, ensure that port 80 (for HTTP) is released if the firewall is enabled.
If a proxy server is to be configured in the operating system, these settings can be transferred. If the proxy settings are correctly configured, click on "OK". The wizard now searches for newly available software updates via the internet connection. If a software update is available, it is displayed. (It may well be that the versions only differ in regard to the build number.) Click on "Next" if you want to use the more current version. This downloads the installation package for the latest software. Click on "Finish" to end the Monitor and start the installation of the software update. After starting the Install Shield Wizard select the installation language (as you would for the standard installation), and then confirm the update process with "Yes". Then the installation will be executed automatically. It is concluded when you reboot the computer.If you are already using a previous version of the Software it will be detected when attempting to install the new Client Software. If this is the case, you will be asked if you wish to update your current Client Software to the newer version now in your possession. During the update the current profile settings, certificate data and call control manager statistics will be applied to the new client. (If other programs are still running, they will be stopped.)
In order to uninstall the Client Software go to: "Start / Settings /Control Panel". Select the client from the list of programs and then click on the "Add/Remove" button. The Uninstall Shield wizard will now delete the client software from your PC. Important: After the removal of the software components, the profile and configuration settings are still stored on the computer and can be restored if a newer version of the client is installed. In order to completely delete everything, you have to manually remove the files from the installation directory.