aXsGUARD Identifier 3.0.2.0 Product Guide v1.5
DIGIPASS
17.4.1.2
Self-Assignment Data
Certain settings and data entry are required for Self-Assignment:
The
Assignment Mode
Policy setting must be
Self-Assignment
.
For Self-Assignment to succeed, the User needs to provide the following:
A static password, validated by back-end authentication
The
Serial Number
of an available DIGIPASS record
A valid OTP for the DIGIPASS
A new Server PIN, if required
The Self-Assignment process is possible during Dynamic User Registration. It is also possible when the
Local
Authentication
setting is
DIGIPASS Only
.
Response Only Data Entry
For a DIGIPASS device that supports
Response Only
, the User needs to enter the following in the password login
field, depending on whether a Server PIN is needed or not:
SERIALNUMBER
password
OTP – where a Server PIN is not required.
SERIALNUMBER
password
PIN
OTP
– where a Server PIN
is
required.
SERIALNUMBER
password
OTP
newpin
newpin – where a Server PIN is required and no initial PIN was set.
Challenge/Response Data Entry
For a DIGIPASS device that supports only
Challenge/Response
, this process requires two steps. In the first step,
the static password and Serial Number are given. This results in a Challenge being returned. If the correct
Response is given to the Challenge, the Self-Assignment is successful.
Step 1: SERIALNUMBER
password
Step 2: OTP
Serial Number Format
The SERIALNUMBER may be entered in one of two formats, depending on the
Serial No. Separator
Policy setting.
No separator specified – the full 10 digit Serial Number must be entered, with no dashes (-) or spaces, for
example
0097123456
.
Separator value specified – the Serial Number can be entered as written on the back of the DIGIPASS device,
for example
9-712345-6
.
©
2009 VASCO Data Security
108