aXsGUARD Identifier 3.0.2.0 Product Guide v1.5
User Authentication Process
Application Type
-
either Response Only, Challenge/Response or Multi-Mode. Only DIGIPASS with the
Application Type are usable, except Multi-Mode which matches all application types.
DIGIPASS Type
-
a list of models such as DP GO3, DP 260. Only DIGIPASS from the listed models are usable.
It is therefore possible that a DIGIPASS User account with a DIGIPASS assigned cannot use the DIGIPASS to log in,
when a certain Policy applies. In this case, the User is regarded as not having a DIGIPASS device. With a different
kind of login, a different Policy may apply with no restrictions. In this case the User is treated as having a DIGIPASS
device.
Example
Consider a company using both GO 3 DIGIPASS (DP GO 3) and Primary Virtual DIGIPASS. The Outlook Web Access login could
permit both, so its Policy would not restrict DIGIPASS Types. However the RADIUS VPN login might require the GO 3, so its Policy
would specify DIGIPASS
Type = DPGO3
.
Searching for a Linked User Account
User accounts can be linked allowing a DIGIPASS device to be shared between two user accounts. This is achieved
with the Linked User Account property, explained in section
. When an authenticating DIGIPASS user account
is linked to another, the other account is searched for.
Example
DIGIPASS
User account 2
is linked to DIGIPASS
User account 1
. The DIGIPASS is assigned to DIGIPASS
User account 1
. When
DIGIPASS
User account 1
logs in, the DIGIPASS search is for that account. However, when DIGIPASS
User account 2
logs in, the
DIGIPASS search is also for DIGIPASS
User account 1
.
Grace Period
A
Grace Period
) may be applied to each DIGIPASS assigned to a DIGIPASS User. Because an
applied Policy might restrict which DIGIPASS can be used during a login, the Grace Period on each DIGIPASS is
independent of other DIGIPASS. This means that if a User is assigned two DIGIPASS, each with a Grace Period of
seven days, the User may log in using one DIGIPASS within the seven-day period (ending the Grace Period for that
DIGIPASS) without affecting the Grace Period for the other DIGIPASS.
Example
The company has set up Policies which require a Response Only login via the local area network, and a Challenge/Response login
via the Internet, limited to certain employees.
John has two DIGIPASS assigned to him: a DP 300 with the Challenge/Response application enabled, and a GO 3 with a Response
Only application. The DIGIPASS are both assigned on Tuesday.
John receives his GO 3 on Friday, and immediately uses an OTP to login. His Grace Period for the GO 3 ends at that time. In future
he must use the GO 3 when logging into the intranet from the LAN.
Over the weekend, John needs to access the company intranet from home. Because a Challenge/Response login is required via the
Internet and he does not yet have his DP 300, he uses only his User ID and static password to log in. As he is still within the Grace
Period for the DP 300, the login is valid.
©
2009 VASCO Data Security
32