aXsGUARD Identifier 3.0.2.0 Product Guide v1.5
DIGIPASS
Table 12: Server Settings Regulating Server PINs
Setting
Explanation
PIN Supported
Factory default built-in technology to support use of a Server PIN (only active if PIN enabled).
PIN Enabled
Factory default setting forcing a Server PIN to be used for login (only possible if PIN Supported).
PIN Change Forced
Whether PIN Change will be forced on next logon (see Forced PIN Change action in section
Whether a User is allowed to change their Server PIN for this DIGIPASS device.
PIN Length
The length of the current Server PIN.
PIN Minimum Length
The minimum PIN length required by the Server.
17.2.3
Grace Period
Each DIGIPASS device may be given a
Grace Period
when it is assigned to a DIGIPASS User Account. The Grace
Period allows some time for Users to continue using their static password before they receive the DIGIPASS device
and learn how to use it. The first time that the User logs in successfully with their DIGIPASS, the Grace Period
ends. After the Grace Period has ended, they must use the DIGIPASS. The Grace Period is time limited, so that the
User is not able to delay too long before starting to use the DIGIPASS.
The Grace Period can be set during manual administrative assignment of DIGIPASS records as well as during
Auto-
Assignment
. However, it is not applicable to
Self-Assignment
, because the User must use the DIGIPASS device to
complete the Self-Assignment process. For more information on assignment options, see section
The Grace Period cannot apply when the Local Authentication setting is
DIGIPASS Only
.
During the Grace Period, if OTP validation fails, the static password is checked. For more information on the static
password check during an authentication attempt, see section
17.2.4
DIGIPASS Authentication Method
DIGIPASS authentication and login processes include:
Response only (described in section
Challenge/Response (described in section
Virtual DIGIPASS
Login (described in section
). For further information on
Virtual DIGIPASS
use, please
see section
Response Only authentication can be:
Time-based, in which case the OTP is based on the current time and changes after a time step, usually every
36 seconds, whether or not an OTP has been requested from the DIGIPASS device.
Event-based, in which case a new OTP is displayed each time a request for an OTP is made.
©
2009 VASCO Data Security
102