13.04.2013 Views

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Digipass</strong> <strong>Plug</strong>-<strong>In</strong> <strong>for</strong> <strong>SBR</strong> <strong>Administrator</strong> <strong>Reference</strong> Audit Messages<br />

Message<br />

Code<br />

I007003 A RADIUS Access-Reject has been<br />

issued.<br />

I007004 A RADIUS Accounting-Response has<br />

been issued.<br />

I008001 A <strong>Digipass</strong> has been moved <strong>for</strong><br />

assignment to a user.<br />

I008002 A user-to-user link has been removed<br />

due to assignment of a <strong>Digipass</strong>.<br />

I009001 A Virtual <strong>Digipass</strong> One Time Password<br />

has been delivered.<br />

Description Notes<br />

The <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> has rejected an Access-Request.<br />

The <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> has acknowledged an Accounting-Request.<br />

Note however that unless the request is <strong>for</strong>warded to a<br />

RADIUS Server, no processing is carried out by the <strong>SBR</strong><br />

<strong>Plug</strong>-<strong>In</strong>.<br />

Upon assignment of a <strong>Digipass</strong> to a User, if the <strong>Digipass</strong> is<br />

not already in the same location (Organizational Unit) as<br />

the User, it is moved to that location.<br />

If a <strong>Digipass</strong> User Account is linked to another in order to<br />

share the <strong>Digipass</strong>, it must not have a <strong>Digipass</strong> assigned<br />

itself. If a <strong>Digipass</strong> is assigned, the link will be broken.<br />

The MDC successfully delivered a text message via the<br />

HTTP gateway, as reported by the gateway. The audit<br />

message may contain further details from the gateway.<br />

Note that depending on the gateway, it may still be<br />

possible <strong>for</strong> delivery to fail after the gateway has reported<br />

success.<br />

I010001 User authentication was not handled. The <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> decided not to handle an authentication<br />

request due to Policy and/or <strong>Digipass</strong> User Account<br />

settings. The main reasons why this may occur are: the<br />

effective Local Authentication and Back-End<br />

Authentication settings were both None; the User failed<br />

the Windows Group Check, using the Pass requests <strong>for</strong><br />

users not in listed groups back to host system option.<br />

Note that the 'effective' settings are the effective settings<br />

of the Policy, unless the <strong>Digipass</strong> User Account overrides<br />

the Policy.<br />

I010002 A stored password change was<br />

unhandled.<br />

I011001 A <strong>Digipass</strong> Grace Period has been ended<br />

by the use of a One Time Password.<br />

I011002 A Backup Virtual <strong>Digipass</strong> expiration<br />

date has been set due to the first<br />

request <strong>for</strong> a Virtual One Time<br />

Password.<br />

I011003 A Backup Virtual <strong>Digipass</strong> time limit has<br />

been expired by the use of the normal<br />

One Time Password.<br />

The <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong> decided not to handle a password change<br />

request due to Policy and/or <strong>Digipass</strong> User Account<br />

settings. The main reasons why this may occur are: the<br />

effective Local Authentication and Back-End<br />

Authentication settings were both None; the User failed<br />

the Windows Group Check, using the Pass requests <strong>for</strong><br />

users not in listed groups back to host system option.<br />

Note that the 'effective' settings are the effective settings<br />

of the Policy, unless the <strong>Digipass</strong> User Account overrides<br />

the Policy.<br />

The first time that an assigned <strong>Digipass</strong> is used<br />

successfully to log in, if a Grace Period is still active, it is<br />

ended immediately. They must continue to use their<br />

<strong>Digipass</strong> to log in after that point.<br />

A User has requested a Backup Virtual <strong>Digipass</strong> OTP <strong>for</strong> the<br />

first time, when the effective Backup VDP Enabled<br />

setting is Yes – Time Limited and they did not already have<br />

an Enabled Until date set on their <strong>Digipass</strong>. At this time,<br />

they are given the Time Limit from the Policy by adding it<br />

to the current date.<br />

A User who has been using Backup Virtual <strong>Digipass</strong> has<br />

used their normal OTP login using the <strong>Digipass</strong> again.<br />

When the effective Backup VDP Enabled setting is Yes –<br />

Time Limited, using the normal OTP login ends their time<br />

limit immediately. This is done by setting the Enabled<br />

Until date on their <strong>Digipass</strong> to the current date.<br />

An administrator action is required to reset their Enabled<br />

© 2006 VASCO Data Security <strong>In</strong>c. 171

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!