13.04.2013 Views

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Digipass</strong> <strong>Plug</strong>-<strong>In</strong> <strong>for</strong> <strong>SBR</strong> <strong>Administrator</strong> <strong>Reference</strong> Field Listings<br />

Field Name in<br />

Administration<br />

<strong>In</strong>terfaces<br />

Description<br />

the last successful login.<br />

This only applies to time-based Applications.<br />

<strong>In</strong> either case, after the first successful login, the <strong>In</strong>itial Time Window is no longer active.<br />

If this setting is not specified at all, there is an inbuilt default value of 6.<br />

Event Window Controls the maximum number of events' variation allowable between a <strong>Digipass</strong> and the<br />

authentication server during login that uses an event-based Application.<br />

If this setting is not specified at all, there is an inbuilt default value of 20.<br />

Identification Threshold Specifies the number of consecutive failed authentication attempts allowed be<strong>for</strong>e the<br />

<strong>Digipass</strong> Application is locked from future authentication attempts.<br />

This locking mechanism is separate from the User Lock Threshold and is normally not<br />

necessary. It only applies when a single <strong>Digipass</strong> Application can be used <strong>for</strong> a login, either<br />

because the User only has one <strong>Digipass</strong> with one Application, or because the Policy<br />

restrictions narrow the list down to one <strong>Digipass</strong> Application. If Policy restrictions are used<br />

in this way, the Identification Threshold can be used to lock a User out of one kind of login<br />

(eg. a VPN) while still permitting them to use another kind (eg. Wireless).<br />

If this setting is not specified at all, this feature is not used.<br />

Signature Threshold Specifies the number of consecutive failed Digital Signature authentication attempts allowed<br />

be<strong>for</strong>e the <strong>Digipass</strong> Application is set to be locked from future authentication attempts.<br />

If this setting is not specified at all, this feature is not used.<br />

Signature Applications are not currently used in RADIUS environments.<br />

Max. Days Since Last<br />

Use<br />

This setting specifies the maximum number of days <strong>for</strong> which a <strong>Digipass</strong> Application can go<br />

unused <strong>for</strong> authentication. After this limit, authentication will be rejected until an<br />

admnistrator per<strong>for</strong>ms a Reset Application operation.<br />

If this setting is not specified at all, this feature is not used.<br />

Challenge Check Mode This setting is <strong>for</strong> advanced control over time-based Challenge/Response authentication.<br />

The value 1 should be used <strong>for</strong> standard RADIUS challenge/response. This is the inbuilt<br />

default value if the setting is not specified at all.<br />

0 No check is made. This is necessary <strong>for</strong> 1-step<br />

Challenge/Response.<br />

1 The challenge presented <strong>for</strong> verification must be the last one that<br />

was generated specifically <strong>for</strong> that <strong>Digipass</strong>. This is the normal mode<br />

of operation in 2-step Challenge/Response.<br />

2 The challenge presented <strong>for</strong> verification is ignored; the last one that<br />

was generated specifically <strong>for</strong> that <strong>Digipass</strong> is used. This is rarely<br />

applicable.<br />

3 Only one verification is permitted per time step. This option only<br />

applies to time-based Challenge/Response. This is a method of<br />

avoiding a potential replay of a captured response if the same<br />

challenge comes up again in the same time step.<br />

4 If the same challenge and response are presented <strong>for</strong> verification<br />

twice in a row during the same time step, they are rejected. This is<br />

an advanced method of avoiding a potential replay of a capture<br />

challenge/response.<br />

Online Signature Level This setting is <strong>for</strong> advanced control of Digital Signature authentication, and is not applicable<br />

currently.<br />

Signature Applications are not currently used in RADIUS environments.<br />

© 2006 VASCO Data Security <strong>In</strong>c. 93

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!