aXsGUARD Identifier 3.0.2.0 Product Guide v1.5
User Authentication Process
In the aXsGUARD Identifier, DIGIPASS User accounts are identified using a User ID and a Domain. This process is
shown in the image below and explained here, cross-referencing the numbers in the image:
1.
If entry fields for the User ID and Domain are separate, name resolution ends and authentication continues.
Otherwise
Simple Name Resolution
continues
in
step 2.
2.
If login uses a similar format to User-Principal-Name:
Simple Name Resolution
continues to
step 3. Otherwise,
Default Domain Processing
proceeds in step 5.
3.
The aXsGUARD Identifier searches for a Domain record with the name given after the '@' sign. If the Domain
record is found, name resolution
continues to step 4. Otherwise,
Default Domain Processing
proceeds in
step 5.
4.
The User ID and domain parts are separated out, name resolution ends and authentication continues.
5.
If the
Default Domain
field has been configured for the Policy, name resolution
continues in step 6.
Otherwise, domain processing continues in step 7.
6.
The User ID is used as entered, with the Default Domain from the Policy. Domain resolution ends and
authentication continues.
7.
The
Master Domain
is used, Domain resolution ends and authentication continues. More information on the
Master Domain
is available in section
Image 5: User ID and Domain Resolution
©
2009 VASCO Data Security
27