aXsGUARD Identifier 3.0.2.0 Product Guide v1.5
User Authentication Process
3.4.3
DIGIPASS User Account Lookup
The aXsGUARD Identifier checks that the User attempting to log in has a DIGIPASS User account in the aXsGUARD
Identifier data store. The
described above determines the search criteria to look up
the DIGIPASS User account.
If a DIGIPASS User account is found, the
Disabled
and
Locked
indicators are checked. If either is set to
Yes
, the
authentication request is rejected immediately.
If no DIGIPASS User account is found, Policy settings determine whether the aXsGUARD Identifier continues
processing or rejects the authentication request:
If
Local Authentication
is required, a DIGIPASS User account must exist. It is therefore only possible to
proceed if the
Dynamic User Registration
feature is enabled. This is explained below.
If
Local Authentication
is not required, authentication can proceed without a DIGIPASS User account.
If the
Local Authentication
Policy setting is
None
, no Local Authentication is required. If it is set to
DIGIPASS/Password
or
DIGIPASS Only
, Local Authentication is required. More information on the different Local
Authentication settings is available in section
3.4.4
Dynamic User Registration
Dynamic User Registration
(DUR) allows DIGIPASS User accounts to be created automatically if their credentials
are validated by
Back-end Authentication.
The correct static password is sufficient to permit a DIGIPASS User
account to be created. DUR saves the administrative work of manually creating or importing DIGIPASS User
accounts.
It is typically used in with:
the DIGIPASS
Auto-Assignment
feature, which assigns the next available DIGIPASS to the new DIGIPASS User
account as it is created, or
the DIGIPASS
Self-Assignment
feature, which allows the new User to assign a DIGIPASS to their account as
part of the login process
The image below shows a typical DUR process and how Auto- and Self-Assignment may be integrated. For more
information on the various DIGIPASS assignment possibilities, please see section
Note:
The User IDs and Domains detected during an authentication attempt are automatically
converted to lower case to prevent the creation of multiple DIGIPASS User Accounts for a single
user. For example, if a User logs in with ‘jsmith’ on one occasion, and ‘JSmith’ on another, only
one DIGIPASS User Account is created – jsmith.
©
2009 VASCO Data Security
28