aXsGUARD Identifier 3.0.2.0 Product Guide v1.5
User Authentication Process
3.6.3.2
Password Autolearn
A back-end server static password can be specified in addition to a DIGIPASS OTP, during an authentication
attempt. If the Password Autolearn option is enabled, the static password is automatically stored in the DIGIPASS
User Account, if authentication with a back-end server succeeds. Use of the Stored Password Proxy functionality is
then possible.
Any changes to a User's back-end server password need to be communicated to the aXsGUARD Identifier. If
Password Autolearn is enabled, a User may directly log in with their new static password in front of their OTP. If it
does not match the static password stored by the aXsGUARD Identifier, it can be verified with the back-end server.
If correct, the aXsGUARD Identifier stores the new static password for future use and authenticates the User.
When the Password Autolearn option is disabled, initial and modified static passwords must be entered manually in
the Administration Web Interface, to support the Stored Password Proxy functionality.
3.6.3.3
Password Replacement (IIS Modules)
The IIS Module is an add-on for the aXsGUARD Identifier, which is installed on the Microsoft IIS Server, for
example, configured with Microsoft Outlook Web Access. The IIS Module supports use of the DIGIPASS OTP for
access to the Outlook Web service. After installing the module on the Microsoft Server, DIGIPASS OTP
authentication requests are intercepted and forwarded to the aXsGUARD Identifier. After successful authentication
on the aXsGUARD Identifier, the stored static password is forwarded to the Outlook Web Access application,
allowing completion of the authentication process (see image below).
The Microsoft Outlook Web Access password (the static password) only needs to be supplied by the User on first-
time use, and when modified on the Microsoft infrastructure, because it is stored in the DIGIPASS User Account on
the aXsGUARD Identifier.
This setup requires the following server-side configuration actions:
Creation of a client component, type SEAL.
Assigning the Policy, IDENTIKEY Microsoft AD Password Replacement, to the client component. In this Policy,
the Password Autolearn and Stored Password Proxy options are enabled.
Uploading the Client License into the client component record.
A Wizard is available during installation of the IIS Module, on the Microsoft Server, which automatically performs
the steps described above on the aXsGUARD Identifier (see the IIS Module related documentation for more
information).
©
2009 VASCO Data Security
42