DIGIPASS Authentication for TAM - Vasco
DIGIPASS Authentication for TAM - Vasco
DIGIPASS Authentication for TAM - Vasco
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
10 <strong>DIGIPASS</strong> <strong>Authentication</strong> <strong>for</strong> <strong>TAM</strong><br />
<strong>DIGIPASS</strong> <strong>Authentication</strong> <strong>for</strong> <strong>TAM</strong><br />
5 Token Repository<br />
5.1 STORING VASCO <strong>DIGIPASS</strong> TOKEN INFORMATION<br />
As stated above, the <strong>DIGIPASS</strong> CDAS uses the <strong>TAM</strong> LDAP Directory as its repository to<br />
store token in<strong>for</strong>mation. In the current release both IBM LDAP and SunOne LDAP are<br />
supported. The token in<strong>for</strong>mation is stored in an object that is located in a sub tree under<br />
the user with whom the token is associated.<br />
The following screen dump shows such an entry.<br />
This screen dump shows that the token with serial number 0097123456 is associated<br />
with the <strong>TAM</strong> user with DN (Distinguished Name) cn=Allowed1, o=sov, c=be. The<br />
CDAS makes absolutely no assumptions about the <strong>for</strong>mat of the DN, as long as it is<br />
accepted by <strong>TAM</strong>. The token in<strong>for</strong>mation is stored as an instance of the Object Class<br />
sitVASCOToken. The object is created under the secAuthority=Default entry created<br />
by <strong>TAM</strong>.<br />
A token entry basically contains the following in<strong>for</strong>mation:<br />
sitVASCO Type of the token (e.g. ResponseOnly)<br />
sitVASCOApplName Application using the token<br />
sitVASCOBlob The token details, aka. BLOB (contains e.g. current valid pincode)<br />
sitVASCODpFlags Token flag (internal use)<br />
sitVASCOSerialNr Token serial number (to physically associate a token with a<br />
user)<br />
sitVASCOMode Mode of operation (optional)<br />
sitVASCOType Type of token (optional)