13.04.2013 Views

Digipass Plug-In for IAS Product Guide - Vasco

Digipass Plug-In for IAS Product Guide - Vasco

Digipass Plug-In for IAS Product Guide - Vasco

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Digipass</strong> <strong>Plug</strong>-<strong>In</strong> <strong>for</strong> <strong>IAS</strong> <strong>Product</strong> <strong>Guide</strong> <strong>Digipass</strong><br />

Some Possible <strong>Guide</strong>lines<br />

<strong>Guide</strong>line Pro Con<br />

Backup Virtual <strong>Digipass</strong> disabled <strong>for</strong> all - enabled<br />

<strong>for</strong> individual Users as required.<br />

Backup Virtual <strong>Digipass</strong> enabled <strong>for</strong> all - either<br />

time/number of usage limit set.<br />

Backup Virtual <strong>Digipass</strong> enabled <strong>for</strong> all - no limits<br />

set.<br />

Table 5: Backup Virtual <strong>Digipass</strong> Example <strong>Guide</strong>lines<br />

Low text message costs Manual enable <strong>for</strong> each User<br />

and circumstance. Possible<br />

heavy administration load.<br />

Predictable text message<br />

costs<br />

2.7.7 Resetting Virtual <strong>Digipass</strong> Restrictions<br />

Administrator may need to reset<br />

limits frequently – medium<br />

administration load.<br />

Lighter administration load Possible high text message<br />

costs.<br />

When a User has reached their limit of Virtual <strong>Digipass</strong> use, an administrator must reset their<br />

limit.<br />

2.7.8 Virtual <strong>Digipass</strong> Login options<br />

A decision must be made as to how Users will log in using Virtual <strong>Digipass</strong>. <strong>In</strong> particular, Users<br />

with a hardware <strong>Digipass</strong> and the Backup Virtual <strong>Digipass</strong> enabled must be able to request an<br />

OTP to be sent to their mobile when required, but to login using the hardware <strong>Digipass</strong> at<br />

other times.<br />

The simplest method <strong>for</strong> the User is to allow a 2-step login process, where the User enters<br />

their User ID and static password only, triggering an OTP Request, and are redirected to a<br />

second login page to enter the OTP sent to them. To use this method, though, your system<br />

must be set up to allow 2-step logins. Check with your system administrator if unsure.<br />

Alternatives to the 2-step login are a sequence of two 1-step logins or the use of the OTP<br />

Request Site.<br />

See the Administrator Reference <strong>for</strong> in<strong>for</strong>mation on possible login permutation.<br />

2.7.9 Location of OTP Request Site<br />

If the OTP Request Site is to be used, its location must be decided. You may choose to install<br />

the Web Site onto any web server, bearing the following in mind:<br />

If the Web Site is installed onto a web server in the DMZ, you need to permit TCP/IP<br />

access from the web server to the <strong>IAS</strong> <strong>Plug</strong>-<strong>In</strong> on port 20003. This is the recommended<br />

option.<br />

The Web Site can be used on the <strong>In</strong>ternet, however it would be essential to provide SSL<br />

(or TLS) encryption <strong>for</strong> access to it. Otherwise, an attacker could discover static<br />

passwords and PINs. The other point to take into consideration is that publishing the<br />

Web Site on the <strong>In</strong>ternet would allow anyone in the world to send requests to the <strong>IAS</strong><br />

<strong>Plug</strong>-<strong>In</strong> – this would provide the potential <strong>for</strong> denial of service and brute <strong>for</strong>ce attacks. It<br />

would be strongly advised to protect the Web Site from general use in some way.<br />

If the Web Site is installed onto a web server that communicates over a WAN link to the<br />

<strong>IAS</strong> Server(s), the WAN link must be encrypted. For example, an IPSEC-based VPN<br />

connection would be sufficient.<br />

© 2005 VASCO Data Security <strong>In</strong>c. 41

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!