- 14 Nov 2024
- 1 Minute à lire
- SombreLumière
- PDF
Authentication Methods
- Mis à jour le 14 Nov 2024
- 1 Minute à lire
- SombreLumière
- PDF
For detailed information about logon methods and options, refer to the product documentation for your authentication server
Response-Only logon
Users log on via the current logon page with their user name and a one-time password (OTP) when they want to access a resource protected by Citrix StoreFront. For information on how to enable this logon procedure, see Enable Response-Only logon or 2-step Challenge/Response logon.
1-step Challenge/Response logon
A random challenge—the length is configured for all users in the authentication server's policy—is displayed on the logon page. Users log on with their user name and authenticator response to the displayed challenge. In a 1-step Challenge/Response logon process, the Digipass Authentication Module receives the authentication credentials of the end user, and sends an authentication request with these credentials to OneSpan Authentication Server. For information on how to enable this logon procedure, see Enable 1-step Challenge/Response logon.
2-step Challenge/Response logon
A first authentication request (first step) is used to request a challenge. The second authentication request (second step) is used to validate the response to that challenge. For information on how to enable this logon procedure, see Enable Response-Only logon or 2-step Challenge/Response logon.
Virtual Mobile Authenticator logon
Virtual Mobile Authenticator logon is used when the end user does not have access to their authenticator and needs to log on to Citrix StoreFront using Virtual Mobile Authenticator. The end user requests OneSpan Authentication Server (by means of an authentication request through Citrix StoreFront) to generate an OTP and deliver that OTP via SMS or email. This process typically starts when the end user clicks a button (indicating that they have forgotten their authenticator) in the Response-Only or 1-step Challenge/Response logon interface.
Users logging in with Virtual Mobile Authenticator use a similar process to the 2-step Challenge/Response logon. If the user has a primary Virtual Mobile Authenticator assigned, or requests use of the backup Virtual Mobile Authenticator feature during the first step to generate an OTP, this OTP can be delivered via SMS or email. The user is then redirected by the Digipass Authentication Module to a new page to enter the OTP.