- 30 Dec 2024
- 1 Minute à lire
- SombreLumière
- PDF
Authenticator records and assignment
- Mis à jour le 30 Dec 2024
- 1 Minute à lire
- SombreLumière
- PDF
Authenticator records can be managed individually or in bulk. You can import authenticator records in bulk from one of the following:
DIGIPASS export file (DPX). A DIGIPASS export file (DPX) is a special text file (.dpx) that contains all authenticator application data for an authenticator batch. They are used, for instance, when you purchase authenticators or authenticator licenses. The authenticator application data is encrypted with a transport key.
You need the following:
- Valid DIGIPASS export file (.dpx)
- Corresponding transport key for the DIGIPASS export file
DIGIPASS import file. A DIGIPASS import file is a comma-separated text file (.csv) that contains authenticator records. They are used, for instance, to import authenticator data from an existing OneSpan Authentication Server Framework environment to OneSpan Authentication Server.
You need the following:
- Valid DIGIPASS import file (.csv)
- Custom storage derive key if the authenticator BLOB data is protected with custom encryption
- The DIGIPASS import file can also be used by Data Migration Tool (DMT). For more information about this type of import files and preparing them, refer to the Data Migration Tool Administrator Guide.
The files can be uploaded in the OneSpan Authentication Server Administration Web Interface, via DIGIPASS > Import DPX and DIGIPASS > Import CSV, respectively.
If you import authenticator records via the DIGIPASS Import wizard, a respective server task is scheduled to perform the actual import operation. The number of concurrent import tasks for Digipass import files and DPX files is limited for each to one task per OneSpan Authentication Server Appliance instance. Subsequent import tasks will be queued and processed one after another.
Authenticator records can be assigned to user accounts in the OneSpan Authentication Server Administration Web Interface in three ways:
- Manual assignment. View an unassigned authenticator or user record, click ASSIGN and complete the ASSIGN wizard. The specific authenticator for the record must be supplied to the user.
- Auto-assignment.The user does not have an authenticator assigned, and the applicable policy permits auto-assignment. An unassigned authenticator record is searched and automatically assigned to the user upon logging in for the first time. The specific authenticator for the record must be supplied to the user.
If maker–checker authorization is enabled, assigning an authenticator requires the approval of a checker administrator. In that case, auto-assignment is not available.
- Self-assignment. The authenticator is in the user's possession, and the applicable policy permits self-assignment. The user completes a self-assignment process.
For more information, refer to the OneSpan Authentication Server Appliance Product Guide.