- 18 Nov 2024
- 2 Minutes à lire
- SombreLumière
- PDF
Connection Settings
- Mis à jour le 18 Nov 2024
- 2 Minutes à lire
- SombreLumière
- PDF
With Digipass Authentication for Remote Desktop Web Access you can manage connections to multiple primary and/or backup authentication servers. This allows redundancy and load sharing over multiple servers.
Enable DNS lookup
Select this option to enable Domain Name System (DNS) lookup for available OneSpan Authentication Server instances. If DNS lookup is enabled, the server(s) to which Digipass Authentication for Remote Desktop Web Access is connecting will be chosen in order of their weight value set in the DNS server record. Server order is randomized on equal weight.
If DNS lookup fails or is disabled, the static configuration values are used.
DNS server service name
Type the DNS record name used for the OneSpan Authentication Server instance in your DNS configuration. This value must match the name specified during the initial OneSpan Authentication Server configuration. It is not necessary (and not recommended) to change this value.
Digipass Authentication for Remote Desktop Web Access performs a couple of DNS queries by appending ._tcp and all connection-specific DNS suffixes to the specified service name. For instance, if you have a primary DNS suffix company.com, Digipass Authentication for Remote Desktop Web Access queries _ias-soap._tcp and _ias-soap._tcp.company.com.
For best performance, you can set DNS server service name to a fully qualified name with a terminating dot, ‘.’, e.g.
_ias-soap._tcp.company.com.
In that case, Digipass Authentication for Remote Desktop Web Access performs a DNS lookup only with the specified value.
The default setting is _ias-soap.
Primary server location
Type the IP address of the primary OneSpan Authentication Server instance. This setting is used if DNS lookup fails or is disabled.
Primary server port
Type the IP port of the primary OneSpan Authentication Server instance. This setting is used if DNS lookup fails or is disabled.
The default setting is 8888.
Backup server location
Type the IP address of the backup OneSpan Authentication Server instance. This setting is used if DNS lookup fails or is disabled and the primary server is not available.
Backup server port
Type the IP port of the backup OneSpan Authentication Server instance. This setting is used if DNS lookup fails or is disabled and the primary server is not available.
The default setting is 8888.
Verify server SSL certificate
Select this option to verify the server SSL certificate for validity when establishing secure connections via SSL, by checking whether the certificate is in the Trusted Root Certification Authorities certificate store. If this check box is cleared, any SSL certificate from the server will be accepted.
For more information about the server SSL certificate and certificate trust, see Server TLS/SSL certificate for secure communication.
Because accepting any SSL certificate from the server constitutes a major security risk, always select Verify server SSL certificate when in production mode.
You should disable this check only for evaluation or testing purposes, if required.
Connection timeout
Enter the maximum time span to establish a connection to OneSpan Authentication Server for online authentication. After the timeout, the connection attempt is considered failed and the authentication also fails. The value is given in seconds.
The default setting is 5.
Test connection
Click this button to verify that your connection settings are valid and a connection to the authentication server can be established. If the connection test fails, a corresponding error message will be displayed.
Standard Server Setup
This setup uses one main authentication server to handle requests from the web server, with a backup authentication server for use when the main server is busy or unavailable.