- 02 Jan 2025
- 1 Minute à lire
- SombreLumière
- PDF
User Attributes
- Mis à jour le 02 Jan 2025
- 1 Minute à lire
- SombreLumière
- PDF
User attributes are used by OneSpan Authentication Server Appliance to return specific information to a client component. There are two types of user attributes available in OneSpan Authentication Server Appliance:
- RADIUS attributes can be returned when handling authentication requests from a RADIUS client.
- Custom user attributes can be returned to Digipass Authentication Module clients and custom Web applications.
OneSpan Authentication Server Appliance uses user attributes for the following:
- Identify that a user account's static password has been randomized (see Static password randomization) .
- Store attributes that may need to be returned to applications when requested .
- Store RADIUS attributes (see RADIUS attribute settings).
- Identify that a user account has been created and is updated via LDAP user synchronization (see Identifying synchronized users) .
User attributes may be set for each authenticator user individually or to a group of authenticator users. For more information about adding user attributes to one or more user accounts, refer to the Administration Web Interface Help.
RADIUS attribute settings
RADIUS reply attributes can be returned with an Access-Accept packet when handling authentication requests from a RADIUS client. The attributes may include authentication parameters or authorization settings.
You can upload a custom RADIUS dictionary file via the Configuration Tool. For more information, refer to the OneSpan Authentication Server Appliance Administrator Guide.
Attribute group
For RADIUS attributes, one or more attribute groups are specified in the policy used for the specific client component.
Usage
Currently not used for RADIUS attributes.
Value
The required value of the RADIUS attribute.
Custom user attribute settings
Custom attributes can be used with OneSpan plug-ins and Digipass Authentication Module clients.
Attribute group
An attribute group is specified by the client component as a parameter in the authentication request. When multiple client components are using custom user attributes, the specified attribute group ensures that only attributes required by the specific client are returned.
Name
A name for the attribute as expected by the client component.
Usage
- Basic. Indicates that the attribute is used by Digipass Authentication for IIS Basic for basic authentication.
- Return. Indicates a return attribute used by Digipass Authentication for Steel-Belted RADIUS Server.
- Check. Indicates a check attribute used by Digipass Authentication for Steel-Belted RADIUS Server.
Value
The required value of the named attribute.