To perform authentication using secure channel, the following two operations must be executed in this particular order:
Get secure challenge (see getSecureChallenge operation)
Authenticate user (see authUser operation)
For this operation to succeed, the following administrative tasks should be performed in OneSpan Authentication Server:
To configure OneSpan Authentication Server to get secure challenge operations
Use the IDENTIKEY Authentication with Secure Channel policy or define a policy that inherits from this policy.
Register a client component and assign the policy to it.
Import authenticators that are compliant with multi-device licensing (MDL) and support Secure Channel.
Create users, assign authenticator licenses to them, and activate new authenticator instances for their devices.
getSecureChallenge operation
The getSecureChallenge operation enables a user to generate a request message, which can be used to initiate an authentication process using secure channel.
getSecureChallenge can send two types of requests to OneSpan Authentication Server:
A request that includes a challenge message and, optionally, a transaction title (which will be used to generate a request body and the request message).
A request that includes a custom request body (which will be transparently used to generate the request message).
At a minimum, the getSecureChallenge operation requires the following set of authentication field attributes to perform this operation:
CREDFLD_COMPONENT_TYPECREDFLD_USERIDCREDFLD_CHALLENGE_MESSAGE, optionally with aCREDFLD_TRANSACTION_TITLEauthentication field attribute.-OR-
CREDFLD_REQUEST_BODY. For more information, see getSecureChallenge SOAP request structure.
By default, OneSpan Authentication Server uses the first applicable authenticator application that is allowed by the effective policy. If you need to use a specific authenticator application for the Secure Channel authentication process, you can specify it by using one of the following attributes when you call the getSecureChallenge operation:
CREDFLD_CRYPTO_APP_INDEXCREDFLD_CRYPTO_APP_NAME
The specified authenticator application must be allowed by the effective policy. Any subsequent call of authUser related to the generated request message will automatically use the specified authenticator application.
If you really need to specify the authenticator application, we recommend to use CREDFLD_CRYPTO_APP_NAME whenever possible, because it is more reliable. The difference is that the application name is explicitly specified in the DIGIPASS export file (DPX), whereas the application index is dynamically created during the DPX import process based on the authenticator application order in the DPX.
For more information about the required and optional attributes for this command, see getSecureChallenge (Command).
authUser operation
At a minimum, the authUser operation requires the following set of authentication field attributes to perform user authentication using secure channel:
CREDFLD_USERIDCREDFLD_COMPONENT_TYPECREDFLD_CHALLENGE_KEYCREDFLD_PASSWORD
CREDFLD_PASSWORD is the password that is generated by the authenticator.
For more information about the required and optional attributes for this command, see authUser (Command).