Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

...


Info
This article includes updates for Digital Access 6.5.0.

...

Select

 Select a predefined provider where an authentication method exists.

  • The admin user needs to set the Activation PIN for the user or check the 'Generate PIN' checkbox to generate and assign a random 6 - digit PIN. This Activation PIN will be sent to the user through the configured notification channel.
  • Select Notification: By screen, by SMS, by email and so on.
  • Click Next and Finish Wizard.
    1. The text in green is "Notification by screen".
    2. The email that is sent to the user contains a QR code. The user shall download the OATH-compliant app and use the app to scan the code. In case of Smart ID desktop app, the user need to enter the activation URL instead of scanning QR code.
  • Expand
    titleEnable the Smart ID app for an end user for secure activation
    1. In Digital Access Admin, go to Manage Accounts and Storage.
    2. Click User Accounts. Search for the user that you shall enable Google Authenticator for, or add a new user account, see Add user account in Digital Access.
    3. If you are updating an existing user account, click Edit User Account and select the Authentication tab.
    4. Select Enable OATH for the user account.
    5. Under Notification Settings, enter email address or SMS (how you want to send the notification). If an Active Directory is connected, the information is added automatically from the user id in the Active Directory. If not, enter the values manually.
    6. Click Next.
    7. The Token ID field is out-grayed since this is not a hardware token.
    8. Select Provider from the drop-down list and select Status active.

    Note

    ...

    In order to

    To use OATH for authentication, the user needs the authentication method Nexus OATH to be enabled. For self-provisioning, the user is required to authenticate with another method, like Password

    , to ensure that he is the one that he pretends to be

    . For this reason, the corresponding method (for example, Password)

    needs to

    must be enabled for this user as well.

    The

     The user will be asked to set the Activation PIN when provisioning through Access point.

  • Under Notification, provide email address and sms. If an Active Directory is connected, the information is added automatically from the user id in the Active Directory. If not, enter the values manually.
  • In case of self service registration, the user is expected to remember the Activation PIN entered on the access-point page while doing the activation process. No notification email/ SMS will be sent for the Activation PIN to the user.
  • Click Next.

  • This

     This step assumes that password has been selected in step 4 as the second authentication method.

     The password that the user shall provide comes from the Active Directory. If no AD, enter a password for the user to use. Also check any password properties.

  • For OATH, do not add a token because the user shall do that as self service registration.
  • Select Notification, for example, select by screen and by email.
  • Click Next.
  • Click Finish Wizard.
    The text in green is "Notification by screen". Note the line containing the user's password.
  • Expand
    titleSet up user account to be able to use self-service
    1. In Digital Access Admin, go to Manage Accounts and Storage.
    2. Click User Accounts. Search for the user that shall be able to use self-service, or add a new user account, see Add user account in Digital Access.
    3. If you are updating an existing user account, click Edit User Account and select the Authentication tab.

    4. Check Enable Nexus OATH for the user account. Also check, for example, Enable Password for the user account.

    Info
    Note

    ...

    Expand
    titleRegister a new device
    1. Next time when the user logs in to Digital Access, there is a "New Device?" link available.
    2. The user shall then first authenticate with the enabled method, for example, password. The user has received an email regarding this.
    3. The user then clicks Confirm to create a new profile.
    4. Depending on the settings, an email regarding OATH profile provisioning is sent to the user and a QR code is also presented, could be either of these or both. The user uses, for example, Google Authenticator to scan the code.
    5. The user will have to enter an Activation PIN that the user configured while self-service registration or through admin UI.
    6. The user then clicks Activate in the app and registers a PIN code and, if applicable, a fingerprint.

    Related information

    ...