Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Section


Column
width75%

Introduction

Similar to the Deepnet MobileID, Google Authenticator is an OATH compliant One-Time Password generator. Google Authenticator is officially available on iPhone, Android and Blackberry. Deepnet DualShield authentication server natively supports Google Authenticator, in very much the same way that it supports Deepnet MobileID. This document describes how users can use Google Authenticator with DualShied.

This policy provides options that control Google-Authenticator/Time-Based Authentication (another OATH compliant One-Time Password generator that works in a similar fashion to MobileID);

The following system policy settings are for the policy "GoogleAuthenticator/Time Based default policies", in the category "GoogleAuthenticator/Time Based";

Image Modified


Column
width25%


The GoogleAuthenticator/Time-Based policy settings can be edited by left clicking on the context menu of the policy and selecting "Edit"";

...

Section


Column
width50%


Column
width50%




Expand
titleCategory:


Panel
borderColorgrey
bgColor#F8F8F8
borderStyledashed

The category for this policy is "GoogleAuthenticator/Time-Based" (this property cannot be edited).




Expand
titleHolder:


Panel
borderColorgrey
bgColor#F8F8F8
borderStyledashed

The holder of this policy is "System" (this property cannot be edited).



Expand
titleName:


Panel
borderColorgrey
bgColor#F8F8F8
borderStyledashed

The name assigned to identify the GoogleAuthenticator/Time Based default policy by the System Administrator.




Expand
titleDescription:


Panel
borderColorgrey
bgColor#F8F8F8
borderStyledashed

The System Administrator may use this field to annotate this policy.



Expand
titleEnabled


Panel
borderColorgrey
bgColor#F8F8F8
borderStyledashed

This option allows the System Administrator to enable or disable this policy.



Expand
titleMaximum Number of Tokens:


Panel
borderColorgrey
bgColor#F8F8F8
borderStyledashed

The maximum number of GoogelAuthenticataor tokens allowed in a user account (enter "0" if there is no limit).



Expand
titleToken Lifetime (days):


Panel
borderColorgrey
bgColor#F8F8F8
borderStyledashed

This value indicates how many days the token will be active (enter "0" if there is no limit).




Expand
titlePasscode History:


Panel
borderColorgrey
bgColor#F8F8F8
borderStyledashed

This value specifies the maximum number of passcodes that can be kept in the History List (this list is used to avoid repeat usage of recent passcodes).




Expand
titleEnable Offline:


Panel
borderColorgrey
bgColor#F8F8F8
borderStyledashed

This option allows the system administrator to allow users to logon whilst offline.




Expand
titleToken Provisioning:


Panel
borderColorgrey
bgColor#F8F8F8
borderStyledashed
Image Modified

In order to use MobileID Authentication in DualShield, the user must first have a MobileID token in their user account in the DualShield Server. 

The token can be manually created by the system administrator for the user using the DualShield Management Console or manually created by the DualShield Server if the MobileID's policy is set up to automatically provisioning tokens to users.

  • Automatically provision token
    Automatically create a token for a user when needed.

  • Manual
    Tokens will be sent manually to users.





Expand
titleClient Provision:


Panel
borderColorgrey
bgColor#F8F8F8
borderStyledashed

This field determines how DualShield deploys the MobileID client to a user;

  • Automatically push
    DualShield will automatically send the MobileID download link via the specified Message Channel.

    If the Token Authorisation Code is required and its policy is set to automatically send Authorisation Code, then the Authorisation Code will also be sent in the same message.

    To complete automatic provisioning of clients you will also need to configure the Message Channel fields "Primary Delivery Channel:" and "Secondary Delivery Channel:"

  • Manual
    DualShield will not send out a download link to the user (the user will need to find and download the MobileID from app stores).



Expandable Policy Sections



The expandable sections can be broken down as follows;

Anchor
Expiration
Expiration
EXPIRATION

Include Page
DualShield6:GoogleAuthenticator: Expiration
DualShield6:GoogleAuthenticator: Expiration

Anchor
TokenActivation
TokenActivation
TOKEN ACTIVATION

Include Page
DualShield6:GoogleAuthenticator: Token Activation
DualShield6:GoogleAuthenticator: Token Activation

Anchor
ChannelSystem
ChannelSystem
DELIVERY CHANNELS USED BY THE SYSTEM

Include Page
DualShield6:GoogleAuthenticator: Delivery Channel Used by the System
DualShield6:GoogleAuthenticator: Delivery Channel Used by the System

Anchor
ChannelUsers
ChannelUsers
DELIVERY CHANNELS AVAILABLE TO USERS

Include Page
DualShield6:GoogleAuthenticator: Delievery Channels Available to Users
DualShield6:GoogleAuthenticator: Delievery Channels Available to Users

Anchor
Download
Download
TOKEN DOWNLOAD

Include Page
DualShield6:GoogleAuthenticator: Token Download
DualShield6:GoogleAuthenticator: Token Download

Anchor
Synchronisation
Synchronisation
SYNCHRONISATION

Include Page
DualShield6:GoogleAuthenticator: Synchronisation
DualShield6:GoogleAuthenticator: Synchronisation

Anchor
PIN
PIN
PIN

Include Page
DualShield6:GoogleAuthenticator: PIN
DualShield6:GoogleAuthenticator: PIN