Vasco Digipass Plug-In Novell NMAS manual

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33

Go to page of

A good user manual

The rules should oblige the seller to give the purchaser an operating instrucion of Vasco Digipass Plug-In Novell NMAS, along with an item. The lack of an instruction or false information given to customer shall constitute grounds to apply for a complaint because of nonconformity of goods with the contract. In accordance with the law, a customer can receive an instruction in non-paper form; lately graphic and electronic forms of the manuals, as well as instructional videos have been majorly used. A necessary precondition for this is the unmistakable, legible character of an instruction.

What is an instruction?

The term originates from the Latin word „instructio”, which means organizing. Therefore, in an instruction of Vasco Digipass Plug-In Novell NMAS one could find a process description. An instruction's purpose is to teach, to ease the start-up and an item's use or performance of certain activities. An instruction is a compilation of information about an item/a service, it is a clue.

Unfortunately, only a few customers devote their time to read an instruction of Vasco Digipass Plug-In Novell NMAS. A good user manual introduces us to a number of additional functionalities of the purchased item, and also helps us to avoid the formation of most of the defects.

What should a perfect user manual contain?

First and foremost, an user manual of Vasco Digipass Plug-In Novell NMAS should contain:
- informations concerning technical data of Vasco Digipass Plug-In Novell NMAS
- name of the manufacturer and a year of construction of the Vasco Digipass Plug-In Novell NMAS item
- rules of operation, control and maintenance of the Vasco Digipass Plug-In Novell NMAS item
- safety signs and mark certificates which confirm compatibility with appropriate standards

Why don't we read the manuals?

Usually it results from the lack of time and certainty about functionalities of purchased items. Unfortunately, networking and start-up of Vasco Digipass Plug-In Novell NMAS alone are not enough. An instruction contains a number of clues concerning respective functionalities, safety rules, maintenance methods (what means should be used), eventual defects of Vasco Digipass Plug-In Novell NMAS, and methods of problem resolution. Eventually, when one still can't find the answer to his problems, he will be directed to the Vasco service. Lately animated manuals and instructional videos are quite popular among customers. These kinds of user manuals are effective; they assure that a customer will familiarize himself with the whole material, and won't skip complicated, technical information of Vasco Digipass Plug-In Novell NMAS.

Why one should read the manuals?

It is mostly in the manuals where we will find the details concerning construction and possibility of the Vasco Digipass Plug-In Novell NMAS item, and its use of respective accessory, as well as information concerning all the functions and facilities.

After a successful purchase of an item one should find a moment and get to know with every part of an instruction. Currently the manuals are carefully prearranged and translated, so they could be fully understood by its users. The manuals will serve as an informational aid.

Table of contents for the manual

  • Page 1

    Using Digipass Strong User Authentication with Novell NMAS and ICHAIN[...]

  • Page 2

    Using Digipass Strong User Authentication with Novell NMAS and ICHAIN Contents Contents ........................................................................................................................................................................................................... 2 Overview ...............................................[...]

  • Page 3

    Overview This document shows you how Novell IChain and NMAS optimizes its authentication by integrating VASCO Digipass for strong user auth entication and offering several secure web and RADIUS access solutions. Situation – Description As electronic connectivity, where hackers, vir uses, electronic eavesdr opping and fraud can threaten the commun[...]

  • Page 4

    Technical Concept Topology Concept – Fig www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 4[...]

  • Page 5

    Novell Components Description NMAS Novell® Modular Authentication Service is an extensible security product that offers you an easy way to centrally manage multiple authentication methods across your network. With Novell Modular Authentication Service, you can implement stronger forms of authentication and authorization to secure your critical co [...]

  • Page 6

    • • • Proxy-server clustering Server fault tolerance Support for Remote Authentication Dial-I n User Service protocol (RADIUS) Novell iChain is the ideal product to secure and accelerate your company's transformation to eBusiness. It is also a key component of Novell Secure Access™, Novell's comprehensive security suite. VASCO Com[...]

  • Page 7

    • • • • User-managed passwords are the single largest cause of incorrect authentication VASCO delivers strong authentication and guar antees data integrity for electronic transactions by means of the Digipass Family of Tokens. In the concept, we implemented the cures for the weak areas of authentication and data in tegrity. To avoid the sta[...]

  • Page 8

    our Digipass Family of tokens. These mode s are the Response-Only mode, the Challenge- Response mode and the Digital Signature mode. But first we will start by showing you the complete application cycle of the Digipass token usage. Databases and Files General concept for Digipass Family hardware token usage (Fig 1a) The first step is the tokens are[...]

  • Page 9

    (Fig 1b) Once this is done, the application ow ner will assign those Digipass secrets to their end-users. This assignment is done based on th e serial number of the Digipass token and the name of the end-user. The Digipass token is th en shipped to the end-user together with a manual and the protected PIN-co de on a secure PIN-mailer. Once the toke[...]

  • Page 10

    Airlines site (web server 10.0.0.1), two subnets ar e configured. As the lo cal data or e-business applications resides on the 10.0.0.0 subnet (Fig 3), address translation will enable transparent access. Fig 3 Radius will be the Protocol used for Authentication, as such, a Radius profile needs to be configured. Fig 3a, 3b www.vasco.com ∙ Using Di[...]

  • Page 11

    Fig 3a Select auth entication, then sel ect radius aut hentication. Fig 3b Configure th e IP Address of the R adius Server www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 11[...]

  • Page 12

    Configuration of NMAS NMAS System Settings In this section we need to configure the type of services to be u sed in order to access its’ resources. The services are user-related. Configuring Radius Access is done in two steps : 1. Add the Radius Dial Access Service 2. Add the Radius Dial Access Protocol (Here we can provide attributes or we can j[...]

  • Page 13

    Services represents the Radius Dial Access Protocol. Double click on Services www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 13[...]

  • Page 14

    Select the RADIUS_DAS Service. www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 14[...]

  • Page 15

    We finished configuring the Radius_DAS Service. Now we need to specify the Radius Protocol . For example Callback , ….. Click Add to configure. www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 15[...]

  • Page 16

    Once again select Services. www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 16[...]

  • Page 17

    Select RADIUS_DAP and click OK. You can rename it to Radius Dial Access Protocol. When no method is specified, adds `default` . Example. Radius Dial Access Protocol. [DEFAULT] www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 17[...]

  • Page 18

    NMAS VASCO Digipass import Configure VASCO Digipass container Fig 5 As NMAS has VASCO integrated, there is only th e need to co nfigure th e service and activate it.Configuration of a container for Digipasse s is done through creating a new object in Services. Fig 5 www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and I[...]

  • Page 19

    Fig 6 VASCO Digipass container will contain the VA SCO Digipass token object, for which you can give a friendly name. Fig 6 www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 19[...]

  • Page 20

    Fig 7 For importing tokens, a VASCO Digipass token object is created. This object will contain all Digipasses and their functions conform the initializ ation sheet. This is also the location where a user will be assigned a Digipass. Fig 7. In order to import tokens, the location of the dpx file and its’ encryption key need to be provided. www.vas[...]

  • Page 21

    Import Dpx files Fig 8. This is also the location where a user will be a ssigned a Digipass. Fig 8. In order to import tokens, the location of the dpx file and its’ encryption key need to be provided. NMAS User-VASCO Digipass Management Assignment users In this section we need to configure type of authentication a user is configured for and the t[...]

  • Page 22

    Fig 9 Fig 9 represents the DNS structure where Digital Airlines is the applicationas well as the container where all users accessing it, will be re gistered and given permissions, levels of access and type of authentication. Fig 10. By selecting the properties of a newly created user, a Digipass is assigned to that user. Fig.10 To be sure that the [...]

  • Page 23

    Activation Authenti cation Method – VASCO Digipass Authentication Fig 12 For each user select the authentication method . Here we select the VASCO token. Fig 12 Configuration of Radius Novell For detailed configuration of Radius within th e Novell Radius Service, we refer you to visit http://www.novell.com VASCO As in this example we integrated N[...]

  • Page 24

    Configuration of Web Novell For more information regarding configuration or product details, we refer to http://www.novell.com Other web servers, services In the current scenario we used the Novell web server. To find other web solutions VASCO has fully support on Apache or IIS. http://www.microsoft.com http://www.apache.org Conclusion ICHAIN and N[...]

  • Page 25

    Appendix A – Delta Airlines Access Examples Authentication – Authoriz ation over IChain secured www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 25[...]

  • Page 26

    www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 26[...]

  • Page 27

    www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 27[...]

  • Page 28

    Appendix B Local Netw ork Log on VASCO – Challenge Response Authentication Novell NMAS will present you the VASCO challeng e which needs to be entered into a token in order to enter the correct response into the `Enter password` field. Once authenticated by VASCO, NMAS presen ts the NDS stat ic password as second verification. Authentication sett[...]

  • Page 29

    www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 29[...]

  • Page 30

    Appendix C – The V ASCO VRM & T ok ens w ork with BM (BMAS) VPN Ser vices VPN Secure Authentication with The Digipass 300 and the Digipass Go-1 with PIN+RESPONSE When defining the Login Policy Rule for VPN, the External Login Service Method must be defined as MANDATORY. You cannot use "Required if assigned" So, it is a global settin[...]

  • Page 31

    Founded: 1997 Web: www.VASCO.com CEO Ken Hunt President and COO: Jan Valcke Employees: 80 Worldwide Headquarters: 1901 South Meyers Road, Suite 210, Oakbrook Terrace, Illinois, USA European Headquarters: Koningin Astridlaan 164, B-1780 Wemmel, Belgium VASCO Product Range: VACMAN : Authentication, Authorization, Administration, AAA Security Digipass[...]

  • Page 32

    • • • • • • • • • Digipass Pro 700 offers sophisticated and yet use r-friendly strong authentication services with extended digital signature capability. Digipass Pro 800 is used by severa l top tier banking institutions worldwide and is strongly appreciated by the banks and their clients for securing full access to financial appl[...]

  • Page 33

    www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 33 • • VACMAN Server for Networks provides strong user authentication and access control management for RADIUS and LAN environments in a fully integrated system. VACMAN Server for Web delivers access control to Web enabled applications, whether Internet[...]