The authentication method configuration is done using Ubisecure SSO Management or the LDIF import files provided by Ubisecure SSO installation.
Any required authentication methods used by users must now be created according to the general guidelines concerning creating authentication methods into Ubisecure SSO.
Typical methods include username and password, SMS OTP, One TIme Password Printout and third-party banking services (TUPAS). Add only the methods that will be used in the current installation:
CustomerID Password
password.2
SPI Password
Set directory to: CustomerID Directory
By default user logs in using the login attribute (which is uid
in Ubisecure Directory and sAMAccountName
in Active Directory). If you want the user to login using email address, you must add directory.account.login=mail
to the configuration string. You must also add general.login.attribute=mail
to eidm2.properties
. Create eidm2.properties
text file under /usr/local/ubisecure/customerid/application/custom
Set the optional policy.password.expiring
configuration string to show a warning to users during login of a pending password expiry. The value is number of minutes. 10080 is one week. This number should be increased accordingly if users rarely use the system.
SMS
ubikey.sms.1
SPI Mobile Phone
Set directory to: CustomerID Directory
Figure 4. SMS method |
uid
in Ubisecure Directory and sAMAccountName
in Active Directory). If you want user to login using email address, you must add directory.account.login=mail
to the configuration string. You must also add general.login.attribute=mail
to eidm2.properties
. Create eidm2.properties
text file under /usr/local/ubisecure/customerid/application/custom
password-name
configuration string. It should contain the name of the used password method (usually password.2).
You need to define the smsUrl
configuration string. It should contain the URL of the SMS server.
Figure 5, SMS URL |
methodUserGroupDN
configuration string. It points to the AD group which defines those users that are allowed to use SMS authentication. The relative name of the correct group is ActiveSMSUser.
The whole DN is installation specific. Typically Active Directory is not used as the main user repository for Ubisecure CustomerID. One Time Password
ubikey.otp.1
SPI Ubikey OTP Printout
Set directory to: CustomerID Directory
uid
in Ubisecure Directory and sAMAccountName
in Active Directory). If you want users to login using their email addresses, you must add directory.account.login=mail
to the configuration string. You must also add general.login.attribute=mail
to eidm2.properties
. Create eidm2.properties
text file under /usr/local/ubisecure/customerid/application/custom
password-name
configuration string. It should contain the name of the used password method (usually password.2
).If Active Directory is used as the main user repository then you need to define the userCredentialsTableDN
configuration string. It defines the name of the OTP table object in Ubisecure Directory. OTP Printout authentication method information is stored in Ubisecure Directory for all Active Directory users who use the OTP Printout method and that information will be stored under the OTP table. Typically Active Directory is not used as the main user repository for Ubisecure CustomerID.
Figure 6, OTP Printout Method, configuration string parameters will be shown after next part |
For sending the OTP list from within the Ubisecure SSO Management application the mailSessionJNDIName configuration string must be set. In most cases, this field can be left blank as it is not required for self-service list management using Ubisecure CustomerID.
Figure 7, OTP Printout Configuration Strings |