Previous Topic: Configuring OATH OTP SettingsNext Topic: Configuring OATH OTP Authentication Policy


Configuring OATH OTP Issuance Profile

An OATH OTP profile can be used to specify the following attribute related to an OATH One-Time Password (OATH OTP Token) credential:

By configuring an OATH OTP profile and assigning it to one or more organizations, you can control the characteristics of OATH OTP Token credentials that are issued to users of those organizations. Use the OATH OTP Profiles page to create OATH OTP Token credential profiles.

Follow these steps:

  1. Click the Services and Server Configurations tab on the main menu.
  2. Verify that the CA Strong Authentication tab in the submenu is active.
  3. Under the OATH OTP Token section, click the Issuance link to display the OATH One Time Password Profiles page.
  4. Edit the fields in the Profile Configurations section, as required.
    Profile Configurations
    Create

    If you choose to create a profile, then:

    • Select the Create option.
    • Specify the Configuration Name of the new profile in the field that appears.
    Update

    To update an existing profile, select the profile that you want to update from the Select Configuration list that appears.

    Copy Configuration

    Enable this option to create the profile by copying the configurations from an existing profile.

    Note: You can also copy from configurations that belong to other organizations that you have scope on.

    Available Configurations

    Select the profile from which the configurations will be copied.

    Validity Start Date

    Set the date from when the issued OATH OTP Token credential will be valid.

    The validity can start from either the date when this credential is created or you can specify a custom date.

    Validity End Date

    Set the date when the OATH OTP Token will expire.

    You can choose any of the following options to set the expiration date:

    • Specify the duration
    • Specify a custom date
    • Choose Never Expires option if you want the OATH OTP Token to not expire at all.
  5. Expand the Advanced Configurations section by clicking the [+] sign.
  6. In the Custom Attributes section, specify any extra information in the Name-Value pair format. For example, the organization information that can be used by plug-ins.
  7. Set the following in the User Validations section:
  8. In the Multiple Credential Options section, enter the description to identify the purpose for which the OATH OTP Token is used in the Usage Type field. For example, a user can have a temporary credential to perform a remote login to the network, the usage type for this credential can be temporary.
  9. Click Save.
  10. Refresh all deployed CA AuthMinder Server instances. See Refresh a Server Instance for instructions about the procedure.