Previous Topic: ArcotID PKI FlowsNext Topic: ArcotID PKI Roaming Flow


ArcotID PKI Only Flow

The ArcotID PKI Only flow defines the steps that must be performed to authenticate end users with the ArcotID PKI credential only. At runtime, this flow takes effect only if the AcrotID PKI credential is enabled.

This section describes the end-user authentication flow based on the following assumptions:

End users are authenticated as follows:

  1. When trying to access a protected resource in a browser, the end user is prompted for their user name and LDAP password.
  2. The Advanced Authentication service then verifies that the end user is an existing user, and checks for the presence of an ArcotID PKI credential on the device being used.
  3. Since ArcotID PKI is present on the device, the Advanced Authentication service authenticates the user.
  4. If authentication is successful, the end user is granted access to the resource.