

CA CloudMinder Advanced Authentication › How Advanced Authentication Works › End User Authentication Flows › ArcotID PKI Flows › ArcotID PKI Roaming Flow
ArcotID PKI Roaming Flow
This section describes the authentication flow for an end user who is enrolled for advanced authentication but is using a different device to which the ArcotID PKI credential has not been provisioned.
End users are authenticated as follows:
- When trying to access a protected resource in a browser, the end user is prompted for their user name and LDAP password.
- The Advanced Authentication service verifies that the end user is an existing user, and checks for the presence of an ArcotID PKI credential on the device being used.
- Since ArcotID PKI is not present on the device, the end user is prompted for secondary authentication using the security question or security code mechanism.
- If the authentication is successful, depending on whether two-step authentication is enabled or not, either of the following steps take place:
- If two-step authentication is not enabled, the ArcotID PKI credential is downloaded to the end user's device.
- If two-step authentication is enabled:
- The end user is authenticated again using a second form of authentication.
Note: If security question was used the first time, then security code is used in this step. Conversely, if security code was used the first time, then security question is used in this step.
- If the verification is successful, the ArcotID PKI credential is downloaded to the end user's device.
Note: Two-step authentication is not enabled for authentication using the ArcotID PKI mobile client. When a mobile client is used, all configured authentication methods are used one after the other.
- The browser then displays the login page with the user name, prompting the end user for the password again.
Note: Apple devices may not prompt for a password.
- The Advanced Authentication service then authenticates the user.
- If authentication is successful, the end user is granted access to the resource.
Copyright © 2014 CA.
All rights reserved.
 
|
|