An ArcotID PKI policy can be used to specify the following attributes related to ArcotID PKI-based authentication:
Note: If the user status check is enabled, then the authentication for users in inactive state results in failure.
Note: Exercise caution while using these options.
To configure a global ArcotID PKI authentication policy:
|
Field |
Description |
|---|---|
|
Policy Configurations |
|
|
Create |
If you choose to create a new policy, then:
|
|
Update |
If you choose to update an existing policy, then select the policy that you want to update from the Select Configuration list that appears. |
|
Copy Configuration |
Enable this option if you want to create the policy by copying the configurations from an existing policy. Note: You can also copy from configurations that belong to other organizations that you have scope on. |
|
Available Configurations |
Select the policy from which the configurations will be copied. |
|
Lockout Credential After |
Specify the number of failed attempts after which the user credential will be locked. |
|
Check User Status Before Authentication |
Select this option if you want to verify whether the user status is active, before authenticating them. |
|
Field |
Description |
|---|---|
|
Advanced Configurations |
|
|
Issue Warning |
Specify the number of days before the warning is sent to the calling application about the user’s impending ArcotID PKI credential expiration. |
|
Allow Successful Authentication |
Specify the number of days for which the users can use an expired ArcotID PKI credential to successfully log in. |
|
Enable Automatic Credential Unlock |
Select this option if you want a locked credential to be automatically unlocked after the time you specify in the Unlock After field. This field is valid only if you specify the corresponding value in the Lockout Credential After field. |
|
Unlock After |
Specify the number of hours after which a locked credential can be used again for authentication. |
|
Challenge Validity (in Seconds) |
Specify the duration for which the ArcotID PKI challenge has to be valid. |
|
Multiple Credential Options |
|
|
Usage Type for Verification |
If you want users to authenticate with the particular ArcotID PKI, then enter the name of its usage type in this field. If you do not specify the usage type, then the usage type mentioned in the default ArcotID PKI authentication policy is used. |
|
Copyright © 2013 CA.
All rights reserved.
|
|