
Display Name:
• The value entered (typically the UserID) is displayed by the token before the
passcode is displayed. Maximum length is 8 characters.
PIN Style:
PIN styles are separated into two general groups: “Stored on Server” or “Token Activated
by PIN”. The RB-1 also supports a “No PIN” option, although this is not recommended.
Stored on Server requires the user to prepend the PIN to the passcode displayed on the
token. The combination of the PIN and passcode form the password that is used to
authenticate the user (the passcode cannot be used to authenticate unless the PIN is
prepended). The PIN is not input into the token (i.e. it is not required to activate the token
and generate a passcode).
• Stored on server, Fixed PIN: this PIN must be prepended to the passcode. An
Operator can change the PIN. This mode emulates SecurID PIN mode.
• Stored on server, User-changeable PIN: periodic PIN change is forced by the
Server according to the PIN Change Period option. The user will determine the new
PIN value within the limits set under the Min PIN Length, Try Attempts, and Allow
Trivial PINs options. This PIN must be prepended to the passcode. This mode
emulates the SecurID PIN mode. If a token in this mode becomes locked by
exceeding the Try Attempts value and is re-enabled, the user must authenticate at
least once before the token Try Attempts is reset to its default value.
• Stored on server, Server-changeable PIN: periodic PIN change is forced by the
Server according to the PIN Change Period option. The Server will determine the
new PIN value within the limits set under the Min PIN Length, Try Attempts, and
Allow Trivial PINs options. This PIN must be prepended to the passcode. This
mode emulates the SecurID PIN mode. This mode is currently not supported when
performing MSCHAPv2 authentication requests. If a token in this mode becomes
locked by exceeding the Try Attempts value and is re-enabled, the user must
authenticate at least once before the token Try Attempts is reset to its default
value.
Initial PIN modifications for a Stored on Server PIN only become active when
Reset Server-side PIN is selected.
Token Activated by PIN requires the user to key the PIN into the token before a passcode is
generated. In this mode, only the passcode displayed by the token is sent to the
authentication server; the PIN is not transmitted across the network.
Copyright © 2005 CRYPTOCard Corporation All Rights Reserved 3