- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Setting Intial PIN
I've searched quite a bit, but have been unable to find where a user's PIN can be set for the first login. We are almost ready to begin testing SecurID soft tokens to authenticate to our network and we'd like to use the PIN + tokencode authentication method. However, I cannot seem to find where these PINs are set initially. Is this something that can only be done once the Web Tier service is live? Or is there another location or step I'm missing.
- Tags:
- authenication
- Authenticator
- Authenticators
- Community Thread
- Discussion
- Forum Thread
- PIN
- RSA SecurID
- RSA SecurID Access
- SecurID
- Token
- Token Auth
- Token Authentication
- Token Authenticator
- Token Authenticators
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There are various ways to do it.
How the system is designed is: Users set up their own pin so no one else knows what it is (more secure).
Normally, there is no pin at the beginning, and the first device the user logs into will prompt the user
to set up a new pin once the tokencode alone works for a login attempt.
If you allow token provisioning on the self service console, one option there is that users can set up
a new pin ahead of time. So, on first use of the token they just use the pin+tokencode first time.
A workaround for an administrator to set up a pin for a user ahead of time, without the user
being involved, could be:
-assign a token to a user
-generate an emergency tokencode for that token
-the admin can log into self-service or security console as that userid and emergency code
-the emergency code login will ask to set up a new pin if the token was in new pin mode
-once you set the pin using the emergency code, that same pin applies to the token itself
AMBA can also be configured to set pins for tokens. Any command that can edit/assign a token and
also has the SetPin capability. *AUP has SetPin also but that is for a fixed passcode, not a token.
AMBA CPS (change pin status) explicitly just manages pins for assigned tokens..
Change PIN Status provides the following functionality:
-Clear the PIN associated with the specified token serial. The token will automatically
be placed in new PIN mode.
-Set the PIN associated with the specified token serial to an explicit value.
-Force the specified token serial into new PIN mode.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There are various ways to do it.
How the system is designed is: Users set up their own pin so no one else knows what it is (more secure).
Normally, there is no pin at the beginning, and the first device the user logs into will prompt the user
to set up a new pin once the tokencode alone works for a login attempt.
If you allow token provisioning on the self service console, one option there is that users can set up
a new pin ahead of time. So, on first use of the token they just use the pin+tokencode first time.
A workaround for an administrator to set up a pin for a user ahead of time, without the user
being involved, could be:
-assign a token to a user
-generate an emergency tokencode for that token
-the admin can log into self-service or security console as that userid and emergency code
-the emergency code login will ask to set up a new pin if the token was in new pin mode
-once you set the pin using the emergency code, that same pin applies to the token itself
AMBA can also be configured to set pins for tokens. Any command that can edit/assign a token and
also has the SetPin capability. *AUP has SetPin also but that is for a fixed passcode, not a token.
AMBA CPS (change pin status) explicitly just manages pins for assigned tokens..
Change PIN Status provides the following functionality:
-Clear the PIN associated with the specified token serial. The token will automatically
be placed in new PIN mode.
-Set the PIN associated with the specified token serial to an explicit value.
-Force the specified token serial into new PIN mode.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Many thanks Edward. This is very helpful.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Keith Gilesā,
Edward Davisā's answer is absolutely correct. For documentation to hand to your end users so they can navigate New PIN Mode, you may want to provide them with one of the following Quick Start Guides, based on the token app they use:
RSA SecurID Software Token 2.2 for Android Quick Start
RSA SecurID Software Token 2.3 for iOS Quick Start
RSA SecurID Software Token 5.0 for Windows Quick Start
All of the software token documentation can be found on the documentation pages for RSA SecurID Software Token Authenticators.
Regards,
Erica
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Many thanks Erica. These guides should be very helpful for educating our end users.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
