POLICIES – Challenge (tab)
The POLICIES > Challenge tab shows the challenge settings of the policy.
Field name | Description |
---|---|
1-Step Challenge/Response | |
Permitted |
Controls whether 1-step Challenge/Response logins will be enabled for the current policy and, if so, where the challenge should originate. To enable 1-step Challenge/Response, you also need to set Challenge Check Mode (see POLICIES – DP Control Parameters (tab)). Note that 1-step Challenge/Response is not applicable in a RADIUS environment. Possible values:
|
Challenge Length |
Specifies the length of the challenge (excluding a check digit) which should be generated for 1-step Challenge/Response logins. |
Add Check Digit | A check digit may be added to the generated challenge. This allows the authenticator to identify invalid challenges more quickly. |
2-Step Challenge/Response | |
Request Method |
The method by which a user has to request a 2-step Challenge/Response logon. This is the only mode of Challenge/Response available in a RADIUS environment. The request is made in the password field during logon. The keyword is specified by Request Keyword. The request fails if the user does not have a Challenge/Response-capable authenticator assigned. This includes authenticator applications of type CR, SG, and MM. Possible values:
|
Request Keyword |
Defines the keyword that a user must enter to request a 2-step Challenge/Response logon if a method using a keyword is selected as Request Method. This can be left blank. |
Available actions
- Edit
- Delete