Authentication Methods
Your Ivanti Secure Access Client administrator can configure a Ivanti Secure Access Client connection to use any of the following authentication methods:
-
Time-based One-Time Password (TOTP)—Time-based One-Time Password (TOTP) is an algorithm that uses a shared secret key and the current time to compute a password (that is, a token) that can be used only once and that expires after a short period. The Ivanti Secure Access Client and the Ivanti Connect Secure (ICS) 8.2R5 gateway support Google’s TOTP authentication server (Google Authenticator).
Google Authenticator can be configured only as a secondary authentication server.
End users must register with a TOTP server before this authentication type can be used. Generally, registration involves connecting to the TOTP authentication server (example, the ICS gateway) with a web browser, passing a primary authentication, and accessing a TOTP registration key, QR code and backup codes. After a user scans the QR code or manually enters a registration key with the Google Authenticator app on a mobile device, a 6-digit token will be generated every 30 seconds by the app for that user. These tokens can be entered in the Ivanti Secure Access Client for TOTP authentication.
- Token authentication—RSA SecurID token
authentication, also called two-factor authentication, generates credentials
that are difficult to compromise. A token code is generated simultaneously
on both the client and server. You create a personal identification
number (PIN), and then the username and the PIN plus the current token code permit you to log
into the server. A PIN plus a token code forms a passcode. A token code expires
after a short interval and is then replaced by a newly generated token
code. The first time you use the system, Ivanti Secure Access Client prompts you to create
a PIN. If your administrator has provided a PIN, you are prompted
to change it. If your administrator requires you to change your PIN
periodically, Ivanti Secure Access Client prompts you for a new PIN. Typically, you must
provide the current token code when you change your PIN. In some cases,
after entering your passcode, you are prompted to enter the next token
code before you can access the network. Just wait until your token
device displays a new token code, and then enter that number to proceed.
The device or software that generates the token is called an authenticator. Ivanti Secure Access Client supports the full range of SecurID hardware and software authenticators. Hardware (physical) authenticators display a new token code every 60 seconds. You must have the card or key fob that generates the token with you when you log in. At the Ivanti Secure Access Client login window, you provide your username and your PIN plus the current token code. A USB authenticator can store your Windows username/password credentials and digital certificates. When the device is connected to your computer, it enables automatic token code entry and Ivanti Secure Access Client automatically accesses token codes directly off the device after you provide your PIN.
Software authenticators include smartphone apps, software for desktop and laptop computers, and browser-based applications. Your Ivanti Secure Access Client log in procedure with a software authenticator depends on how your security administrator has configured the system. Typically, if you have the SecurID software installed on your endpoint, Ivanti Secure Access Client interacts with the software to retrieve the token code after you provide your PIN.
-
Smart card authentication—A smart card is a plastic card that includes embedded user authentication information. If your environment is configured with multiple digital certificates, Ivanti Secure Access Client prompts you to select one. Typically, if you have a smart card reader configured on your endpoint, Ivanti Secure Access Client interacts with the smart card software to retrieve the token code after you provide your PIN.
- Machine authentication—Machine authentication uses machine credentials to authenticate the endpoint. The credentials are generated by Active Directory when the machine joins a domain. The endpoint must be a member of a Windows domain. Depending on how your administrator has configured the authentication process, you might be prompted for your Windows credentials.
-
Credential provider—Ivanti Secure Access Client credential provider integration enables connectivity to a network that is required for you to log in to the Windows domain. For example, the Windows domain controller might reside behind a firewall, and Ivanti Secure Access Client uses credential provider login to connect to a Ivanti Secure Access Client server prior to domain login. Ivanti Secure Access Client integrates with Microsoft credential providers to enable password-based login and smart card login. A credential provider interface appears as a tile on a Windows Vista, Windows 7, or Windows 8 login screen. The Ivanti Secure Access Client connection may be configured so that Ivanti Secure Access Client prompts are presented during the login process, for example, prompts for realm or role selection. Ivanti Secure Access Client upgrade notifications and actions are disabled during credential provider login and postponed until the connection is established.