Device Initialization Profiles and Policies
The Device Initialization Tool default profiles are organized into different directories (under the main Spl/Legacy directory) by device type.
The tables below list the policies included in all device profiles (as organized in the ActivID Token Configuration Utility).
Device Initialization Profile Policies:
Policy |
Parameter |
Parameter Values |
Description |
---|---|---|---|
PIN Policy |
PIN Protection |
|
The minimum time (in seconds) between two bad PIN entries to prevent brute force attacks. |
PIN |
Initial PIN (Fixed/random) |
1254 |
Initial PIN Code value. |
Number of Wrong PIN Entries Allowed |
1 to 15 Default is 6. |
Maximum number of wrong PIN entries allowed before the device locks. |
|
PIN length (min/max) |
0 to 8 Default is 4. |
Minimum/Maximum PIN length allowed when PIN is updated. |
|
Weak PIN Control |
|
Prevent the user from setting weak PIN codes (1234 2468 ...). |
|
Change PIN at first Use |
|
Force the user to change the initial PIN at device startup. |
|
Change PIN after unlock |
|
Force the user to change the PIN after unlocking their device. |
|
Use PIN in Blind Mode |
|
Use PIN in blind mode. |
|
Lock Policy |
Number of Unlock Attempts Allowed |
1 to 15 |
Maximum unlock attempts allowed before the device resets. |
Lock after wrong PIN |
|
Allow the device to lock after unsuccessful PIN entries. |
|
Reset when locked |
|
Allow the device to erase its contents after the number of allowed wrong unlock attempts is reached. |
Policy |
Parameter |
Parameter Values |
Description |
---|---|---|---|
User Authentication type |
Defines the Authentication service. |
||
Granularity Window (in seconds) |
1 to 32 Default is 8 seconds. |
Synchronous mode only. |
|
Challenge length (min/max) |
4 to 8 |
Asynchronous mode only. |
|
Host Verification |
|
Host Verification. |
|
Response Length |
6 to 8 Default is 8. |
Response One-Time Password generated in response to a challenge. See asynchronous authentication. code length. |
|
Counter Increment |
|
Enable diversification of the authentication key. |
|
Signature (AI) |
Signature Certification type |
|
Signature service type. |
Granularity Window (in seconds) |
1 to 32 Default is 8 seconds. |
Synchronous mode only. |
|
Host Verification |
|
Host Verification. |
|
Response length |
6 to 8 Default is 8. |
Response code length. |
|
Message |
Label |
Label of the data field. |
|
Length min |
0 to 10 |
Value minimum length. |
|
Length max |
1 to 10 |
Value maximum length. |
|
Maximum number of fields |
1 to 5 |
Number of fields to define. |
|
User Authentication (OATH) |
User Authentication type |
|
Authentication service type. |
Key Length (in bytes) |
20, 32, or 40 Default is 20. |
Only 20 bytes is supported by ActivID Appliance/Authentication Server. |
|
Validity Windows (in seconds) |
1 to 255 Default is 30. |
Time Stamping (only for Time Authentication). |
|
Truncation Offset |
|
Truncation Offset of the MAC. |
|
Response length |
6 to 8 Default is 6. |
Response code length. |
|
Qformat |
|
Only for OCRA. |
|
Add Checksum |
Boolean |
Not supported by ActivID Appliance/Authentication Server. |
|
Startup No Delay |
|
Only supported for Mini Token. |
|
Counter Display |
|
Only for Event-based authentication. |
|
Host Verification |
|
Host Verification. |
|
Challenge Length Max |
8 |
Challenge maximum length, use only for OCRA. |
|
Signature (OATH) |
Signature Type |
|
Define Signature service. |
Key Length |
20, 32 or 40 Default is 20. |
|
|
Validity Windows (in seconds) |
1 to 255 Default is 30. |
Time Stamping (only for Time Authentication). |
|
Truncation Offset |
|
Truncation Offset of the MAC. |
|
Response length |
6 to 8 Default is 6. |
Response code length. |
|
Add Checksum |
Boolean |
Add Checksum. |
|
Startup No Delay |
|
Startup No Delay. |
|
Counter Display |
|
Counter Display. |
|
Host Verification |
|
Host Verification. |
|
Message |
Label |
Label of the data field. |
|
Length min |
0 to 10 Default is 1. |
Value minimum length. |
|
Length max |
1 to 10 Default is 8. |
Value maximum length. |
|
Maximum number of fields |
1 to 5 |
Number of fields to define. |
Policy |
Parameter |
Parameter Values |
Description |
---|---|---|---|
Menu Mode |
Menu |
|
|
Application Mode |
Application |
Application 1 |
Authentication or signature service defined in Security Services associated with key 1. |
Application 2 |
Authentication or signature service defined in Security Services associated with key 2. |
||
Application 3 |
Authentication or signature service defined in Security Services associated with key 3. |
||
Misc Parameters |
Power Timeout |
0 to 127 Default is 30. |
Power Timeout in seconds. |
Lock Menu |
|
Menu is locked. |
|
Switch Off on Enter |
|
Switch off device on Enter. |
|
Token Messages |
|
All messages are limited to 10 characters. |
|
View Clock |
VIEW CLOCK |
|
|
Change Battery |
CHANGE BAT |
|
|
New PIN |
NEW PIN |
|
|
Confirm PIN |
CONFIRM |
|
|
Enter PIN |
ENTER PIN |
|
|
Last PIN Try |
LAST TRY |
|
|
Change PIN |
CHANGE PIN |
|
|
View Authentication Counter |
VIEW COUNT |
|
|
Locked |
LOCKED |
|
|
Ok |
COMPLETE |
|
|
Not Ok |
ERROR |
|
|
Enter Key |
INIT |
|
|
View Serial Number |
VIEW SN |
|
|
Manual Init |
INIT KEYS |
|
|
Wait |
WAIT |
|
|
Host Auth |
HOST AUTH |
|
|
Certification |
CERTIFICAT |
|
|
Sec Mod AS |
SEC MOD AS |
|
|
Challenge |
CHALLENGE |
|
|
Select App |
SELECT APP |
|
Policy |
Parameter |
Parameter Values |
Description |
---|---|---|---|
Speech |
Speech Behavior |
|
Set Speech Behavior (only for Desktop Token). |
Font |
Custom Font Name |
Font name |
Set a specific font (for all tokens except Mini Token and Flexi Token). |
Policy |
Parameter |
Parameter Values |
Description |
---|---|---|---|
File Format |
SDS Format |
|
Set SDS as the file format. |
PSKC Format |
|
Set PSKC as the file format. |
|
CSV Format |
|
Set CSV as the file format | |
Transport Key |
SDS Key Type |
|
Define the PSKC Transport Key. |
PSKC Key Type |
|
Define the SDS Transport Key. |
|
Exchange Mode |
Exchange List |
|
Exchange Mode List. |
Policy |
Parameter |
Parameter Values |
Description |
---|---|---|---|
Select Device |
Device List |
|
The list of available devices as determined by the previously selected parameters in PIN POLICY, SECURITY SERVICES and TOKEN BEHAVIOR. |