Monday, 2013-07-22

*** nowen (~nowen@2600:1003:b10d:ea5d:e426:ca49:d38d:f93e) has joined #wikid13:35
*** nowen1 (~nowen@46.sub-70-208-149.myvzw.com) has joined #wikid14:38
*** nowen has quit (Ping timeout: 240 seconds)14:39
*** nowen (~nowen@233.sub-70-208-161.myvzw.com) has joined #wikid16:06
*** nowen1 has quit (Ping timeout: 246 seconds)16:06
*** nowen has quit (Ping timeout: 256 seconds)16:10
*** nowen (~nowen@101.sub-70-208-153.myvzw.com) has joined #wikid16:53
AngelHi Nick.17:39
nowenhi angel17:51
AngelQuestion. How would I use a locked token with Preregistration.17:55
nowenin pre-registration, you create a list of users and pre-shared secrets.  you upload the list to the wikid server under Users/Pre-register user.  then you securely deliver each user their secret17:57
nowenthey enter the secret and double enter their pin in the token17:58
nowenand they are registered!17:58
nowenif you look on the Pre-register users page, you will see the format for the list17:59
AngelWe usually preregister the user. What then is different between the locked and the unlocked token. They seem to function the same.18:01
nowenthe locked token takes some data from the computer during registration and hashes it such as the cpu id.18:01
nowenit sends this to the server during registration18:02
noweneach OTP request must also contain this has18:02
nowenh18:02
nowenthat keeps users from moving the token18:02
nowenit also has the variable pin-pad18:02
AngelSo would you recommend I deploy the locked token or the non locked for desktops in our corporate offices.18:09
nowenwill these users only be logging in from those desktops?18:11
nowenif you are worried that they might try to load up the tokens on usb drives and work from home or if you are worried about malware stealing the tokens, then use the locked tokens.18:17
nowenif you want users to be able to move tokens around use the unlocked tokens18:18
nowendoes that make sense, Angel?18:28
AngelYes makes sense.18:31
AngelSo functionality wise its no different than the unlocked for preregistering a user correct?18:32
*** nowen has quit (Ping timeout: 246 seconds)18:34
*** nowen (~nowen@2600:1003:b105:1722:caf7:33ff:fef1:d35d) has joined #wikid18:50
AngelSo functionality wise its no different than the unlocked for preregistering a user correct?18:56
*** nowen1 (~nowen@2600:1003:b126:2d93:e426:ca49:d38d:f93e) has joined #wikid18:57
*** nowen has quit (Ping timeout: 240 seconds)18:57
*** nowen1 is now known as nowen_also18:57
*** nowen_also is now known as nowen18:57
nowenAngel: sorry - did I miss anything?18:58
AngelI was asking: So functionality wise its no different than the unlocked for preregistering a user correct?19:02
nowenthat is correct19:02
*** nowen has quit (Ping timeout: 240 seconds)20:48

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!