Hardware TOTP
Hardware TOTP can be used for authentication in the following modules:
- ADFS Extension
- Enterprise SSO
- Identity Provider
- IIS Extension
- NPS RADIUS Extension
- RDP Windows Logon
- Windows Logon
Hardware TOTP allows you to obtain one-time passwords with the following devices:
- The eToken PASS standalone one-time password generator. It can be used for authentication in any applications and services, including those that support the RADIUS authentication protocol — VPN, Microsoft ISA, Microsoft IIS, Outlook Web Access, and others.
Device characteristics
| Device | File format | Algorithm | Refresh period |
|---|---|---|---|
| eToken PASS | XML | SHA1 | 30 seconds |
Provider ID
{CEB3FEAF-86ED-4A5A-BD3F-6A7B6E60CA05}
Install the provider
- Run the installation file located at
axidian <Version number>/Axidian Providers/Axidian Hardware TOTP Provider/<Version number>and follow the steps of the installation wizard. - After the installation is complete, a system restart may be required. If the installation wizard prompts you to restart the system, confirm this action.
- To remove or restore the product, open the Control panel menu and use the standard procedure for the supported operating systems.
Add a device
You can add a device manually or by uploading a file with the device parameters.
A device can be registered for one user only.
Add manually
To add an eToken PASS device:
- Open the Management Console.
- In the menu on the left, select Devices.
- Click Add device.
- In the window that opens, select the eToken PASS model.
- Fill in the Serial number, Secret key, and Comment fields (the last one is optional) and click Add.
Add from a file
To add an eToken PASS device:
- Open the Management Console.
- In the menu on the left, select Devices.
- Click Add from file.
- In the window that opens, select the eToken PASS model.
- In the window that opens, select the XML file with the device parameters and click Add.
Synchronize a device
To synchronize a device:
- Open the Management Console.
- In the menu on the left, select Devices.
- Select the device from the list and click Synchronize.
- In the new window that opens, in the One-time password 1 and One-time password 2 fields, enter the passwords from the device and click Synchronize.
Change the serial number and disable a device
To edit a device:
- Open the Management Console.
- In the menu on the left, select Devices.
- In the Authentication provider drop-down list, select Hardware TOTP, in the Serial number field enter the device serial number if you know it, and click Search.
- Select the device found and click the edit icon.
Example
- In the editing window, you can change the device serial number or the comment, or disable the device. After you make the changes, click Save.
Example
Delete a device
You can delete a device manually or by uploading a file with the device parameters.
Delete manually
To delete a device:
- Open the Management Console.
- In the menu on the left, select Devices.
- In the Authentication provider drop-down list, select Hardware TOTP, in the Serial number field enter the device serial number if you know it, and click Search.
- Select the device found and click Delete device.
- In the window that opens, confirm the deletion.
Delete from a file
To delete an eToken PASS device:
- Open the Management Console.
- In the menu on the left, select Devices.
- Click Delete from file.
- In the window that opens, select the eToken PASS model.
- In the window that opens, select the XML file with the device parameters and click Delete.