Smart Card
The Smart Card Provider component is designed for user authentication with personal devices (smart cards, USB keys).
Authenticators of this type can only be registered with the authenticator management tool.
This authentication method is supported in the following modules:
The following devices are supported:
eToken devices
- eToken Pro 32k
- eToken Pro 64k
- eToken Pro Java 72k
ESMART devices
- Token 64k
- Token SC 64k
- Token USB 64k
Avest devices
- Avest Key 256A
SafeNet devices
- iKey 1000
- iKey 1032
JaCarta devices
- JaCarta PKI
Gemalto devices
- IDPrime MD
The same authentication device can be used either with or without a PIN code request:
- The Smart Card Provider component allows the user to authenticate with a card without a PIN code request.
- The Smart Card Provider + PIN component requires a PIN code at every user authentication.
Smart Card Provider with PIN does not allow you to set, change, or delete the PIN codes of the authentication devices. To change or delete the PIN codes, use the dedicated software from the authentication device manufacturers.
Smartcard {0AF65AD8-DB77-4B64-B489-958D9B36E28C}
Smartcard + PIN {42456525-8EC1-4AB1-97B8-45AF8635D10F}
Prerequisites
The provider requires Bsp Broker installed on the Axidian Access server.
Files for Bsp Broker are located at axidian <Version number>/Axidian Providers/Axidian Bsp Broker/<Version number>.
- AuthProviders.BspBroker-<version number>.x64.en-us.msi — the installation package of Bsp Broker for 64-bit operating systems.
- AuthProviders.BspBroker-<version number>.x86.en-us.msi — the installation package of Bsp Broker for 32-bit operating systems.
Install the provider
- Run the installation file located at
axidian <Version number>/Axidian Providers/Axidian SmartCard Provider/<Version number>and follow the steps of the installation wizard. Install the provider both on the computer with Core Server installed and on the client computer.
If several Core Servers are used in your infrastructure, install the provider on all the servers of the infrastructure.
After the installation is complete, a system restart may be required. If the installation wizard prompts you to restart the system, confirm this action.
To remove or restore the product, open the Control panel menu and use the standard procedure for the supported operating systems.
Authentication example
When you first sign in to the system or to an application via Axidian Access authentication, select the sign-in method.
To do this, click Change the sign-in method in the Windows sign-in window (in the Authentication for Enterprise SSO window). Select the Smart card or USB key or Smart card or USB key + PIN sign-in method.
Connect the USB key or the smart card to the computer. If the Smart Card Provider + PIN sign-in method is used, enter the PIN code and click Sign in.
The authentication is performed once the card data has been processed. If the sign-in with the authenticator is successful, the Smart card or USB key (Smart card or USB key + PIN) sign-in method is saved as the preferred one and is offered to the user automatically at the next sign-in to the system or to an application.