Managing SecurID tokens for users
To enable the ability to manage SecurID tokens for users via the Help Desk menu, you must turn on the Modules > Manage Tokens (PSP) > PSP ENABLED setting. Once enabled, Bravura Pass allows you to:
Enable or disable a token.
Request emergency access codes for a user.
Clear previously requested emergency access codes.
Set a new PIN.
Clear a PIN.
Resynchronize a token.
Enable (activate) a new token
To enable a new token:
Click the Manage tokens tab.
If the user has more than one token, select the token you want to manage.
Select the Enable token option.
Bravura Security Fabric confirms that the token is activated.
Disable a lost or stolen token
To disable a lost or stolen token:
Click the Manage tokens tab.
If the user has more than one token, select the token you want to manage.
Select the Disable token option.
Bravura Security Fabric confirms that the token is deactivated.
You can have Bravura Pass generate secure one-time passwords for a user.
To request one-time passwords:
Click the Manage tokens tab.
If the user has more than one token, select the token you want to manage.
In the Put token into Emergency Access Mode section:
Type the number of hours for which the codes will be valid in the Number of hours before Emergency Access Mode expires field.
Enable Use one-time passwords.
Type a value in the Number of passwords to generate field. Each code may only be used once.
Type the required length of the codes in the Length of passwords to be generated (4-8) field.
Select the appropriate checkboxes so that the password is a combination of Digits, Letters, and Punctuation marks.
Select the Put token into Emergency Access Mode option.
Bravura Security Fabric confirms entry into emergency access mode, displays the access codes, and provides details on how the access codes is to be used.
Communicate the emergency access code(s) to the user.
Each emergency access code can be used only once.
Create a fixed password for Emergency Access Mode
You can specify fixed password for users to use , or have a fixed password be randomly generated for Emergency Access Mode.
To create a fixed password:
Click the Manage tokens tab.
If the user has more than one token, select the token you want to manage.
In the Put token into Emergency Access Mode section:
Type the number of hours for which the code will be valid in the Number of hours before Emergency Access Mode expires field.
Enable Use a fixed password, and type the password in the adjacent text field.
This password must conform to the password rules set by the RSA Authentication Manager server.
Enter -1 in order to have a fixed password be randomly generated.
Select the Put token into Emergency Access Mode option.
Bravura Security Fabric confirms entry into emergency access mode, displays the access codes, and provides details on how the access codes is to be used.
Communicate the emergency access code to the user.
Clear Emergency Access Mode
To clear an emergency access mode for a user:
Click the Manage tokens tab.
If the user has more than one token, select the token you want to manage.
Select the Take token out of Emergency Access Mode option.
Set a new PIN
To set a new PIN for a user’s token:
Click the Manage tokens tab.
If the user has more than one token, select the token you want to manage.
In the Set token PIN section, type a new PIN that will satisfy the requirements of the Token Policy on the RSA Authentication Manager 7.1/8.2 server or leave the PIN field empty if you want Bravura Security Fabric to select a random PIN for you.
Select the Set token PIN option.
Communicate the PIN to the user.
Clear a PIN
To clear a PIN:
Click the Manage tokens tab.
If the user has more than one token, select the token you want to manage.
Select the Clear token PIN option.
Resynchronize a token with the RSA Authentication Manager
To resynchronize a token with the RSA Authentication Manager:
Click the Manage tokens tab.
If the user has more than one token, select the token you want to manage.
Ask the user for the token displayed on his SecurID card. Type the code in the Code displaying on token now field.
Select the Resynchronize token option.
Ask the user to give you the new token when it changes on the display of the card. Type the new code in the New code displaying on token field.
Select the Resynchronize token option.
The SecurID card is now synchronized with the RSA Authentication Manager 7.1/8.2 server.