ActivIdentity 4TRESS Soft Token Manager Licensing and Credentials Overview
The Soft Token License
What is a Soft Token license? A Soft Token license is the entitlement for a single user to use a single Soft Token of any type, (PC, Mobile, Web). A Soft Token license is reusable if a Soft Token is unassigned from a user, the associated license is freed up and can be used for a new assignment. This unassignment / new assignment may occur an infinite number of times. Soft Token licenses are delivered in batches contained within a file, e.g. 1000 soft token licenses may be delivered in a single file. The minimum batch size is 100 licenses, amounts beyond 100 can be arbitrary in number, e.g. 137 Soft Token license files do not contain any secret credential data, only information valuable to the Soft Token Manager server (i.e. number of licenses, validity period to import license file).
What is a Soft Token license? License files have a validity period (to import into Soft Token Manager) of 30 days if a customer requires an extension, put a footnote in the shipping instructions of the order. If a customer s license file expired before importing to Soft Token Manager, they may contact ActivIdentity Support to request a refreshed license file. License files are bound to a unique Site Key
What is a Soft Token license? This area displays information related to the License Inventory Inventory view in 4TRESS Soft Token Manager for AAA
What is a Soft Token license? About the Site Key A Site Key is bound to a Soft Token license file, at the time of installation of Soft Token Manager, a Site Key must be provided (or defined) Typically ActivIdentity will provide the Site Key with the delivery of the soft token license file. If the customer defines their own Site Key (usually for evaluation before a license purchase) they should follow a simple set of guidelines for generating a good Site Key (reference product documentation). Examples of a good Site Key: Company name (ACTIVIDENTITY) Company name plus organizational unit (ACTIVIDENTITY_FINANCE) Company name plus region (ACTIVIDENTITY_EMEA)
The Soft Token Credential
What is a Soft Token Credential? A Soft Token credential is a OATH credential unique to each Soft Token. Although licenses are reusable, a credential is never reused. Example, if a Soft Token is unassigned from a user the credential (token and auth server) is terminated permanently. If a Soft Token is reassigned to a user, a new credential is generated and used. The Soft Token Manager may be used to generate an infinite amount of credentials over a the lifetime of a Soft Token deployment. When a customer purchases Soft Token licenses, credential secrets are NOT delivered with the Soft Token license file.
What is a Soft Token Credential? Note: Licenses are reusable and credentials are not. So there can be a discrepancy between License and the Credential inventory number values. This area, Token displays information related to the Credential Inventory Inventory view: 4TRESS Soft Token Manager for AAA
ActivIdentity 4TRESS AS vs. ActivIdentity 4TRESS AAA There is a difference in how credentials are managed between ActivIdentity 4TRESS AS and ActivIdentity 4TRESS AAA. For ActivIdentity 4TRESS AS, the credentials are automatically generated by the system. No user intervention is required for importing credentials from the ActivIdentity 4TRESS Soft Token Manager to the ActivIdentity 4TRESS AS. For ActivIdentity 4TRESS AAA, the credentials are generated by a manually driven process from the ActivIdentity 4TRESS Soft Token Manager. The newly generated Soft Token Credentials must be imported into ActivIdentity 4TRESS AAA.
Example: Deployment with ActivIdentity 4TRESS AAA In ActivIdentity 4TRESS AAA, both license and credential inventory information is displayed to the Operator. In ActivIdentity 4TRESS AAA, a generate button exists to create new Soft Token credentials as needed.
Example: Deployment with ActivIdentity 4TRESS AS In ActivIdentity 4TRESS AS, only license inventory information is displayed to the Operator. Note: In an ActivIdentity 4TRESS AS deployment, the management of credentials is performed automatically.
Practical Examples Soft Token License and Credentials
Practical Example 1: PC Token User is assigned a PC Soft Token for his Desktop workstation A single soft token license is used. And a single soft token credential is used. User is assigned another PC Soft Token for his Laptop A single soft token license is used. And a single soft token credential is used. Total: 2 soft token licenses and 2 soft token credentials assigned to a single user on two separate PCs. Single User Desktop Workstation. 1 Token, 1 License, 1 Credential Laptop. 1 Token, 1 License, 1 Credential
Practical Example 2: Web Token User is assigned a single Web Soft Token with roaming capability A single soft token license is used. And a single soft token credential is used. User registers her web token on her desktop workstation at work User registers her web token on her laptop User registers her web token on her home desktop workstation Total: 1 soft token license, 1 soft token credential registered on 3 machines for 1 user. Desktop @ Work. Roaming Web Token. Single User. Laptop. Roaming Web Token. Desktop @ Home. Roaming Web Token.