Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

To add an Identity Service use the button Add Identity Service from the above list of Identity Services:


Image Added


Explanation:

  • The Identity Service Name can be freely chosen.
  • The Identity Service Type can be selected as available from the above matrix.
  • The Ordering specifies the sequence in which a login is performed with available Identity Services.
  • The Required the attribute specifies if login with the respective Identity Service is required to be successful, for example if a number of Identity Services are triggered on login of a user account.
  • The Identity Service Authentication Scheme allows to select
    • single-factor authentication: user account and password are specified for login with the Identity Service.
    • two-factor authentication: in addition or as an alternative to user account and password a Client Authentication Certificate is required, see JS7 - Certificate based Authentication

...

Global settings are applied for all Identity Services.

...

.

...


...


Explanation:

  • Session Idle Timeout
    • Should the lifetime of a token provided by an external Identity Service be different from the max. idle-timeout then JOC Cockpit will try to renew the token with the Identity Service. Renewal of a token does not require the user to repeatedly specify credentials for login.
    • Identity Services can restrict the lifetime of tokens and they can deny renewal of tokens. If a token cannot be renewed then the user session is terminated and the user is required to perform a login.
  • Initial Password
    • If an administrator adds user accounts with JOC Cockpit and does not specify a password then the Initial Password will be used. As a general rule JOC Cockpit does not allow to use empty passwords but populates them from the Initial Password if no password is specified by the user that adds or modifies an account.
    • In addition, the operation to reset a user account's password is available that will replace an existing password with the Initial Password.
  • Minimum Password Length
    • For any passwords specified - including the Initial Password - a minimum length is specified.
    • Consider that the number and arbitrariness of characters are key factors for secure passwords. Password complexity requiring e.g. digits and special characters to be used do not add to password security except in case of short passwords.

...

Settings specific for Identity Services

Such settings are explained with the individual Identity Service:

...