Modify Legacy Token settings
Legacy tokens are older model tokens supported by Entrust Identity Enterprise (formerly Entrust IdentityGuard). IDaaS supports legacy tokens for the migration of Entrust Identity Enterprise users to the cloud.
Use this page only if your organization is migrating users who still use legacy hardware tokens. If you are deploying standard OATH hardware tokens, use Modify hardware token settings.
Before you update these values, confirm the expected authentication behavior in your current environment. Large changes to time or event windows can increase support requests if users' tokens are already close to policy limits.
Modify Legacy token settings
-
Click > Policies > Authenticators. The Authenticators page appears.
-
Select Legacy Token. The Legacy Token settings appear.
-
Set Max. Time Steps to define how long a token response remains valid during normal authentication.
This setting defines the number of time steps that are searched to find a matching user response during authentication. A value of
1equates to30seconds. The default value is10, or300seconds. -
Set Max Reset Clock Window to the number of minutes that IDaaS searches to find a matching user response during a token reset operation.
The value must be between
1and120(or two hours). The default value is10minutes. -
Set Max Event Window to the numbers of token responses that are searched to find a matching user response during authentication. The value entered must be less than the Max Reset Event Window.
The value must be between
10and200, in increments of10. The default value is100. -
Set Max Reset Event Window to the number of token responses that IDaaS searches during a token reset operation.
The value must be between
10and5000, in increments of10. The default value is100. -
Click Save.
Validate your changes
After you save, verify the following:
- A test user can complete normal token authentication within the configured Max. Time Steps and Max Event Window limits.
- Token reset succeeds within the configured Max Reset Clock Window and Max Reset Event Window values.
- Authentication failures do not increase unexpectedly after the policy update.