Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • the name of the user account,
  • the user's e-mail address.
    • Users can register just once for a given e-mail address and account.
    • Users can register with additional JOC Cockpit instances specifying the same account and e-mail address.
    • Users can add additional Security Key devices from their Profile once they are logged in.

Image Modified


If a JS7 - JOC Cockpit Cluster is operated then registration of Security Keys has to be performed for each JOC Cockpit instance individually.

...

  • For example, if Windows® Hello is enabled, optionally for Windows login, then users first might receive a popup window to login using the Windows Authenticator.

    Image Modified

  • Users can cancel the popup window if they want to register a Security Key that is not managed by Windows® Hello.

...

At this point in time users should have their Security Key readily available and connected. For example, if a USB stick is used then it should be connected to the computer that runs the browser with access to JOC Cockpit.

Image Modified


A follow-up popup window informs abut the fact that the brand and model of the Security Key will be displayed like this:

Image Modified


In the next step the user is asked to specify the PIN for access to the Security Key. If a PIN, biometric characteristics or other will be requested to access the Security Key depends on the nature of the Authenticator.

  • The PIN or other characteristics are configured once during initial operation of a Security Key. The same input is required when the Security Key is used later on.
  • If the Security Key is used for the first time then a dialog is added to specify and to confirm the PIN or other characteristics.

Image Modified


The next popup window asks the user for a gesture. This will happen

  • if the FIDO Identity Service is configured for preferred or required user verification,
  • if the user's Security Key is equipped for use of gestures such as touching a USB Stick.

Image Modified


With this step the registration request is completed.

...

The user is sent an e-mail from JOC Cockpit that includes a link to JOC Cockpit which is used to confirm the user's e-mail address like this:

Image Modified


Users should check if the indicated e-mail address corresponds to their address and if the URL offered to confirm their e-mail address starts from the same hostname as the JOC Cockpit URL used for registration. If in doubt users should not follow links in the confirmation mail but get in contact to their JS7 administrator.

...

With approval of a user's registration request the user is sent an e-mail from JOC Cockpit that notifies about successful completion of the registration request like this:

Image Modified

Users should check if the indicated e-mail address corresponds to their address and if the URL offered to navigate to JOC Cockpit starts from the same hostname as the JOC Cockpit URL used for registration. If in doubt users should not follow links in the confirmation mail but get in contact to their JS7 administrator.

...

  • If Windows® Hello is used as an Authenticator for FIDO Passkeys then this option can be used.
  • If a Security Key, for example a USB-Stick, is used then this option has to be selected.

Image Modified