Maximum Number Of Activated Devices (maximumNumberOfActivatedDevices)
Description
The maximum number of devices that a user can have activated simultaneously.
Attributes
Default value
8
Default Allowed Platforms (defaultAllowedPlatforms)
Description
Defines the platforms for which an activation letter can be used per default. This can always be changed by an administrator for an individual letter.
Currently, the following platform codes are supported:
- 0: stand-alone Cronto device
- 1: iOS
- 2: Android
- 3: Windows phone
- 4: Blackberry
- 5: rooted iOS
- 6: rooted Android
Enter the numbers for all allowed platforms as one sequence, without spaces or commas, e.g. "012" to allow stand-alone, iOS and Android devices.
Attributes
Default value
01234
Platform Blacklist (platformBlacklist)
Description
Blacklist of blocked platform types. If a type is on this list, it can not be used for login or transaction signing and new devices of this type cannot be activated, independent of the allowed platforms in the activation letter.
Currently, the following platform codes are supported:
- 0: stand-alone Cronto device
- 1: iOS
- 2: Android
- 3: Windows phone
- 4: Blackberry
- 5: rooted iOS
- 6: rooted Android
Enter the numbers for all allowed platforms as one sequence, without spaces or commas, e.g. "56" to block rooted iOS and Android devices.
Attributes
Challenge Token Lifetime [s] (challengeTokenLifetime)
Description
The lifetime in seconds of a challenge token. After the lifetime of a challenge token has expired, no successful validation with this token is possible anymore and the token is deleted upon the next verification request.
Attributes
Default value
300
Enable Push Notifications (enablePushNotifications)
Description
If this option is selected, push notifications are enabled for users with a device that supports this feature.
Attributes
Default value
false
Bank URL Index (bankUrlIndex)
Description
Index of the bank URL hard-coded in the CrontoSign application.
Attributes
Push Notifications Reminder Period (pushNotificationsReminderPeriod)
Description
Number of Cronto device usages required before a user is asked again whether push notifications should be activated for this device. A value of "1" means that the user is asked upon every login.
Attributes
Default value
3
Service Code (serviceCode)
Description
The Cronto Service Code used to generate the Cronto challenges. If the value is empty the Service Code of IAM will be used. Normally there is no need to overwrite this property.
Attributes
String
Optional
Sensitive
Push Notification Sender (pushNotificationSender)
Description
Plugin responsible for sending Cronto push notifications.
Attributes
Assignable plugins
Token Data Provider (tokenDataProvider)
Description
Plugin to load tokens from persistence.
Attributes
Assignable plugins
Default Number of Letter Usages (defaultNumberOfActivations)
Description
Defines how many times an activation letter can be used per default to activate devices or apps. This can always be changed by an administrator for an individual letter.
Attributes
Default value
8
Default Letter Validity Time (defaultLetterValidityTime)
Description
Defines how long (how many days) an activation letter can be used per default to activate devices or apps. This can always be changed by an administrator for an individual letter. If no value is set, the validity is not limited.
Attributes
Selectable As Auth Method (selectableAsAuthMethod)
Description
Disable to prevent CrontoSign from being selected as active authentication method.
Attributes
Default value
true
Selectable As Next Auth Method (selectableAsNextAuthMethod)
Description
Disable to prevent CrontoSign from being selected as the next authentication method (migration).
Attributes
Default value
true
Enable On-Screen Activation (enableOnScreenActivation)
Description
If enabled, allows users to register Cronto devices with an on-screen activation cryptogram. This is typically the case when users do not have activation letters. If on-screen activation with a letter must be possible, enable "Enable On-Screen Activation With Letter".
On-screen activation is only possible in two situations: (1) during credential migration and (2) when activating an additional device.
Attention: make sure that such an activation can only be accessed by strongly authenticated users. For this, the "Strong Authentication Tag" must be configured on the following plugins (if used):
- Cronto Activation Step
- Cronto Activation Possible
- Cronto Activation Required
Attributes
Default value
false
Enable On-Screen Activation With Letter (enableOnScreenActivationWithLetter)
Description
If enabled, allows users who have a Cronto activation letter to register Cronto devices with the activation cryptogram from the letter being displayed in the browser.
Attention: make sure that such an activation can only be accessed by strongly authenticated users (refer to the documentation of "Enable On-Screen Activation")
Attributes
Default value
false
Available Printing Options (availableOrderOptions)
Description
If several different ways of printing the letter are needed (for example to print locally or via the central printer, or to also order a device), then these printing options can be defined. The printing options allow to define separate printing task for different printing options.
Attributes
Default value
[default]
Options Resource Key Prefix (optionsResourceKeyPrefix)
Description
If this property is defined, the order options are assumed to be resource key and are used together with the prefix defined here to display a translated version of the options. If left empty, the options are displayed as defined above.
Attributes
Default value
cronto-order-option.
Default Printing Options (defaultOrderOptions)
Description
Defines the default order options for a new letter (what will be set for a new letter).
Attributes
Default value
[default]