← Back to plugin index

Vasco Cronto Handler

Description
Handles Cronto functionality for Vasco Cronto (using the Vacman Controller).
Type name
VascoCrontoHandler
Class
com.airlock.iam.core.misc.impl.cronto.vascocronto.VascoCrontoHandler
May be used by
License-Tags
Cronto
Properties
Vasco Handler (vascoHandler)
Description
Handles calls to the native Vacman Controller.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Enable Online Validation (enableOnlineValidation)
Description
If this option is selected, online validation (Scan and Login) is enabled for users with a device that supports online validation.
Attributes
Boolean
Optional
Default value
false
Enable Online Activation (enableOnlineActivation)
Description
If this option is selected, online activation is enabled for users with a device that supports this feature. During online activation the user can activate a device by scanning the Cryptogram from a letter and the device activates itself without further interaction. If this feature is enabled, anyone with a valid letter can activate a cronto device without further authentication.
Attributes
Boolean
Optional
Default value
false
Enable Push Notifications (enablePushNotifications)
Description
If this option is selected, push notifications are enabled for users with a device that supports this feature.
Attributes
Boolean
Optional
Default value
false
Push App Handler (pushAppHandler)
Description
Defines which app is used for push workflows.
Attributes
Plugin-Link
Optional
Assignable plugins
Fallback To Offline Validation (fallbackToOfflineValidation)
Description
The fallback method from Cronto Push defines which Cronto method is chosen and initiated by IAM if push notifications are enabled and a user has no push-enabled device, but has a device that supports online validation (i.e., smartphone app with push disabled). If this property is enabled, the fallback method from push is offline validation (Scan and TAN). Otherwise, the fallback method is online validation (Scan and Login). Note that the user can in the latter case still choose to be authenticated by offline validation. Furthermore, Scan and TAN will be chosen independently of the value of this property for users that only have hardware devices.
Attributes
Boolean
Optional
Default value
false
Maximum Number Of Activated Devices (maximumNumberOfActivatedDevices)
Description
The maximum number of devices that a user can have activated simultaneously.
Attributes
Integer
Optional
Default value
99
Account Token Usages Threshold (accountTokenUsagesThreshold)
Description

Only Vasco Account Tokens, which have been used for at most n device activations, will be assigned to new users (n = this setting).

This threshold only applies when assigning an account token to a new user. Once a token is assigned to a user, this threshold does not limit the number of device activations the account token can be used for.

If e.g., the threshold is 90 and the license allows 99 device activations per account token, every user is guaranteed to be able to activate nine devices.

If a 'Cronto Activation Step' is aborted after the initial Cronto image has been scanned, this also counts as device activation, even though the device is not successfully registered with Airlock IAM.

Attributes
Integer
Optional
Default value
90
Default Allowed Platforms (defaultAllowedPlatforms)
Description

Defines the platforms that may be activated per default. This can be overridden by an administrator for each individual letter.

Currently, the following platform codes are supported:

  • 0: DIGIPASS 760
  • 3: iOS
  • 7: Android
  • 11: Windows phone
  • 13: Blackberry
  • 5: jailbroken iOS
  • 9: rooted Android
Enter the numbers for all allowed platforms as a comma-separated list (without spaces), e.g. "0,3,7" to allow stand-alone, iOS and Android devices.

Attributes
String
Optional
Default value
0,3,7,11,13
Platform Blacklist (platformBlacklist)
Description

Blacklist of blocked platform types. If a type is on this list, it can not be used for login or transaction signing and new devices of this type cannot be activated, independent of the allowed platforms in the activation letter.

Currently, the following platform codes are supported:

  • 0: DIGIPASS 760
  • 3: iOS
  • 7: Android
  • 11: Windows phone
  • 13: Blackberry
  • 5: jailbroken iOS
  • 9: rooted Android
Enter the numbers for all allowed platforms as a comma-separated list (without spaces), e.g. "5,9" to block jailbroken iOS and rooted Android devices.

Attributes
String
Optional
Show MAC (showMac)
Description
If enabled, the device or app must present the calculated MAC to the user.
Attributes
Boolean
Optional
Default value
true
Show Warning (showWarning)
Description
If enabled, a flag is set in the challenge (cryptogram) that prompts the app/device to display a warning to the user.
Attributes
Boolean
Optional
Default value
false
Ask Approval (online) (askApproval)
Description
If this option is enabled, the user is asked to confirm the signature request during online validation (i.e. Scan&Login and push modes). Disabling this feature can increase usability during the login process but it should always be enabled for transaction approval. With Digipass for Mobile, this option is only effective if used together with the "Show Data" setting.
Attributes
Boolean
Optional
Default value
true
Ask Approval (offline) (askApprovalOffline)
Description
If this option is enabled, the user is asked to confirm the signature request during offline validation. This is normally not needed because the user actively approves the transaction/login by manually entering the TAN. Depending on the app implementations, it might be needed for app-to-app setups.
Attributes
Boolean
Optional
Default value
false
Ask for PIN (askForPin)
Description
If this option is set, a PIN will be asked by the DigiPass 780 device each time a transaction is to be signed. Note that this feature is only supported by the DigiPass 780 device.
Attributes
Boolean
Optional
Default value
false
Show Data (showData)
Description
If this option is enabled, the transaction data is displayed on the app before online validation. Note that with Digipass for Mobile, this option is only effective if used together with the "Ask Approval" setting. For offline validation (entering TAN manually), the data is always displayed.
Attributes
Boolean
Optional
Default value
true
Template Number (templateNumber)
Description

Index (encoded in the challenge cryptogram) that selects the template to be used by the Cronto app to display the challenge data.

Note that this option is currently not supported by DIGIPASS for Mobile and will be ignored by the application.

Attributes
Integer
Optional
Default value
0
Character Encoding Index (characterEncodingIndex)
Description

Index (encoded in the challenge cryptogram) that selects the character encoding (font table index) to be used by the Cronto app to display the challenge data.

Currently, the following languages are supported:

  • 0: for encoding messages in ISO-8859-15
  • 1: for encoding messages with Katakana support
  • 2: for encoding messages with Central- and East-European languages support
  • 3: for encoding messages with Greek language support

Attributes
Integer
Optional
Default value
0
App Security Version (appSecurityVersion)
Description
Minimum application version required to parse the transaction message.
Attributes
Integer
Optional
Default value
0
Challenge Token Lifetime (challengeTokenLifetime)
Description
The lifetime in seconds of a challenge token. After the lifetime of a challenge token has expired, no successful validation with this token is possible anymore and the token is deleted upon the next verification request.
Attributes
Integer
Optional
Default value
300
Show Newest Open Transaction Only (showNewestOpenTransactionOnly)
Description
If enabled, only the latest open transaction should be be offered to be signed if push is activated.
Attributes
Boolean
Optional
Default value
true
Store OTP Application for new Devices (storeOtpApplicationForNewDevices)
Description
Enable to always store the OTP crypto application upon activation of new devices. Should be enabled if push notifications are planned in the future but are not enabled yet.
Attributes
Boolean
Optional
Default value
true
Future Application Indices (futureApplicationIndices)
Description

Comma-separated list of indices of crypto applications that should be saved upon device activation for currently not implemented use-cases.

To allow future authentication with push, it is sufficient to enable the "Store OTP Application for new Devices" property.

Attributes
String
Optional
Log Response Codes (logResponseCodes)
Description
If enabled, response codes of Cronto challenge verifications are logged to INFO level.
Attributes
Boolean
Optional
Default value
false
Token Data Provider (tokenDataProvider)
Description
Plugin to load tokens from persistence.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Default Number of Letter Usages (defaultNumberOfActivations)
Description

Defines how many times an activation letter can be used per default to activate devices or apps. This can always be changed by an administrator for an individual letter.

Attributes
Integer
Optional
Default value
8
Default Letter Validity Time (defaultLetterValidityTime)
Description
Defines how long (how many days) an activation letter can be used per default to activate devices or apps. This can always be changed by an administrator for an individual letter. If no value is set, the validity is not limited.
Attributes
Integer
Optional
Selectable As Auth Method (selectableAsAuthMethod)
Description
Disable to prevent CrontoSign from being selected as active authentication method.
Attributes
Boolean
Optional
Default value
true
Selectable As Next Auth Method (selectableAsNextAuthMethod)
Description
Disable to prevent CrontoSign from being selected as the next authentication method (migration).
Attributes
Boolean
Optional
Default value
true
Enable On-Screen Activation (enableOnScreenActivation)
Description
If enabled, allows users to register Cronto devices with an on-screen activation cryptogram. This is typically the case when users do not have activation letters. If on-screen activation with a letter must be possible, enable "Enable On-Screen Activation With Letter".

On-screen activation is only possible in two situations: (1) during credential migration and (2) when activating an additional device.

Attention: make sure that such an activation can only be accessed by strongly authenticated users. For this, the "Strong Authentication Tag" must be configured on the following plugins (if used):
  • Cronto Activation Step
  • Cronto Activation Possible
  • Cronto Activation Required
Attributes
Boolean
Optional
Default value
false
Enable On-Screen Activation With Letter (enableOnScreenActivationWithLetter)
Description
If enabled, allows users who have a Cronto activation letter to register Cronto devices with the activation cryptogram from the letter being displayed in the browser.

Attention: make sure that such an activation can only be accessed by strongly authenticated users (refer to the documentation of "Enable On-Screen Activation")

Attributes
Boolean
Optional
Default value
false
Available Printing Options (availableOrderOptions)
Description
If several different ways of printing the letter are needed (for example to print locally or via the central printer, or to also order a device), then these printing options can be defined. The printing options allow to define separate printing task for different printing options.
Attributes
String-List
Optional
Default value
[default]
Options Resource Key Prefix (optionsResourceKeyPrefix)
Description
If this property is defined, the order options are assumed to be resource key and are used together with the prefix defined here to display a translated version of the options. If left empty, the options are displayed as defined above.
Attributes
String
Optional
Default value
cronto-order-option.
Default Printing Options (defaultOrderOptions)
Description
Defines the default order options for a new letter (what will be set for a new letter).
Attributes
String-List
Optional
Default value
[default]
YAML Template (with default values)

type: VascoCrontoHandler
id: VascoCrontoHandler-xxxxxx
displayName: 
comment: 
properties:
  accountTokenUsagesThreshold: 90
  appSecurityVersion: 0
  askApproval: true
  askApprovalOffline: false
  askForPin: false
  availableOrderOptions: [default]
  challengeTokenLifetime: 300
  characterEncodingIndex: 0
  defaultAllowedPlatforms: 0,3,7,11,13
  defaultLetterValidityTime:
  defaultNumberOfActivations: 8
  defaultOrderOptions: [default]
  enableOnScreenActivation: false
  enableOnScreenActivationWithLetter: false
  enableOnlineActivation: false
  enableOnlineValidation: false
  enablePushNotifications: false
  fallbackToOfflineValidation: false
  futureApplicationIndices:
  logResponseCodes: false
  maximumNumberOfActivatedDevices: 99
  optionsResourceKeyPrefix: cronto-order-option.
  platformBlacklist:
  pushAppHandler:
  selectableAsAuthMethod: true
  selectableAsNextAuthMethod: true
  showData: true
  showMac: true
  showNewestOpenTransactionOnly: true
  showWarning: false
  storeOtpApplicationForNewDevices: true
  templateNumber: 0
  tokenDataProvider:
  vascoHandler: