Authentication...


Use this function to enable device authentication, create user accounts and passwords, and set password policies and authentication settings.

To turn on authentication

  1. Select the Authentication Enable check box to launch the Create Admin Info... group box and create the administrative account, which is required to turn on Authentication.  

    NOTE: The Create Admin Info...group box is displayed only if no administrative account is present on the device.  

Create Admin Info...

  1. Type the admin[strator] information in the Username, Password, and Verify Password text boxes, and click the OK button.  This reboots the device.  After the device initialization, you will be prompted for the Username and Password to connect to the device.

Authentication

  1. After the reboot, Toolbox displays an Authentication dialog box with a single tab: Current User.

  2. To change the current user's password, click on the Change Current Users Password button.

  3. Type the new password in the Password and Verify Password text boxes, and click the OK button.  

  4. The Authentication dialog box adds the following tabs: Current User, Users, Groups, Blocked IPs, and Authentication Options.

NOTE: The User, Groups and Blocked IPs tabs appear only if you are logged in with an account in the Administrators group.  Similarly, you must be logged into the device as the administrator or with an account in the Administrators group to perform any tasks on the User, Groups or Blocked IPs tabs.

User Tab


To change user password

  1. Click on the Change User Password button.
  2. In the Change User Password... dialog box, enter the new password in both the New Password and Verify New Password text box and click the OK button:

To create and delete users

  1. Click on the Create New User button.

  2. In the Create New User... dialog box, type the user information in the Username for new user, Password for new user and Verify Password text boxes:



  3. In the Groups To Join group box, click on a Group to assign the new user to it.  The user inherits the group's access level/rights.  Use CTRL+Click to assign the new user to multiple groups.

  4. Click the OK button when finished.

  5. To delete a user, click on the user name to highlight it and then click the Delete User button.  Click the Yes button to confirm the deletion:


To add users to a group or to remove users from a group

  1. Double click on the user name.  The User Information dialog box displays the user's group memberships:


     

  2. Click the Add User Name to Group(s) button (where User Name is the actual user name).  The Select Groups for User Name dialog box displays. Click on the appropriate group.   Use CTRL+Click to add the new user to multiple groups.  Click the OK button to return to the main Authentication dialog box:

  3. Click the appropriate group and then click the Remove User Name from Group button.  Click the OK button and then click the Yes button to confirm the user's removal from the group.  Click the OK button to return to the main Authentication dialog box.

To set a public key

  1. Click on the Set Public Key button:

    1. In the Set Public Key dialog box, click the Browse button:


    2. In the Open dialog box, navigate to and select the applicable Public Key file and click the Open button:


    3. In the Set Public Key dialog box, click the Send button:


      The public key text will populate the Public Key window.



      The Users table displays the Public Key that has been for the user.


    To block/unblock a user

  1. Select the applicable user and click on the Block/Unblock button:



  2. In the Block/Unblock dialog box, select the BLOCK user or UNBLOCK ALL users radio button, as applicable, and click the OK button:


Groups Tab

To create a group or delete a group

  1. Click on the Groups tab.

  2. To create a group, click on the Create Group button.  Type the group name in the Create Group on Device... dialog box's Group Name text box.  In the Group Access Level drop-down combo box, use the drop-down arrow to select the appropriate group access level for the new group.  Click the OK button. Click the OK button again in Done message box.

  3. To delete a group, select the group form Current Groups list box and click on the Delete Group button.  Click the OK button to confirm the deletion.

To display group information

  1. Click on the Groups tab.

  2. Double click on the appropriate group in the Current Groups list box to display Group information box for the selected group.

  3. If the group is empty, the Add User(s) To GROUP name and Add AD User(s) To GROUP name buttons are available (where GROUP name is the actual group's name).

  4. If the group has users, the Remove User From GROUP name button is available.

To add an Active Directory Group to a device

  1. Click on the Groups tab.

  2. Double click on the appropriate group in the Current Groups list box to display Group information box for the selected group:



  3. In the Active Directory Group Authentication... dialog box, enter the Active Directory server name in the Domain text filed , enter a valid user name and password in the corresponding Username and Password text fields and click the OK button:



    Note: Some control systems may require Active Directory Group Authentication--and other control systems may not.

  4. In the Add Active Directory Group to Device... dialog box, type the Active Directory Group in the Group Name text box:

    Notes:

    1. AD Group Name is case-sensitive for Linux/Androids.

    For example, “swdevtoolsadmins” will work on 3-series but needs to be “SWDevToolsAdmins” on 4-series.

    1. AD Group Name does not require the Domain for Linux/Androids.

    For example, “rnd.com\ SWDevToolsAdmins” on 3-series, just “SWDevToolsAdmins” on 4-series.

  5. Click on the Group Access Level drop-down, select the applicable access level and then click the OK button:



  6. In the Active Directory Group successfully added dialog box, click the OK button:






    The Active Directory Group is displayed in the Groups - Current Groups table; a Yes in the AD Group? column indicates that this group is an Active Directory Group.

  7. On the Groups Tab, double-click on ADMINISTRATORS (or other applicable Group):



  8. In the Group information for ADMINISTRATORS dialog box, click the Add AD User(s) to ADMINISTRATORS:



  9. In the Select AD User(s) for ADMINISTRATORS dialog enter the AD User in the form Domain\Username and click the OK button:

    Note:

    1. AD User must include “.com” in the Domain for Linux/Androids.

    For example, “rnd\john.smith” on 3-series must be “rnd.com\john.smith” on 4-series.

  10. In the AD Group Authentication... dialog box, add the applicable credentials to add the above AD User and click the OK button:



    Note: Some control systems may require Active Directory Group Authentication--and other control systems may not.

  11. In the User(s) added for ADMINISTRATORS! dialog box, click the OK button.


  12. On the Groups Tab, double-click on ADMINISTRATORS (or other applicable Group) to confirm display the added user:

Block IPs Tab

To block an IP Address or to remove a blocked IP Address

  1. To block an IP address, click the Add Address To Blocked List button.

  2. Enter the IP address in the Add Blocked IP Address dialog box's Specify an IP Address To text box.

  3.  Click the OK button on the Done message box to return to the Block IPs tab.

  4. To remove a blocked IP address, click on the IP address in the Blocked IP Addresses list box and then click on the Remove Address From Block button.

  5.  Click the OK button on the Done message box to return to the Block IPs tab.

To block an IP Address for a limited amount of time

  1. Un-check the No Limit check box.

  2. Enter the time in hours in the Time an IP Address remains on the blocked  drop-down combo box or use the drop-down arrows.

    Note:  A blocked IP address is indefinitely blocked unless a time limit is entered.

Authentication Options



To set authentication options

To set password policy

  1. Select the appropriate check boxes from the Authentication Options tab's Password Policy group box to require numeric, special or mixed case characters (mixed case characters = a mix of upper and lower case characters) in the password.

  2. To set a minimum password length, un-check the Use Default Length check box; type the minimum password length in the Set Minimum Password spin box or use the up-arrow or down-arrow.

  3. Click the Update Password Policy button, to set the specified password policy.

Note: These password policies are applied when new users and passwords are created; these policies are not retroactively applied to previously created passwords.

To configure miscellaneous authentication settings

  1. To set a password entry attempt limit, un-check the No Attempt Limit check box in the Miscellaneous Authentication Settings group box, type the allowable number of password entry attempts in the Set Maximum Password Entry combo box.

  2. To set an idle time that logs out the user due to inactivity, un-check the No Idle Limit check box; type the idle time in minutes in the Set Default User Idle combo box or use the up- or down-arrow.

  3. Click the Update Miscellaneous Authentication Settings button to apply the settings.