Installation guide
77 | Page Celestix HOTPin Appliance Installation Guide
Key Configuration Formats
The token key configuration comes in three formats, a file, QR code, or data
string. The file option can be used with any device that has the ability to import a
DAT file. The QR code requires that the device be present and have a camera
through which it can scan the code. The string option is intended to be used
with devices that have cut and paste functionality, but the string can also be
entered manually. The following sections provide instructions for each of the
format options.
Please Note: Depending on device capabilities and the client software version,
some import formats may not be supported. Check the client
software instructions for the version you are using for import
functionality.
File
Download property configuration options include:
Passphrase – protect the key configuration with optional encryption.
The file passphrase feature provides security while the key configuration
is in transit. The passphrase is case sensitive, should be between 6-16
characters, and cannot contain spaces. If entered here, it must also be
provided to the user.
Require key passphrase – select to require users to create a
passphrase in client software during token key import. Users will then
be prompted for the passphrase each time they open HOTPin or when
they load the encrypted key. The key passphrase is different from the
file passphrase described in the Passphrase item above; it can protect
the key from being accessed by anyone other than the user who
imported it.
Clear key file after import – if possible, force the client software token
application to overwrite and/or delete the key configuration file after the
key has been imported to the client. This helps to prevent both later
reimporting the key (when it would be out of sync with the server
application) and access by a malicious program.
Note: Some devices do not support file overwrite functionality by
the client application.
Download File – click to save the configuration file locally.
Next, the file will need to be imported to the client software.
See the following Key Configuration Transfer topic for information about
providing the file to end users.
Please Note: The default settings for the Require key passphrase and Clear
key file after import properties are assigned on the HOTPin