ACF2

 View Only
  • 1.  ACF2 Provides Enhanced PassTicket Support

    Broadcom Employee
    Posted Jan 30, 2023 09:38 AM
    Edited by Laura Fletcher Jan 31, 2023 09:34 AM

    The ACF2 team is pleased to announce the availability of enhanced PassTicket support. Enhanced PassTickets use a more secure algorithm and have additional features compared to legacy PassTickets.

    Enhanced PassTickets

    • Key must be stored encrypted in ICSF.
    • 256-2048 bit HMAC secret key.
    • PassTickets contain upper and lowercase A-Z, a-z, 0-9, - (dash), and _ (underscore) when PTTYPE is set to MIXED.
    • Time out is configurable (1-600 seconds).

    Legacy PassTickets

    • Can be masked or key stored encrypted in ICSF.
    • Secret 64-bit DES key.
    • PassTickets contain uppercase A-Z, 0-9.
    • Time out is 10 minutes.

    For more information, see PTKTDATA Profile Records.



    ------------------------------
    Laura Fletcher
    Staff Technical Writer
    Broadcom
    Illinois
    ------------------------------


  • 2.  RE: ACF2 Provides Enhanced PassTicket Support

    Posted Jan 31, 2023 02:03 AM
    Hi Laura

    the provided documentation Define PassTicket (AZFPTKT1) seems not be valid or at least confusing, this is the documentation how to configure IBM MFA with PassTicket.

    br Ewald