• Votes

    5

    Option to hide QR Code in TOTP enrollment

    It would be a good feature if there is an option to disable the QR-Code or hide the QR Code, if TOTP method is enrolled. If a user re-open an enrolled T-OTP over the ...

  • Votes

    3

    NAAF Client 5.6 should get the language for a parameter that it can be ...

    NAAF Client 5.6 should get the language for a parameter that it can be changed by the end user. In our case the system locale can only be changed by the administrator and ...

  • Votes

    1

    On appliance install we ask for hostname (e.g server.domain.com). ...

    Have seen many installs on POCs where customer enters hostname and not the FQDN. Maybe change on install to: FQDN hostname (e.g server.domain.com)

  • Votes

    2

    When chains are created and user enrolls force that the chain must ...

    While on POC customer enrolled Bluetooth and Proxcard. They then logged out and only had LDAP Password. They were surprised and asked if when they are chained like this ...

  • Votes

    2

    Once a user has enrolled methods provide option to turn off LDAP ...

    On a customer POC and they have Bluetooth and PIN as well as Proxcard and PIN enrolled however they still see LDAP Password as a method when logging into Desktop. They ...

  • Votes

    3

    Set user attribute in repository after enrollment (LDAP hook)

    Often AAF is working in conjunction with Identity Management / Access Management systems. In these cases it is desirable to know when users have enrolled (one or more) ...

  • Votes

    12

    MFA Smartphone native NetIQ App avoid additonal info after QR code ...

    - Customer uses AAF Version: 5.6 and Access Manager 4.4. - Using the current version, an additonal info entry is offered after the scan of the QR code for an ...

  • Planned

    11

    authenticator sharing

    Allow a shared authenticator to be used regardless of whether or not the the account it is shared with has the same authenticator enrolled or not. For example, if a ...

  • Planned

    14

    Periodically export database backup to network location

    Right now you can manually export the database backup and then download it to your local machine. In the future, it is desirable that the database would automatically ...

  • Votes

    7

    Display serial number of enrolled HOTP authenticator

    It would be beneficial for a user to see the serial number of their currently enrolled HOTP authenticator in the authenticators management portal. A user may have one or ...

  • Votes

    8

    Customize RADIUS Reply-Messages per method in a chain

    Applications that correctly implement RADIUS will show the Reply-Message value sent from the AAF server when authenticating with a chain. Right now, the Reply-Message ...

  • Votes

    2

    5.6.5 config import to v6 destroys cluster

    after initial import of 5.6.5 config into v6, and then build the global cluster, doing the last import before go-live and migration to v6, all cluster information is ...

  • Votes

    5

    Allow IP address in multiple RADIUS events

    We are leveraging the NAS Identifier in that each of our RADIUS configurations have an Event for each chain. This enables us to provide our users a clever way to select ...

  • Planned

    4

    Configurable RADIUS auto-enrollment behavior

    Current status: When the RADIUS method is configured with a Radius client, a user is auto-enrolled in the RADIUS method no matter if they have an account in the ...

  • Planned

    4

    Logon Filter for "other" directories

    A potential customer is looking for the logon filter feature but for non-AD directories, in their case an Apple OpenDirectory (a fork of openLDAP). This could as well be ...

  • Votes

    4

    Search for tokens

    In an environment where there are a bunch of tokens, the pagination makes it tough to find a specific token. You need to search each page and you can easily need to ...

  • Votes

    4

    Configure appliance proxy settings through Configuration portal

    It would be convenient to be able to set the proxy settings in the Configuration portal of the appliance versus having to do it through yast.

  • Votes

    8

    Use SSL for AD repository DNS discovery

    When using DNS discovery for AD repositories, there should be an option to add them as SSL-enabled on port 636. Today when using DNS discovery for AD repositories, they ...

  • Votes

    2

    Ability to set a user specific fixed token

    With other Radius solutions (e.g. SMS Passcode) it is possible to set a fixed code in case the user forgot his smartphone.

  • Votes

    3

    Configure endpoint whitlist based on ad group

    We would like the ability to configure endpoints whitlist based on ad/eDirectory group, not by specifying the endpoints directly.