Hi,   I would like to log a request for enhancing the current way Riskminder handles the client request headers. As per current implementation of CA Risk Authentication server webservices, it sends [Server,Content-Type,Content-Length] in response header. I would like the server response to be enhanced so that it relays the request headers.   I…
Hi - CA Advanced Authentication currently lacks the capability of sending logs to a centralized syslog server. The administrator audit related events stay in the database backend and can be accessed manually through reports or by running queries against the database. This makes it difficult for us to integrate the solution with SIEM platforms and…
We are a UK bank currently using a combination of SiteMinder and Gemalto 2 factor card readers for customer auth/ SSO to our banking sites. We know of one other UK bank and 3 European banks using BOTH SiteMinder and Gemalto, so we believe this use case maybe something of interest to other CA banking customers! Please vote if you approve and or…
Download the Library DOwnload the attached library "secure-tomcat-datasourcefactory-0.2.jar". Generate Key and Encrypted PasswordGenerate a new random encryption key to a file e.g to create a new 128-bit AES key run the command: $ java -jar secure-tomcat-datasourcefactory-0.2.jar generateKey AES 128 ./testkeyfile   Generate the encrypted password…
Hi Team,   At present the failover capability is not present. we have to configure wioth VIP only. Due to this there can be possibilities in  increased response times. So, If we have the failover capability for ArcotSMBaseURL in SHIM Adapter, then it can lead to better performance.   Thanks!!
Hello Team, Currently we have two parameters configured in ARRFCONFIGURATION i.e USERLOCKEDTIMEDIFF and DEVICELOCKEDTIMEDIFF. Basically these two parameters will influence the risk engine to wait in case same user /device record is locked and contunue the txn. Currently it takes time only in sec, it should be made to mili sec.   Thanks M.G.HEGDE…
Hi,   Is it possible to enable LDAP login on an existing organisation on RiskAuthentication?     Regards; Neo
When a rule referencing a list is removed Risk Auth ruleset, the list is not removed. Even though the list is empty and not referenced by any rule, it is maintained in the ruleset and after a while it gets quite confusing when managing data in the list and the dropdown shows the unused lists. Deleting a rule should either prompt you for deleting…
Combine the CA MobileOTP and CA Mobile Authenticator (Push Notifications) applications into one app so that users can go to one app and be able to use the credential of their choice. This increases the usability and avoids the need to download and keep up with updates to multiple apps.
