P-Synch is a commercial product from M-TECH Mercury Information Technologies Inc. that provides password management and SecurID management via a self-service web interface. The product is in use at Princeton University as well as at PPPL.

P-Synch allows users to define one password for multiple systems and to change or reset that password. Additionally, if a user has a SecureID badge for remote access to PPPL, P-Synch provides the user with mechanisms to manage the token and to troubleshoot and correct access problems. Service is provided 24/7.

Systems currently under P-Synch password management are UNIX Cluster/E-mail, PPPL Windows 2000 Domain, and SecureID badges. Future addition of other systems such as the Timesheets and Business Systems is anticipated.

Note that passwords expire annually. When your password(s) next expires, you will be required to change it using this utility. 

From inside the lab, you must have either a known UNIX password or a working SecureID badge to access P-Synch. If you have a working SecureID badge but have forgotten your password, you can reset your password. However, if you have forgotten your password and do not have a working SecureID badge, you must call the Help Desk (x2275) for assistance.

From outside the lab, if your SecurID badge is not working, follow this procedure:

  1. Log in at the firewall, entering username pppl and password pppl. This will get you through the firewall  to P-Synch.
  2. Open your browser and connect to P-Synch (http://password.pppl.gov/)
  3. Enter your UNIX / e-mail username and password (described further below) to authenticate to P-Synch
  4. Resync your token, change pin, or get emergency codes as described later in this document.

Once again, if you have forgotten your password and do not have a working SecureID badge, you must call the Help Desk (x2275) for assistance.

P-Synch expects your PPPL UNIX Cluster/ Mail account name as the P-synch Login ID. This account name is usually composed of the first letter of your first name followed by up to 7 characters of your last name. For example, the P-Synch account name for Steve Davis is 'sdavis'. Since account names are truncated at eight characters, Lew Randerson's account name is 'lranders'.

When you first access P-Synch and display the top level page, you will be asked to log in using this account name in order to get started. To access P-Synch, open your browser and enter the following url in the address window:

http://password.pppl.gov/


The P-Synch top level page includes the dialog shown below. Note that you cannot use your browser's BACK or FORWARD functions to navigate through P-Synch web pages. You must use the round blue navigation buttons provided on the P-Synch pages themselves. (Clicking on your browser's navigation buttons will produce "page expired" errors.)



Princeton Plasma Physics Laboratory

   

Self-service login

Please enter your network login ID:

My login ID on Unix Cluster/Mail Accounts

Press to continue:

 
 

Administrator login




The authentication page displays next. This page gives you the option of entering your Unix Cluster/Mail account password or your SecurID pin+tokencode to identify yourself.. The preferred method of authentication is via the SecurID token. You should use your Unix Cluster/Mail account password only when your token is not working - that is, when it is necessary to gain access in order to manage your SecurID and resync the token to the SecurID server, or to reset your pin if you have forgotten it, or to get a set of emergency numbers to use.

For our example, let's authenticate with a SecurID pin+token:


 

Princeton Plasma Physics Laboratory

Steve Davis (SDAVIS)

 

Select an authentication method

Please select an action:

Use password verification on selected target systems.

Use SecurID token passcodes.

 
 

Selecting Use SecurID token brings up this page:


Princeton Plasma Physics Laboratory

Steve Davis (SDAVIS)

 

Challenge-response

You must answer all of the following questions correctly before proceeding.

Question

Answer

What's your PASSCODE (PIN + tokencode displayed on SecurID card)?


 
 

Back to top


After entering your 4-digit pin plus your token code, click Continue. If you are successful, you can now use P-synch to manage passwords or tokens. The page displays the options shown below:


Princeton Plasma Physics Laboratory

Steve Davis (SDAVIS)

 

What would you like to do?

Your last successful login was at 6/18/2003 10:59 AM.
You've had 0 failed attempts since your last successful login.

Passwords
 

Pick a new password  

You last changed your passwords using P-Synch on 5/18/2003 6:41 PM, via the self-service reset module.
 


Accounts  

Add my login accounts  

You have registered 4 account(s) on 3 out of 3 target(s).
 


SecurID tokens  

Manage my token(s)  

 

Logout


Passwords

Select Pick a new password for our example:


Princeton Plasma Physics Laboratory

Steve Davis (SDAVIS)

 

Select a new password for Steve Davis [SDAVIS]

Select a new password for CARROLL:

New password:

Confirm:



Can't think of a password?

Try one of these:

Your password must:

  • have at least 8 characters!
  • have upper and lower case characters!
  • have at least 1 punctuation characters not at the beginning and end!
  • have at least 3 letter(s)!
  • have at least 1 digit(s)!
  • not be constructed from a dictionary word!
  • not be an exact dictionary word match!
  • not contain a dictionary word!
  • not be your username with the letters rearranged!
  • have no more than 2 pair(s) of repeating characters!

Select one of the passwords from the pull down list or pick a password that follows the password policy rules. Enter the same password again to confirm the change and then hit the change your password button. If the password you select does not conform to the password policy rules, the page will display which specific rule was not met and you may enter another revised password.

If successful a new page is displayed that confirms the change in green at the top of the page and what accounts were changed. If the password update failed on one or more systems it reports the failure message in red at the top of the page and displays what accounts failed. You may exit or return to the P-Synch main page from this page.


Accounts

The Accounts option is used to view the accounts you have in P-Synch but a users ability to add an account has been disabled. It can be done by helpdesk personnel.

If you had selected Manage my token(s) the page display looks like:


 

Princeton Plasma Physics Laboratory

Steve Davis (SDAVIS)

 

SecurID profile management

-- Key fob Serial Number 95932412 --

Disable my Key fob

Put my Key fob into Emergency Access Mode

Enter the number of codes to generate:

Enter the number of hours before Emergency Access Mode expires:

Enter the number of digits in token code to be generated (4-8):

Clear my Key fob PIN

Set my Key fob PIN

Enter the 4-8 character PIN to be used (-1 for randomly generated PIN):

Resynchronize my Key fob

Enter the code displaying on Key fob now:

   
 

Managing SecurID Tokens

P-Synch allows users who have SecurID tokens to manage their tokens. Specifically, P-Synch is configured to allow users to do any of the following:

Enabling (activating) a new token

To enable a new token:

  1. Log in and navigate to the SecurID profile management page.
  2. If you have more than one token, click Select token on the row for the token you want to enable. P-Synch displays the management page for the token you selected.
  3. Click Enable. P-Synch confirms that the token is activated.

Disabling a lost or stolen token

To disable a lost or stolen token:

  1. Log in and navigate to the SecurID profile management page.
  2. If you have more than one token, click Select token on the row for the token you want to enable. P-Synch displays the management page for the token you selected.
  3. Click Disable. P-Synch confirms that the token is deactivated.

Getting emergency access codes for temporary use

To get emergency access codes for temporary use, if you need access to a system protected by SecurID but don’t have your token with you:

  1. Log in and navigate to the SecurID profile management page.
  2. If you have more than one token, click Select token on the row for the token you want to generate emergency access codes for. P-Synch displays the management page for the token you selected.
  3. In the Put my SecurID card into Emergency Access Mode section, type a value in the Enter the number of codes to generate field. Each code may only be used once.
  4. Type the number of hours the codes will be valid in the Enter the number of hours before Emergency Access Mode expires field.
  5. Type the required length of the codes in the Enter the number of digits in token code to be generated (4-8) field. Always enter 6 -- the same number of digits your token would generate -- for the length of the code.
  6. Press the Emergency on button. P-Synch confirms entry into emergency access mode.
  7. Make note of the emergency access codes you were given.

Clearing emergency access mode

To clear emergency access mode, if you found your token:

  1. Log in and navigate to the SecurID profile management page.
  2. If you have more than one token, click Select token on the row for the token you want to enable. P-Synch displays the management page for the token you selected.
  3. Click Emergency off.

Setting a new PIN

To set a new PIN for your token, especially if you have forgotten your current PIN:

  1. Log in and navigate to the SecurID profile management page.
  2. If you have more than one token, click Select token on the row for the token you want to enable. P-Synch displays the management page for the token you selected.
  3. In the Set my SecurID card PIN section, type a new PIN, from 4 to 8 digits long, or type -1 to have P-Synch to select a random PIN for you.
  4. Click Set Pin.
  5. Take note of the new PIN displayed on the screen.

Resynchronizing a token with the ACE/SECURID server

To resynchronize your token because you have had more than 3 consecutive log fails (which locks out your token with the ACE/SECURID server) or because the internal timer on the token is out of sync with the server.

  1. Log in and navigate to the SecurID profile management page.
  2. If you have more than one token, click Select token on the row for the token you want to resynchronize. P-Synch displays the management page for the token you selected.
  3. Type the code displayed on your token in the Enter the code displaying on SecurID card now field, and click Resynchronize.
  4. Wait for the display on your token to change.
  5. Type the code displayed on your token in the Enter the code displaying on SecurID token, and click Resynchronize.

Special Note:

If you resync your tokencode, enter only the token code displayed on the token. The PIN is not needed here --- only the token code. Enter a second token code to finish the resync. If the resync was successful, it will display in green at the top of the page.