English
Published: 2016-07-08 13:58:05 CEST
Derivatives
IT information

IT – Genium INET – Nasdaq to introduce Two-Factor Authentication for CMS Web (44/16)

This IT-Notice contains a technical overview and implementation process of a Two Factor Authentication solution, 2FA, for CMS Web. This information is directed primarily to IT staff, secondarily to administrators of the CMS Web application as well as the end users.

Introduction

Today, customers can login to Nasdaq web applications by using a combination of various authentication methods. With increasing focus on cyber security and in order to streamline the login procedure, Nasdaq will implement a 2FA solution to improve member login security to all our web-based applications.

First Nasdaq application to adapt the 2FA is the CMS Web application for Genium INET. Other web-based platforms will follow hereafter.

The 2FA solution chosen is
provided by SafeNet and can be used on smartphones, tablets or computers. After the 2FA solution has been implemented, users will be authenticating using username, password and one-time passcodes generated using the SafeNet MobilePASS app.

Time line

The enrollment period of 2FA for CMS Web will open in the middle of September with an expected completion by the end of November 2016. When the enrollment period starts, users will be requested to enroll as part of the standard login procedure to CMS Web.

Users will have a maximum of three login attempts available using the old authentication method (username & password only) before the enrollment to 2FA is mandated.

Enrollment Prerequisites


All customers need to decide what device(s) should be used and prepare these for token installation. For easy and trouble-free usage we recommend the use of smartphones, but local software installations are also possible.

  • Smartphones/Tablets – Download the app SafeNet MobilePASS from your Apple App Store, Blackberry AppWorld or the Android Play Store 
  • Desktop computers – Download the applicable SafeNet MobilePASS for your OS from
    • Please note: The initial app installation requires local administrative privileges. However, after the installation has been completed, the usage of the app does not require administrative privileges
    • All interaction with the SafeNet MobilePASS takes place over HTTPS, port 443, the standard for secure browser traffic

SafeNet MobilePASS app can be installed already now but please note that the tokens will be issued as part of the enrollment process.

Enrollment of 2FA for CMS Web


The 2FA enrollment process for users of CMS Web will start in the middle of September.

Provided the preparatory steps described further down have been taken, the enrollment process will be fully self-service i.e. the end user can enroll without assistance of Nasdaq or an administrator.
 

The following preparatory steps are recommended before the enrollment period starts:

  1. Identify the CMS Web Administrator(s) within your company. Nasdaq can assist with this if needed
  2. Identify the CMS Web users within your company. Nasdaq can assist with this if needed
  3. Inform all CMS Web users of the upcoming change and the enrollment process
  4. CMS Web Administrator needs to ensure that all user accounts are individual. All potentially shared accounts need to be changed or removed. With the new 2FA Single Sign-On solution, the use of shared email address will be strongly discouraged.
    Please note: Only use e-mail addresses that are being owned by you as a member, do not use shared or generic email addresses such as username@gmail.com or user.name@hotmail.com
  5. Decide which device should be used for each CMS Web user

Contact Details For Assistance

If you have questions or concerns over the supported platforms for the SafeNet MobilePASS, please raise these as soon as possible to Technical Support: technicalsupport@nasdaq.com  +46 8 405 6750

For CMS user or password questions, please contact Member Services: ms.gi@nasdaq.com  +46 8 405 6660

More information will be communicated in August 2016, but if you want to know more about the 2FA project already now, you are welcome to reach out to technicalrelations@nasdaq.com

 

Best regards,

 

Technical Relations
technicalrelations@nasdaq.com


IT_Exchange_Notice_ 2FA for CMS Web.pdf