Updated on 2026-07-30 GMT+08:00

Configuring an OTP Token Vendor

Scenarios

An OTP token is a security hardware device that generates one-time passwords. You can use event-based OTP tokens. In OTP token authentication, a static login password and a 6-digit one-time password are required for login.

In an instance, only OTP tokens from one vendor can be used. Before issuing an OTP token, configure the OTP token vendor that can be used in the system. Currently, the following OTP token vendors are supported: Feitian and Jansh.

Precautions

If you change an OTP token vendor for your system, the originally issued OTP token device will become invalid.

Prerequisites

The role you belong to has the management permission for the System module. For details about how to check the permissions of each role, see Role.

Configuring an OTP Token Vendor

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose System > System Config > Security.
  3. In the OTP Token Config area, click Edit. The configuration window is displayed.
  4. Configure the OTP token vendor for the system.

    Table 1 OTP token configuration parameters

    Parameter

    Description

    Token type

    Select an OTP token vendor. The options are FTCX and JSCX.

    Authentication Time Range

    Set the authentication time difference to calibrate the time difference between the server and the OTP token device. This parameter is available only when Token type is set to FTCX.

    • Value range: 1 to 60, in minutes. Default value: 2.
    • If the time difference exceeds 5 minutes, the same OTP token may be considered valid for a longer period of time. If the token is intercepted or leaked, attackers will have a longer time window, and the risk of account spoofing rises accordingly. Make sure you set a reasonable value to this parameter.

  1. Click OK. You can then check the OTP token vendor configured for the system on the Security tab.

Follow-up Operations

After configuring an OTP token vendor, issue OTP tokens and enable OTP token authentication for login. For details, see Configuring OTP Token Login Verification.