9.19.3 Importing PSKC or CSV Files

You can import the PSKC or CSV files. These token files contain token information. To import these files, perform the following steps:

  1. Click the OATH Token tab.

  2. Click Add.

  3. Click Browse and select a PSKC or CSV file.

  4. Choose a File type. The options are:

    • OATH compliant PSKC: This file type must be compliant with OAuth. For example, HID OATH TOTP compliant tokens.

    • OATH csv: This file type must contain the format as described in CSV File Format To Import OATH Compliant Tokens. You cannot use the YubiKey CSV files.

    • Yubico csv: In this file type, you must use one of the supported Log configuration output (see YubiKey Personalization Tool > Settings tab > Logging Settings) formats with comma as a delimiter.

      • Traditional format: In this file type, OATH Token Identifier must be enabled.

      • Yubico format: This file type is supported only for HOTP Length set to 6 Digits and OATH Token Identifier set to All numeric.

      IMPORTANT:Moving Factor Seed must not exceed 100000.

  5. Add the encrypted PSKC files. For this, select Password or Pre-shared key in PSKC file encryption type and provide the information.You can select Not encrypted, if the PSKC file is not encrypted with either the password or key.

  6. Click Upload to import tokens from the file.

NOTE:Advanced Authentication receives an OTP format from the imported tokens file and stores the information in the enrolled authenticator. Therefore, you need not change the default value of OTP format on the Edit Method tab.

When the tokens are imported, you can see the list and you must assign the tokens to users. This can be done in the following two ways:

  • Click Edit next to the token and select Owner and click Save.

  • A user can self-enroll a token in the Self-Service portal. Administrator must let the user know an appropriate value from the Serial column for the self-enrollment.

NOTE:Tenancy settings are not supported for the OATH tokens. Therefore, the configurations in the OATH Tokens tab cannot be enforced on tenant administrators.