This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Electronic signature transition with PIN instead password (secure!)

One of our customer will type in a PIN from Windows authenticator rather than the password of the M-Files user a second time as 2-factor-authentication while confirming an electronic signature workflow transition. - Does anyone knows a solution for this requirement? Then I don't need to invent everything new.

It's a highly security relevant feature because this transition should authenticate an QUALIFIED electronic signature of the CEO (D-Trust card from German Bundesdruckerei installed on a Secrypt signing server).

  • Hi - I have moved this to the General forum as I think it's more to do with the product configuration than APIs.

  • Hi ,

    I know that M-Files has Smart Card signatures that work with smart cards and PINs. It is a 2-factor-authentication with smart cards. I have never used it though. It can be used with workflow approvals.

    You can read here

    I wonder if it would work with PKI tokens such as RSA Secure ID. If yes that would be really a good one.

  • Hi dejan,

    the customer has bought a signature server where the signature cards are located in that you don't have to travel around with it. The PIN entry of smart cards has been done by the input device where you put your smart card into - and should be typed in directly on the hardware device as recommendation of the hardware vendors like reinersct.com which is the preferred vendor of the official Bundesdruckerei / D-TRUST in Germany.

    But I need a solution for only typing in an authenticator's PIN as second factor beside logging in into M-Files via Windows password - instead of typing in Windows password again.

    This was a requirement of their IT security manager.