Skip to main content

Define out of band token lifespan

Summary

The system must expire out of band authentication requests, codes or tokens after 10 minutes and should only allow them to be used once within this period.

Description

Secure out of band authenticators are physical devices that can communicate with an authentication verifier over a secure secondary channel. They serve as an additional security measure for identity assertion during authentication processes or sensitive transactions. Systems should expire out of band tokens after 10 minutes and allow them to be used only once within this period to prevent replay attacks.

Supported In

This requirement is verified in following services:

PlanSupported
Machine🔴
Squad🟢
One-Shot🟢

References

Vulnerabilities