Sierra Password Training 01.18.2023

Sierra Password Training 01.18.2023

 


Table of Contents

Password Training 01.18.2023

Training recording

Q & A Section

Sierra & Pika 

Q: Will this replace the last name/school ID our students currently use in Pika?

A: Right now, to log into Pika patrons use their name and school ID/library barcode. Whatever is stored in Sierra within the name and barcode field is authenticated against Pika. So essentially, once passwords are enabled Pika will authenticate against the barcode field and the password or PIN field that sits in Sierra. The person’s name will be completely removed from the authentication for Pika. 

Q: Will patrons be locked out of their account after a certain number of attempts and have to wait or go through additional steps to re-enable?

A: Currently, the functionality to lock out a patron from their account does not exist in any of the systems that patrons can log into that would communicate any failed attempts to Sierra.

Q: Is this correct: the password is always stored in Sierra.  Pika is just the place where patrons are going to set their passwords.

A: Correct, the patron record within Sierra is the authority of all the patron’s data. Pika just communicates via an API connection back to Sierra and sets that password field in the patron record. The password that gets set in Pika does not live in its own silo and is communicated back to Sierra.   

Q: Will the new PIN prompt NOT be automatic?

A: Marmot can update everyone’s patron record templates so the PIN field is automatically added. Library staff who normally edit record templates for your library can go into the patron record template to make changes.   

Q: Will we need to add Pin to accounts or will it already be set on the March 28 date?

A: Existing patron accounts will be populated with the default PIN on March 28th.  Based on the library’s preference Marmot will set a default PIN. 

  • For public libraries, if you set a PIN now, on March 28th that PIN or password will be reset to the default PIN or password. Unfortunately, there is no way to tell the system that if a password is set do not overwrite it.  

  • Academic libraries will not be getting the default passwords because they are constantly loading patron records every night. If Marmot was to set the default password it would just get overlaid the next night.   

Q: When can we start amending patron record templates to add PINs?

A: Technically within Sierra, library staff can start adding the PIN field now. Patrons will not be prompted for the authentication until Marmot turns on PINs on March 28th. 

Q: Can we add the PIN field to the patron record now?

A: Technically within Sierra, library staff can start adding the PIN field now. Patrons will not be prompted for the authentication until Marmot turns on PINs on March 28th. 

Q: For new patrons, we give them a PIN and then they update the PIN in Pika?

A: That would be the preference essentially because the purpose of passwords is supposed to be a patron-controlled field so that patrons are the only ones that know their passwords for the best security. Ideally, the library staff would not know the patron password and do not need to know the patron password. The library staff just needs to be able to provide the patron with a temporary means to log into Pika to set their own password.  

  • There has been a question asking if library staff can turn the keyboard towards the patron to have them type in their own password. This is a library-by-library decision. Patrons do have the option to set their own passwords in Pika as well.

Q: For the password default structure of the first three characters of the name field, what if the last name is less than three characters? 

A: Marmot is pulling the entire name field so they can pull more information from the name field. Marmot will share a file of the names that will cause errors for the password. Marmot will decide on case-by-case bases what should be done with some names that will not work with the default password structure.  

Q: Once this is all turned on and we are completely live with passwords, and library staff are creating a brand new patron record with a PIN in the PIN field so the patron will change it, will the patron automatically be prompted to change the password the first time they go to PIka?

A: This will require the use of the trigger fields within Sierra. In the patron record template, the trigger fields can be set for new patron accounts so that when the patrons go to log into Pika they will be prompted to change their password. Library staff can also go into the patron record and add the Reset Password field to a patron’s record after the patron record has been created.  

Q: Did I understand correctly that if we don't give them a PIN when we create the account, will they be prompted to create their password the first time they access PIKA?

A: No, patrons will be asked to give login into Pika with a card number and a password. If they do not know that password they cannot log in to change it. The only other functionality for leaving the password blank would be if the patron record has an email address then they can use the Reset My Password link to have an email sent to them to set their new password.  

Q: So for academic libraries how will we deal with the default passwords if they won't be automatically added on March 28?

A: Marmot will not be setting a default password for academic libraries. Marmot is allowing academic libraries to utilize the patron load functionality to choose the field that is being loaded into your student records. Marmot figures that academics have student accounts that have passwords or ID numbers that are part of the school system. Academic libraries will need to coordinate with their IT departments to load the student records because, within the load field or file, there is a column for the PIN.  This is where you are going to population the passwords.  In short, academics will be working with their IT departments to load an approved field into those password or PIN columns. 

  • For example, Colorado Mesa University actually started loading their PIN fields already. All of their student accounts now have a PIN field or a password field within their patron records in Sierra. 

  • As an academic, you could start coordinating with your IT department and start loading those whenever you wanted as well.    

Q: So the Sierra passwords do not really apply to academics?

A: Yes, the Sierra password and the password field will apply to the academic libraries. Passwords will be necessary to log into Pika and Prospector. Each academic institution decides what data from their school system gets loaded into the PIN field.  

Q: What if our IT doesn't want to share those passwords with us? Can we still get a default set by Marmot?

A: Yes, you can get a default password set by Marmot. Marmot would have to communicate with your IT department what the default is for the students so that their system will not overlay it. Marmot can also change the load profile that your library uses for student loads so that field does not get overlaid. The defaults are going to be temporary. Marmot does not want the default password to be something that is permanent. Marmot wants patrons to go in and change their password to something that they know.  At an academic institution, Marmot would encourage the students to change their password.  

Q: The PIN number is field 23, correct?

A: It is column 23 within the patron load.   

Q: Could academics use the institution credentials for this process?

A: Yes, whatever credentials you have for the academic institution will not be in the record as raw text. For example, if your institution uses the student ID number, ideally your password field would not also be the student ID number. Marmot does not encourage the barcode/student ID and password to be the same thing. As long as the student ID/barcode does not match the password, you can use your institution's credentials.   

Q: What if the patron's last name is less than 3 characters and we do use commas? Will the letters be lowercase?

A: We are using the first three letters of the name field, and the last four of either the barcode or phone number. Each library decides on the numeric display.

Q: So this resetting PIN functionality in PIKA is the same as using the trigger field in Sierra?

A: The Password Reset  trigger field in Sierra is how Pika authenticates if a password has been reset. Pika will not prompt for password reset if the trigger field in Sierra is fulfilled.

Q: Can I still use Sierra to place holds for patrons?

A: Yes, you can still use Sierra to place holds for patrons without ever needing a password. You will never be prompted for a password in Sierra. You are logging in as a staff member and not as a patron. You can place holds in Sierra for things like Homebound, branch display, and event cards. 

Q: What minimum number of digits or alphanumeric (with special characters) length should we use?

A: The functionality for limits is currently set for a minimum of 6 characters within the Sierra settings. Marmot suggests 8 characters, alphanumeric with symbols. 

Top of page

Pika Masquerade Mode & Reset Password

Q: Can we change the wording? School ID vs Barcode in Pika?

A: Currently, the field for the password reset has the word card number. This information can be changed to use the same login label there as well. Currently, libraries can change the wording on their login box. 

Q: So are we only using the barcode and password for Pika when we flip the switch? Or will it be the name + barcode + password?

A: Pika will use two fields for authentication. Barcode and Password.

Q: What if a patron does not have a valid email address to reset their password in Pika?

A: When filling out the reset my password field, if the patron does not have a valid email address in Sierra, the patron will get a message in Pika that they do not have an email address on their account and they should visit their library to reset their password. Library staff would use the Password Reset trigger field to prompt the patron to reset their password in Pika.

Q: On the login screen can there be a message for the first week regarding the new Password requirement?

A: The login labels can be changed to instruct patrons on the password requirements for your library. Pika admins or Marmot staff can change those login labels as well as set system messages that will display as banners on their Pika site.

Q: So if we choose no trigger, then the patron will not have to reset their password in PIKA, correct? If we are the ones who changed it in Sierra?

A: Essentially, Marmot’s stance from the security side of things is that library staff do not know the passwords in 90% of the cases. There are edge cases where the patrons do not ever log in and it is ideal for the library staff to know the password in the case of a home-bound patron. This is when the primary user of the account is a staff user. With those edge cases, the question is accurate. The staff can set the password and the patron does not have to reset it. For those edge cases, do what works for your library and try to set something that is secure. In the other 90% of cases with patrons who normally interact with their patron records in Pika, it is ideal for the patron to be the only one who knows their password. If the library staff knows the password on a patron’s record and that record gets breached, the library staff could be held liable for having the password as well as being the potential for the breach.   

Q: Where is the password reset message/email coming from? Is it a third-party provider to Marmot? Will it be the same provider for all Marmot Library Members?

A: The emails will come from the email address that is associated with the server. For Marmot, it will be coming from pika@marmot.org. This is Marmot functionality that is built into Pika. It is developed in-house and is not ported off to some third-party provider or vendor.  

Q: Will all staffers have this permission to masquerade as patrons?

A: Permission to masquerade is set by patron type. Libraries that do not have staff patron types should plan on adding one. Let Marmot know if you need to add a staff patron type.

Q: Can a person tell whether something was done in their account through masquerading mode?

A: Unless the patron is aware of what holds they had placed, the patron would not know that a staff member was in their account. Just beware when you are masquerading as a patron that if you cancel a hold or place a hold does happen live in their account.  

Q: Will masquerade mode be apparent from home or only at the library? Will staff be able to log in using someone else’s card number?

A: You have to be logged in with a library staff account in Pika. You have to have the patron’s library card number,  barcode number, or student ID to masquerade as them.  

Q: So we can turn on masquerade mode now and get our staff used to using it, correct?

A: It is currently only available in your test Pika sites until the go-live on March 28, 2023. You could use it on your Pika test sites to get prepared for the go-live. 

Q: What will happen to linked accounts in Sierra and Pika?

A: For linked accounts in Sierra, nothing will happen. As a staff member, you can log into Sierra without a password. The linked accounts functionality in Sierra is completely separate and will remain the same as it is now.  

In Pika, if accounts were previously linked, the linking is not lost, but both the manager and managed accounts have to reset their passwords for authentication. For newly established linking, the manager account will have to know the managed account’s unique password – the default password will not allow linking in Pika.

Q: So if we are logged in as staff, will the masquerade mode have a button on the website for us to access it?

A: When staff are logged into Pika with an account with a ptype that allows for masquerade mode, they will see the Masquerade option in the Pika account section. This is all outlined in the documentation in the knowledge base.

Top of page

Other Vendors

Q: Will we need to add passwords into Libby, do you know? 

A: Yes. The OverDrive system updates patrons against the ILS every 24 hours. On March 28th, any new logins will be required to sign in with their card number and password. Within 24 hours, all patrons who are currently logged in will be prompted to verify their cards which include the password that is now required to log in. The 24 hours applies to cards that are already signed in. A password change should not prevent a patron from signing into the collection.

Q: I assume the Libby password will have to be the same as the PIKA password/PIN correct?

A: Yes. It is not the Pika or Libby password, It is the Sierra password.  Pika and OverDrive both come back to Sierra and look at the one central location for the patron credentials. 

Q: Will this affect other databases? hoopla, EBSCO & other sideloaded records (we use a proxy server for off-campus)?

A: Databases that are library specific are on a case-by-case basis. Each library can choose if they want to have their patrons use passwords. For the shared eContent collections like OverDrive, we have to set those at the shared level rather than the individual library level. Marmot highly recommends that you turn on password authentication with as many of your database vendors as you can.  

Q: Will that conflict with logging into the Proxy Server? Will patrons need to log in twice?

A:  Authentication with a proxy server or EZProxy can be set at the individual library level. If you use a proxy that is hosted by Marmot the plan is to turn on password authentication for EZProxy.    

Top of page

Prospector

Q: For the Prospector override code supplied by Marmot to members, will the override code be changed periodically?

A: The override code is set at the Prospector system level. The plan is not necessary to change it. The only time we would need to change it is if that code was breached. Marmot would reach out to the Alliance that hosts the Prospector system and ask for a code change. Each library has its own override code to place Prospector holds for patrons. 

Q: Will patrons need the new password to do their own holds in Prospector?

A: Patrons will have to provide their name, card number, and password/PIN. We do not have the same control over how Prospector authenticates as we do with Pika.

Q: Do we have control over the "Password" placeholder text  in that Prospector window?

A: No, the placeholder text in the Encore system is controlled by the Alliance’s system. We don’t have the ability to change this at will.

Top of page