Integration Guide. SafeNet Authentication Service. SAS Using RADIUS Protocol with Microsoft DirectAccess
|
|
|
- Daniela Dennis
- 9 years ago
- Views:
Transcription
1 SafeNet Authentication Service Integration Guide SAS Using RADIUS Protocol with Microsoft DirectAccess Technical Manual Template Release 1.0, PN: , Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1
2 Document Information Document Part Number , Rev. A Release Date November 2014 Trademarks All intellectual property is protected by copyright. All trademarks and product names used or referred to are the copyright of their respective owners. No part of this document may be reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, chemical, photocopy, recording, or otherwise, without the prior written permission of SafeNet, Inc. Disclaimer SafeNet makes no representations or warranties with respect to the contents of this document and specifically disclaims any implied warranties of merchantability or fitness for any particular purpose. Furthermore, SafeNet reserves the right to revise this publication and to make changes from time to time in the content hereof without the obligation upon SafeNet to notify any person or organization of any such revisions or changes. We have attempted to make these documents complete, accurate, and useful, but we cannot guarantee them to be perfect. When we discover errors or omissions, or they are brought to our attention, we endeavor to correct them in succeeding releases of the product. SafeNet invites constructive comments on the contents of this document. These comments, together with your personal and/or company details, should be sent to the address or below. Contact Method Mail Contact Information SafeNet, Inc Millennium Drive Belcamp, Maryland 21017, USA [email protected] 2
3 Contents Contents Third-Party Software Acknowledgement... 4 Description... 4 Applicability... 4 Environment... 4 Audience... 5 RADIUS-based Authentication using SAS Cloud... 5 RADIUS-based Authentication using SAS-SPE and SAS-PCE... 6 RADIUS Authentication Flow using SAS... 6 RADIUS Prerequisites... 7 Configuring SafeNet Authentication Service... 7 Synchronizing User Stores to SafeNet Authentication Service... 7 Assigning Authenticator in SAS... 8 Adding Microsoft DirectAccess as an Authentication Node in SAS... 9 Checking the SAS RADIUS IP Address Creating DAProbeUser Configuring Microsoft DirectAccess Creating and Deploying a Certificate Template for Signing the OTP Certificate Requests Creating and Deploying a Certificate Template for OTP Certificates Issued by Corporate CA Configuring OTP for DirectAccess Confirming DirectAccess Configuration for OTP Configuring the DirectAccess Client Running the Solution Troubleshooting DirectAccess Not Prompting for OTP Credentials Support Contacts
4 Third-Party Software Acknowledgement This document is intended to help users of SafeNet products when working with third-party software, such as Microsoft DirectAccess. Material from third-party software is being used solely for the purpose of making instructions clear. Screen images and content obtained from third-party software will be acknowledged as such. Description SafeNet Authentication Service delivers a fully automated, versatile, and strong authentication-as-a-service solution. With no infrastructure required, SafeNet Authentication Service provides smooth management processes and highly flexible security policies, token choice, and integration APIs. DirectAccess is a VPN-like technology that provides intranet connectivity to the client computers when they are connected to the Internet. Unlike many traditional VPN connections, which must be initiated and terminated by explicit user action, DirectAccess connections are designed to connect automatically as soon as the computer connects to the Internet. DirectAccess was introduced in Windows Server 2008 R2, providing this service to Windows 7 and Windows 8 Enterprise edition clients. This document describes how to: Deploy multi-factor authentication (MFA) options in Microsoft DirectAccess using SafeNet OTP authenticators managed by SafeNet Authentication Service. Configure Microsoft DirectAccess to work with SafeNet Authentication Service in RADIUS mode. It is assumed that the Microsoft DirectAccess environment is already configured and working with static passwords prior to implementing multi-factor authentication using SafeNet Authentication Service. Microsoft DirectAccess can be configured to support multi-factor authentication in several modes. The RADIUS protocol will be used for the purpose of working with SafeNet Authentication Service. Applicability The information in this document applies to: SafeNet Authentication Service (SAS) SafeNet s cloud-based authentication service. SafeNet Authentication Service Service Provider Edition (SAS-SPE) A server version that is used by Service Providers to deploy instances of SafeNet Authentication Service. SafeNet Authentication Service Private Cloud Edition (SAS-PCE) A server version that is used to deploy the solution on-premises in the organization. Environment The integration environment that was used in this document is based on the following software versions: SafeNet Authentication Service SafeNet s cloud-based authentication service Microsoft DirectAccess - Windows Server 2012 R2 4
5 Audience This document is targeted to system administrators who are familiar with Microsoft DirectAccess and are interested in adding multi-factor authentication capabilities using SafeNet Authentication Service. RADIUS-based Authentication using SAS Cloud SAS Cloud provides two RADIUS mode topologies: SAS cloud hosted RADIUS service A RADIUS service that is already implemented in the SAS cloud environment and can be used without any installation or configuration requirements. Local RADIUS hosted on-premises - A RADIUS agent that is implemented in the existing customer s RADIUS environment. The agent forwards the RADIUS authentication requests to the SAS cloud environment. The RADIUS agent can be implemented on a Microsoft NPS/IAS or FreeRADIUS server. For more information on how to install and configure SAS Agent for IAS/NPS, refer to: For more details on how to install and configure FreeRADIUS, refer to the SAS FreeRADIUS Agent Configuration Guide. This document demonstrates the solution using the SAS cloud hosted RADIUS service. 5
6 RADIUS-based Authentication using SAS-SPE and SAS-PCE In addition to the pure cloud-based offering, SafeNet Authentication Service comes with two on-premises versions: SafeNet Authentication Service Service Provider Edition (SPE) An on-premises version of SafeNet Authentication Service targeted at service providers interested in hosting SAS in their data center. SafeNet Authentication Service Private Cloud Edition (PCE) An on-premises version of SafeNet Authentication Service targeted at organizations interested in hosting SAS in their private cloud environment. For both on-premises versions, SAS can be integrated with the following solutions that serve as local RADIUS servers: Microsoft Network Policy Server (MS-NPS) or the legacy Microsoft Internet Authentication Service (MS-IAS) SafeNet Authentication Service is integrated with the local RADIUS servers using a special onpremises agent called SAS Agent for Microsoft IAS and NPS. For more information on how to install and configure the SAS Agent for Microsoft IAS and NPS, refer to the following document: FreeRADIUS The SAS FreeRADIUS Agent is a strong authentication agent that is able to communicate with SAS through the RADIUS protocol. For more information on how to install and configure the SAS FreeRADIUS Agent, refer to the SafeNet Support Portal. RADIUS Authentication Flow using SAS SafeNet Authentication Service communicates with a large number of VPN and access-gateway solutions using the RADIUS protocol. The image below describes the dataflow of a multi-factor authentication transaction for Microsoft DirectAccess. 1. A user attempts to log on to Microsoft DirectAccess using an OTP authenticator. 2. Microsoft DirectAccess sends a RADIUS request with the user s credentials to SafeNet Authentication Service for validation. 3. The SAS authentication reply is sent back to Microsoft DirectAccess. 4. The user is granted or denied access to Microsoft DirectAccess based on the OTP value calculation results from SAS. 6
7 RADIUS Prerequisites To enable SafeNet Authentication Service to receive RADIUS requests from Microsoft DirectAccess, ensure the following: End users can authenticate through the Microsoft DirectAccess environment with a static password before configuring the Microsoft DirectAccess to use RADIUS authentication. Port 1812 is open to and from Microsoft DirectAccess. A shared secret key has been selected, providing an added layer of security by supplying an indirect reference to a shared secret key. It is used by a mutual agreement between the RADIUS server and the RADIUS client for encryption, decryption, and digital signature purposes. The user DAProbeUser exists in SAS. For more information, refer to the section Creating DAProbeUser on page 12. NOTE: For RADIUS authentication, DirectAccess should be set up using this guide: NOTE: RADIUS authentication does not work with DirectAccess set up on a single server. Configuring SafeNet Authentication Service The deployment of multi-factor authentication using SAS with Microsoft DirectAccess using the RADIUS protocol requires the following: Synchronizing User Stores to SAS Assigning Authenticator in SAS Adding Microsoft DirectAccess as an Authentication Node in SAS Checking the SAS RADIUS IP address Creating DAProbeUser Synchronizing User Stores to SafeNet Authentication Service Before SAS can authenticate any user in your organization, you must create a user store in SAS that reflects the users that would need to use multi-factor authentication. User records are created in the SAS user store using one of the following methods: Manually, one user at a time using the Create User shortcut Manually, by importing one or more user records via a flat file Automatically, by synchronizing with your Active Directory / LDAP server using the SAS Synchronization Agent 7
8 For further details on importing users to SafeNet Authentication Service, refer to the section on creating users in the SafeNet Authentication Service Subscriber Account Operator Guide. SubscriberAccountOperatorGuide.pdf All SafeNet Authentication Service documentation can be found on the SafeNet Knowledge Base site. Assigning Authenticator in SAS SAS supports a number of authentication methods that can be used as second authentication factor for users who are authenticating through Microsoft DirectAccess. The following authenticators are supported: etoken PASS KT-4 token SMS token MP-1 software token MobilePASS Authenticators can be assigned to users in two ways: Manual provisioning Assign an authenticator to users one by one. Provisioning rules The administrator can set provisioning rules in SAS so that the rules will be triggered when group memberships and other user attributes change; an authenticator will be assigned automatically to the user. Refer to provisioning rules in the SafeNet Authentication Service - Subscriber Account Operator Guide to learn how to provision the different authentication methods to the users in the SAS user store. SubscriberAccountOperatorGuide.pdf 8
9 Adding Microsoft DirectAccess as an Authentication Node in SAS Add a RADIUS entry in the SAS Authentication Nodes module to prepare it to receive RADIUS authentication requests from Microsoft DirectAccess. You will need the IP address of Microsoft DirectAccess and the shared secret to be used by both SAS and Microsoft DirectAccess. To add an Authentication Node in SAS: 1. Log in to the SAS console with an Operator account. 2. Click the COMMS tab, and then select the Auth Nodes module. 3. In the Auth Nodes module, click the Auth Nodes link. 9
10 4. Click Add. 5. In the Add Auth Nodes section, complete the following fields, and then click Save: Agent Description Host Name Low IP Address In Range Configure FreeRADIUS Synchronization Shared Secret Confirm Shared Secret Enter a host description. Enter the name of the host that will authenticate with SAS. Enter the IP address of the host. Select this option. Enter the shared secret key. Re-enter the shared secret key to confirm it. The Auth Node is added to the system. 10
11 Checking the SAS RADIUS IP Address Before adding SafeNet Authentication Service as a RADIUS server in Microsoft DirectAccess, check the IP address of the SAS RADIUS server. The IP address will then be added to Microsoft DirectAccess as a RADIUS server at a later stage. To check the IP address of the SAS RADIUS server: 1. Log in to the SAS console with an Operator account. 2. Click the COMMS tab, and then select the Auth Nodes module. 3. Click the Auth Nodes link. 11
12 The SAS RADIUS server details are displayed. Creating DAProbeUser DirectAccess uses an internal built-in user, DAProbeUser, to check the RADIUS connectivity. There is no need to allocate a token to DAProbeUser. You must create a user with the same name in SAS. 1. Log in to the SAS console with an Operator account. 2. In the left pane, click Create User. 3. On the Create User window, complete the following, and then click Add. First Name Last Name User ID Enter the first name of the user. Enter the last name of the user. Enter DAProbeUser. Enter the ID of the user. 12
13 Configuring Microsoft DirectAccess Configuring Microsoft DirectAccess for RADIUS authentication requires the following: Creating and Deploying a Certificate Template for Signing the OTP Certificate Requests page 13 Creating and Deploying a Certificate Template for OTP Certificates Issued by Corporate CA page 20 Configuring OTP for DirectAccess page 29 Confirming DirectAccess Configuration for OTP page 30 Configuring the DirectAccess Client page 30 Creating and Deploying a Certificate Template for Signing the OTP Certificate Requests You must create and configure a certificate template, which will be used to sign the OTP certificate requests. 1. Log in to the system on which the Certificate Authority server is installed. 2. Start the Windows Command Prompt application, and run the certtmpl.msc application. 3. On the Certificate Templates Console window, right-click the Computer template, and then click Duplicate Template. 13
14 4. On the Properties of New Template window, on the Compatibility tab, complete the following fields. Certificate Authority Certificate recipient Select an appropriate Certification Authority; for example, Windows Server On the Resulting changes window, click OK. Select an appropriate Certificate recipient; for example, Windows 8/Windows Server On the Resulting changes window, click OK. 14
15 5. On the Properties of New Template window, on the General tab, complete the following fields. Template display name Validity period Renewal period Enter the template name for display; for example, DAOTPRA. Set the validity period to 2 days. Set the renewal period to 1 day. NOTE: If the Certificate Templates warning is displayed, click OK. 15
16 6. On the Properties of New Template window, on the Security tab, click Add. 7. On the Select Users, Computers, Service Accounts, or Groups window, perform the following steps: a. Click Object Types. b. On the Object Types window, select Computers, and then click OK. c. In the Enter the object names to select field, enter the name of server on which DirectAccess is configured, and then click OK. 16
17 8. On the Properties of New Template window, on the Security tab, select a group or a user in the Group or user names section and then set permissions for that group or user in the Permissions section, as explained in the table below: DA Authenticated Users Domain Computers Domain Admins Enterprise Admins Set only the Read, Enroll, and Autoenroll permissions. Set only the Read permission. Remove the Enroll permission and keep the other default permissions. Set the Full Control permission. Set the Full Control permission. 17
18 9. On the Properties of New Template window, on the Subject Name tab, perform the following, and then click Apply: a. Select Build from this Active Directory information. b. In the Subject name format field, select DNS name. c. Under Include this information in alternate subject name, select DNS name. 18
19 10. On the Properties of New Template window, on the Extensions tab, perform the following steps, and then click OK. a. In the Extensions included in the template list, select Application Policies, and then click Edit. b. On the Edit Application Policies Extension window, remove all the existing application policies, and then click Add. c. On the Add Application Policy window, click New, complete the following fields, and then click OK. Name Enter DAOTPRA. Object identifier Enter d. On the Add Application Policy window, click OK. e. On the Edit Application Policies Extension window, click OK. 19
20 Creating and Deploying a Certificate Template for OTP Certificates Issued by Corporate CA You must create and configure a certificate template for OTP certificates, which is issued by the corporate Certificate Authority. 1. Log in to the system on which the Certificate Authority server is installed. 2. Start the Windows Command Prompt application, and run the certtmpl.msc application. 3. On the Certificate Templates Console window, right-click the Smartcard Logon template, and then click Duplicate Template. 20
21 4. On the Properties of New Template window, on the Compatibility tab, complete the following fields. Certificate Authority Certificate recipient Select an appropriate Certification Authority; for example, Windows Server On the Resulting changes window, click OK. Select an appropriate Certificate recipient; for example, Windows 8/Windows Server On the Resulting changes window, click OK. 21
22 5. On the Properties of New Template window, on the General tab, complete the following fields. Template display name Validity period Renewal period Enter the template name for display; for example, DAOTPLogon. Set the validity period to 1 hour. Set the renewal period to 0 hour. For more information on setting the Validity period and Renewal period, see 22
23 6. On the Properties of New Template window, on the Security tab, select a group or a user in the Group or user names section and then set permissions for that group or user in the Permissions section, as explained in the table below: Authenticated Users Domain Admins Enterprise Admins Set only the Read and Enroll permissions. Set the Full Control permission. Set the Full Control permission. 23
24 7. On the Properties of New Template window, on the Subject Name tab, perform the following steps, and then click Apply: a. Select Build from this Active Directory information. b. In the Subject name format field, select Fully distinguished name. c. Under Include this information in alternate subject name, select User principal name (UPN). 24
25 8. On the Properties of New Template window, on the Server tab, perform the following steps, and then click Apply: a. Select Do not store certificates and requests in the CA database. b. Clear Do not include revocation information in issued certificates. 25
26 9. On the Properties of New Template window, on the Issuance Requirements tab, complete the following fields, and then click Apply: This number of authorized signatures Policy type required in signature Application policy Select this option and then set the value to 1. Select Application policy. Select DAOTPRA. 26
27 10. On the Properties of New Template window, on the Extensions tab, perform the following steps, and then click OK. a. In the Extensions included in the template list, select Application Policies, and then click Edit. b. On the Edit Application Policies Extension window, delete Client Authentication and keep SmartCardLogon. c. On the Edit Application Policies Extension window, click OK. 11. Close the Certificate Templates Console window. 12. Start the Windows Command Prompt application, and run the certsrv.msc application. 27
28 13. On the Certificate Authority window, in the left pane, expand Certification Authority, rightclick Certificate Templates, and then click New > Certificate Template to Issue. 14. On the Enable Certificate Templates window, select DAOTPRA and DAOTPLogon, and then click OK. 28
29 15. On the Certificate Authority window, in the right pane, the DAOTPRA and DAOTPLogon certificate templates are added. 16. Restart the Certification Authority services. 17. Close the Certificate Authority window. 18. Start the Windows Command Prompt application as an administrator, and run the following command: CertUtil.exe SetReg DBFlags +DBFLAGS_ENABLEVOLATILEREQUESTS Configuring OTP for DirectAccess To configure OTP authentication for DirectAccess: 1. Log in to the server on which DirectAccess is installed. 2. Run PowerShell as an administrator, and run the following command: Enable-DAOtpAuthentication RadiusServer <RADIUS server name/ip address> SharedSecret <Shared Secret> -CAServer <Certificate Authority Name> CertificateTemplateName <Certificate template Name> SigningCertificateTemplate <Signing Certificate Template name> Where, RADIUS server name/ip Address is the FQDN of the RADIUS server or its IP address. Shared Secret is the shared password used for communication between the RADIUS server and DirectAccess. Certificate Authority Name is the Certification Authority (CA) servers that issue certificates for OTP authentication. Specify a server in the following format: -- CAServer_Name\CAService_Name Certificate Template Name is the name of the certificate template configured in the section Creating and Deploying a Certificate Template for OTP Certificates Issued by Corporate CA on page 20. Signing Certificate Template Name is the name of the certificate template configured in the section: Creating and Deploying a Certificate Template for Signing the OTP Certificate Requests on page 13. NOTE: The same steps can be done using the Remote Access Management Console as well. Currently, Windows Server 2012 R2 does not automatically detect CAServer. Thus, the PowerShell command is used to configure OTP for DirectAccess. 29
30 Confirming DirectAccess Configuration for OTP Verify whether the configurations for OTP on DirectAccess were successfully applied or not. 1. On the DirectAccess server, open Remote Access Management Console. 2. In the left pane, click Operations Status. 3. In the right pane, verify that the status of OTP is Working. Configuring the DirectAccess Client Update the group policies of DirectAccess client to receive the DirectAccess settings. 1. Connect the DirectAccess client to the corporate network. 2. Open PowerShell as an administrator. 3. Type Get-DnsClientNrptPolicy and press ENTER. The Name Resolution Policy Table (NRPT) entries for DirectAccess are displayed. 4. Type Get-NCSIPolicyConfiguration and press ENTER. The network connectivity status indicator settings deployed by the wizard are displayed. 5. Type gpupdate /force and press ENTER. 30
31 Running the Solution To run the DirectAccess solution with SafeNet Authentication Service, perform the following steps: 1. Connect the DirectAccess client to the Internet. 2. In the System Notification area, click the network icon. Click the name of the DirectAccess connection and then click Continue. 3. When a message is shown to press Ctrl+Alt+Delete to enter the credentials, do so. 31
32 4. Click One-time password (OTP). 5. Generate the OTP and enter it in the Enter your OTP credentials field. Click OK. If the credentials are correct, the user will be logged in and will get connected to DirectAccess. 32
33 Troubleshooting DirectAccess Not Prompting for OTP Credentials Even when DirectAccess is configured for two-factor authentication, the client machine may not ask for the OTP and gets automatically connected to the DirectAccess server. This can happen because the client machine has access to internal resources without OTP authentication. To troubleshoot this problem, perform the following steps: 1. Log in to the machine on which the Domain Name Server is present, and then open DNS Manager. 33
34 2. In the left pane, expand Forward Lookup Zones, right-click the Domain name and click New Host (A or AAAA). 3. On the New Host window, enter a host name in the Name field (for example, fileshare) and then enter the IP address of NLS server in the IP address field. Click Add Host. 34
35 4. Log in to the machine on which DirectAccess is configured and open Remote Access Management Console. 5. On the Remote Access Management Console window, in the left pane, click DirectAccess and VPN. Under Step 1, click Edit. 6. In the left pane, click Network Connectivity Assistant. 35
36 7. In the right pane, right-click on the empty row, and then click New. 8. On the Configure Corporate Resources for NCA window, enter the URL of the new host added (for example, and then click Validate. If connectivity is successfully validated, click Add. 9. Click Finish. 10. Click Finish again to apply the configuration. 36
37 Support Contacts If you encounter a problem while installing, registering, or operating this product, please make sure that you have read the documentation. If you cannot resolve the issue, contact your supplier or SafeNet Customer Support. SafeNet Customer Support operates 24 hours a day, 7 days a week. Your level of access to this service is governed by the support plan arrangements made between SafeNet and your organization. Please consult this support plan for further information about your entitlements, including the hours when telephone support is available to you. Contact Method Address Contact Information SafeNet, Inc Millennium Drive Belcamp, Maryland USA Phone United States International Technical Support Customer Portal Existing customers with a Technical Support Customer Portal account can log in to manage incidents, get the latest software upgrades, and access the SafeNet Knowledge Base. 37
Integration Guide. SafeNet Authentication Service. SAS Using RADIUS Protocol with Apache HTTP Server
SafeNet Authentication Service Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
Integration Guide. SafeNet Authentication Service. Using SAS as an Identity Provider for Tableau Server
SafeNet Authentication Service Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
Integration Guide. SafeNet Authentication Service. Using SAS as an Identity Provider for Salesforce
SafeNet Authentication Service Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
Integration Guide. SafeNet Authentication Service. Using RADIUS Protocol for Radiator RADIUS Server
SafeNet Authentication Service Integration Guide TechnicalManual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information Document
Integration Guide. SafeNet Authentication Service. VMWare View 5.1
SafeNet Authentication Service Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
Integration Guide. SafeNet Authentication Service. Using SAS as an Identity Provider for Drupal
SafeNet Authentication Service Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
SafeNet Authentication Service
SafeNet Authentication Service Integration Guide All information herein is either public information or is the property of and owned solely by Gemalto NV. and/or its subsidiaries who shall have and keep
SafeNet Authentication Service
SafeNet Authentication Service All information herein is either public information or is the property of and owned solely by Gemalto NV. and/or its subsidiaries who shall have and keep the sole right to
Integration Guide. SafeNet Authentication Service. Using RADIUS and LDAP Protocols for Cisco Secure ACS
SafeNet Authentication Service Integration Guide Using RADIUS and LDAP Protocols for Cisco Secure ACS Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet,
Integration Guide. SafeNet Authentication Service. Using SAS with Web Application Proxy. Technical Manual Template
SafeNet Authentication Service Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
Installation Guide. SafeNet Authentication Service
SafeNet Authentication Service Installation Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
Configuration Guide. SafeNet Authentication Service AD FS Agent
SafeNet Authentication Service AD FS Agent Configuration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document
Integration Guide. SafeNet Authentication Service. Oracle Secure Desktop Using SAS RADIUS OTP Authentication
SafeNet Authentication Service Integration Guide Oracle Secure Desktop Using SAS RADIUS OTP Authentication Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013
HOTPin Integration Guide: DirectAccess
1 HOTPin Integration Guide: DirectAccess Disclaimer Disclaimer of Warranties and Limitation of Liabilities All information contained in this document is provided 'as is'; Celestix assumes no responsibility
SafeNet Authentication Service
SafeNet Authentication Service Integration Guide All information herein is either public information or is the property of and owned solely by Gemalto NV. and/or its subsidiaries who shall have and keep
Integration Guide. SafeNet Authentication Client. Using SAC CBA for Check Point Security Gateway
SafeNet Authentication Client Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information Document
Configuration Guide. SafeNet Authentication Service. SAS Agent for Microsoft Outlook Web Access 1.06
SafeNet Authentication Service Configuration Guide 1.06 Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
Agent Configuration Guide
SafeNet Authentication Service Agent Configuration Guide SAS Agent for Microsoft Internet Information Services (IIS) Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright
Configuration Guide. SafeNet Authentication Service. Remote Logging Agent
SafeNet Authentication Service Configuration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
Integration Guide. SafeNet Authentication Service. Using RADIUS Protocol for Cisco ASA
SafeNet Authentication Service Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copy right 2013 Saf enet, Inc. All rights reserv ed. 1 Document Information
Integration Guide. SafeNet Authentication Client. Using SAC with Putty-CAC
SafeNet Authentication Client Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information Document
Configuration Guide. SafeNet Authentication Service. SAS Agent for Microsoft Internet Information Services (IIS)
SafeNet Authentication Service Configuration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
Configuration Guide. SafeNet Authentication Service. Token Validator Proxy Agent
SafeNet Authentication Service Configuration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
Synchronization Agent Configuration Guide
SafeNet Authentication Service Synchronization Agent Configuration Guide 1 Document Information Document Part Number 007-012476-001, Revision A Release Date July 2014 Trademarks All intellectual property
Configuration Guide. SafeNet Authentication Service. SAS Agent for Microsoft Outlook Web App. Technical Manual Template
SafeNet Authentication Service Configuration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
SafeNet Cisco AnyConnect Client. Configuration Guide
SafeNet Cisco AnyConnect Client Configuration Guide All information herein is either public information or is the property of and owned solely by Gemalto NV. and/or its subsidiaries who shall have and
SafeNet Authentication Service
SafeNet Authentication Service Push OTP Integration Guide All information herein is either public information or is the property of and owned solely by Gemalto NV. and/or its subsidiaries who shall have
Migration Guide. SafeNet Authentication Service. SafeWord/SAMx. Migration Guide: SafeNet Authentication Service. SafeWord/SAMx
SafeNet Authentication Service Migration Guide 1 Document Information Document Part Number 007-012524-001, Rev. C Release Date January 2015 Trademarks All intellectual property is protected by copyright.
Microsoft IAS and NPS Agent Configuration Guide
Microsoft IAS and NPS Agent Configuration Guide Powerful Authentication Management for Service Providers and Enterprises Authentication Service Delivery Made EASY Agent IAS and NPS (Microsoft) Configuration
Integration Guide. SafeNet Authentication Service. Integrating Active Directory Lightweight Services
SafeNet Authentication Service Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
Gemalto SafeNet Minidriver 9.0
SafeNet Authentication Client Gemalto SafeNet Minidriver 9.0 Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document
SafeNet Authentication Manager Express. Upgrade Instructions All versions
SafeNet Authentication Manager Express Upgrade Instructions All versions www.safenet-inc.com 4690 Millennium Drive, Belcamp, Maryland 21017 USA Telephone: +1 410 931 7500 or 1 800 533 3958 www.safenet-inc.com
Microsoft IIS Integration Guide
Microsoft IIS Integration Guide Preface Preface 2015 SafeNet, Inc. All rights reserved. Part Number: 007-011955-001 (Rev E, 12/2015) All intellectual property is protected by copyright. All trademarks
SAS Agent for Outlook Web Access
SAS Agent for Outlook Web Access CUSTOMER RELEASE NOTES Version: 1.06 Build: 1.06.27725 Issue Date: 4 February 2015 Document Part Number: 007-012888-001, Rev. D Contents Product Description... 2 Release
User Guide. SafeNet MobilePASS for Windows Phone
SafeNet MobilePASS for Windows Phone User Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information Product
Active Directory Rights Management Service Integration Guide
Active Directory Rights Management Service Integration Guide Preface Preface 2013 SafeNet, Inc. All rights reserved. Part Number: 007-011230-001 (Rev F, 07/2013) All intellectual property is protected
Preface. Microsoft Office Sharepoint Server 2007 Integration Guide. 2009 SafeNet, Inc. All rights reserved. Part Number: 009804-001 (Rev A, 06/2009)
Microsoft Office Sharepoint Server 2007 Integration Guide Preface Preface 2009 SafeNet, Inc. All rights reserved. Part Number: 009804-001 (Rev A, 06/2009) All intellectual property is protected by copyright.
SafeNet MobilePASS Version 8.2.0, Revision B
SafeNet MobilePASS Version 8.2.0, Revision B User Guide Software Version 8.2.0 Documentation Version: 20101118 2012 SafeNet, Inc. All rights reserved Preface All intellectual property is protected by copyright.
Juniper SSL VPN Authentication QUICKStart Guide
Juniper SSL VPN Authentication QUICKStart Guide Powerful Authentication Management for Service Providers and Enterprises Authentication Service Delivery Made EASY Copyright 2012 SafeNet, Inc. All rights
DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication
DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication Certificate Based 2010 Integration VASCO Data Security. Guideline All rights reserved. Page 1 of 31 Disclaimer Disclaimer of
Cisco ASA Authentication QUICKStart Guide
Cisco ASA Authentication QUICKStart Guide Powerful Authentication Management for Service Providers and Enterprises Authentication Service Delivery Made EASY Copyright 2012 SafeNet, Inc. All rights reserved.
SafeNet Authentication Service
SafeNet Authentication Service Integration Guide All information herein is either public information or is the property of and owned solely by Gemalto NV. and/or its subsidiaries who shall have and keep
Protecting Juniper SA using Certificate-Based Authentication. Quick Start Guide
Protecting Juniper SA using Certificate-Based Authentication Copyright 2013 SafeNet, Inc. All rights reserved. All attempts have been made to make the information in this document complete and accurate.
Microsoft SQL Server Integration Guide
Microsoft SQL Server Integration Guide Document Information Document Part Number 007-011108-001 (Rev J) Release Date August 2013 Trademarks All intellectual property is protected by copyright. All trademarks
Windows Server Update Services 3.0 SP2 Step By Step Guide
Windows Server Update Services 3.0 SP2 Step By Step Guide Microsoft Corporation Author: Anita Taylor Editor: Theresa Haynie Abstract This guide provides detailed instructions for installing Windows Server
SAS Agent for Outlook Web App
SAS Agent for Outlook Web App CUSTOMER RELEASE NOTES Version: 1.08 Build: 1.08.579 Issue Date: 17 November 2015 Document Part Number: 007-012888-001, Rev. F Contents Product Description... 2 Release Description...
Dell One Identity Cloud Access Manager 8.0.1 - How to Configure Microsoft Office 365
Dell One Identity Cloud Access Manager 8.0.1 - How to Configure Microsoft Office 365 May 2015 This guide describes how to configure Microsoft Office 365 for use with Dell One Identity Cloud Access Manager
SAS Token Validator Proxy Agent Configuration Guide
SAS Token Validator Proxy Agent Configuration Guide Powerful Authentication Management for Service Providers and Enterprises Authentication Service Delivery Made EASY Copyright 2014 SafeNet, Inc. All rights
SafeNet Authentication Service
SafeNet Authentication Service Integration Guide Using SafeNet Authentication Service as an Identity Provider for Microsoft Outlook Web App All information herein is either public information or is the
Strong Authentication for Juniper Networks SSL VPN
Strong Authentication for Juniper Networks SSL VPN with Powerful Authentication Management for Service Providers and Enterprises Authentication Service Delivery Made EASY Copyright Copyright 2011. CRYPTOCard
Microsoft Dynamics GP Release
Microsoft Dynamics GP Release Workflow Installation and Upgrade Guide February 17, 2011 Copyright Copyright 2011 Microsoft. All rights reserved. Limitation of liability This document is provided as-is.
SafeNet MSSQL EKM Provider User Guide
SafeNet MSSQL EKM Provider User Guide Version 4.8.5 Documentation Version: 20080705 Copyright Information 2009 SafeNet, Inc. All rights reserved All intellectual property is protected by copyright. All
Hands-On Lab: WSUS. Lab Manual Expediting WSUS Service for XP Embedded OS
Lab Manual Expediting WSUS Service for XP Embedded OS Summary In this lab, you will learn how to deploy the security update to your XP Pro or XP embedded images. You will also learn how to prepare the
Step By Step Guide: Demonstrate DirectAccess in a Test Lab
Step By Step Guide: Demonstrate DirectAccess in a Test Lab Microsoft Corporation Published: May 2009 Updated: October 2009 Abstract DirectAccess is a new feature in the Windows 7 and Windows Server 2008
HOTPin Integration Guide: Microsoft Office 365 with Active Directory Federated Services
HOTPin Integration Guide: Microsoft Office 365 with Active Directory Federated Services Disclaimer Disclaimer of Warranties and Limitation of Liabilities All information contained in this document is provided
SECO Whitepaper. SuisseID Smart Card Logon Configuration Guide. Prepared for SECO. Publish Date 19.05.2010 Version V1.0
SECO Whitepaper SuisseID Smart Card Logon Configuration Guide Prepared for SECO Publish Date 19.05.2010 Version V1.0 Prepared by Martin Sieber (Microsoft) Contributors Kunal Kodkani (Microsoft) Template
Configuration Guide. BES12 Cloud
Configuration Guide BES12 Cloud Published: 2016-04-08 SWD-20160408113328879 Contents About this guide... 6 Getting started... 7 Configuring BES12 for the first time...7 Administrator permissions you need
Installation and Configuration Guide
www.novell.com/documentation Installation and Configuration Guide GroupWise Coexistence Solution for Exchange November 2015 Legal Notices Novell, Inc., makes no representations or warranties with respect
Digipass Plug-In for IAS. IAS Plug-In IAS. Microsoft's Internet Authentication Service. Installation Guide
Digipass Plug-In for IAS IAS Plug-In IAS Microsoft's Internet Authentication Service Installation Guide Disclaimer of Warranties and Limitations of Liabilities Disclaimer of Warranties and Limitations
Installation and Configuration Guide
Entrust Managed Services PKI Auto-enrollment Server 7.0 Installation and Configuration Guide Document issue: 1.0 Date of Issue: July 2009 Copyright 2009 Entrust. All rights reserved. Entrust is a trademark
Configuration Guide. SafeNet Authentication Service. SAS Agent for PEAP
SafeNet Authentication Service Configuration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
Dell One Identity Cloud Access Manager 8.0.1 - How to Configure for SSO to SAP NetWeaver using SAML 2.0
Dell One Identity Cloud Access Manager 8.0.1 - How to Configure for SSO to SAP NetWeaver using SAML 2.0 May 2015 About this guide Prerequisites and requirements NetWeaver configuration Legal notices About
Sage 200 Web Time & Expenses Guide
Sage 200 Web Time & Expenses Guide Sage (UK) Limited Copyright Statement Sage (UK) Limited, 2006. All rights reserved If this documentation includes advice or information relating to any matter other than
Compiled By: Chris Presland v1.0. 29 th September. Revision History Phil Underwood v1.1
Compiled By: Chris Presland v1.0 Date 29 th September Revision History Phil Underwood v1.1 This document describes how to integrate Checkpoint VPN with SecurEnvoy twofactor Authentication solution called
SAM Context-Based Authentication Using Juniper SA Integration Guide
SAM Context-Based Authentication Using Juniper SA Integration Guide Revision A Copyright 2012 SafeNet, Inc. All rights reserved. All attempts have been made to make the information in this document complete
www.novell.com/documentation Jobs Guide Identity Manager 4.0.1 February 10, 2012
www.novell.com/documentation Jobs Guide Identity Manager 4.0.1 February 10, 2012 Legal Notices Novell, Inc. makes no representations or warranties with respect to the contents or use of this documentation,
User Application: Design Guide
www.novell.com/documentation User Application: Design Guide Designer for Identity Manager Roles Based Provisioning Tools 4.0.2 June 15, 2012 Legal Notices Novell, Inc. makes no representations or warranties
Sophos Mobile Control as a Service Startup guide. Product version: 3.5
Sophos Mobile Control as a Service Startup guide Product version: 3.5 Document date: August 2013 Contents 1 About this guide...3 2 What are the key steps?...4 3 First login...5 4 Change your administrator
Business Portal for Microsoft Dynamics GP 2010. Field Service Suite
Business Portal for Microsoft Dynamics GP 2010 Field Service Suite Copyright Copyright 2010 Microsoft. All rights reserved. Limitation of liability This document is provided as-is. Information and views
Avaya Modular Messaging Microsoft Outlook Client Release 5.2
Avaya Modular Messaging Microsoft Outlook Client Release 5.2 Important: Instructions in this guide are applicable only if your message store is the Avaya Message Storage Server (MSS) or Microsoft Exchange
HOTPin Integration Guide: Google Apps with Active Directory Federated Services
HOTPin Integration Guide: Google Apps with Active Directory Federated Services Disclaimer Disclaimer of Warranties and Limitation of Liabilities All information contained in this document is provided 'as
YubiKey PIV Deployment Guide
YubiKey PIV Deployment Guide Best Practices and Basic Setup YubiKey 4, YubiKey 4 Nano, YubiKey NEO, YubiKey NEO-n YubiKey PIV Deployment Guide 2016 Yubico. All rights reserved. Page 1 of 27 Copyright 2016
Security Provider Integration RADIUS Server
Security Provider Integration RADIUS Server 2015 Bomgar Corporation. All rights reserved worldwide. BOMGAR and the BOMGAR logo are trademarks of Bomgar Corporation; other trademarks shown are the property
MaaS360 On-Premises Cloud Extender
MaaS360 On-Premises Cloud Extender Installation Guide Copyright 2014 Fiberlink Communications Corporation. All rights reserved. Information in this document is subject to change without notice. The software
Defender EAP Agent Installation and Configuration Guide
Defender EAP Agent Installation and Configuration Guide Introduction A VPN is an extension of a private network that encompasses links across shared or public networks like the Internet. VPN connections
Strong Authentication for Juniper Networks
Strong Authentication for Juniper Networks SSL VPN SSO and OWA with Powerful Authentication Management for Service Providers and Enterprises Authentication Service Delivery Made EASY Copyright Copyright
Lab 05: Deploying Microsoft Office Web Apps Server
Lab 05: Deploying Microsoft Office Web Apps Server DISCLAIMER 2013 Microsoft Corporation. All rights reserved. Microsoft, Active Directory, Hyper-V, Internet Explorer, Lync, PowerPoint, Silverlight, SQL
Installing and Configuring vcloud Connector
Installing and Configuring vcloud Connector vcloud Connector 2.0.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new
Technical Certificates Overview
Technical Certificates Overview Version 8.2 Mobile Service Manager Legal Notice This document, as well as all accompanying documents for this product, is published by Good Technology Corporation ( Good
INTEGRATION GUIDE. DIGIPASS Authentication for Juniper SSL-VPN
INTEGRATION GUIDE DIGIPASS Authentication for Juniper SSL-VPN Disclaimer Disclaimer of Warranties and Limitation of Liabilities All information contained in this document is provided 'as is'; VASCO Data
AD RMS Step-by-Step Guide
AD RMS Step-by-Step Guide Microsoft Corporation Published: March 2008 Author: Brian Lich Editor: Carolyn Eller Abstract This step-by-step guide provides instructions for setting up a test environment to
Content Filtering Client Policy & Reporting Administrator s Guide
Content Filtering Client Policy & Reporting Administrator s Guide Notes, Cautions, and Warnings NOTE: A NOTE indicates important information that helps you make better use of your system. CAUTION: A CAUTION
Dell One Identity Cloud Access Manager 8.0.1- How to Configure for High Availability
Dell One Identity Cloud Access Manager 8.0.1- How to Configure for High Availability May 2015 Cloning the database Cloning the STS host Cloning the proxy host This guide describes how to extend a typical
Step-By-Step Guide to Deploying Lync Server 2010 Enterprise Edition
Step-By-Step Guide to Deploying Lync Server 2010 Enterprise Edition The installation of Lync Server 2010 is a fairly task-intensive process. In this article, I will walk you through each of the tasks,
AVG Business SSO Connecting to Active Directory
AVG Business SSO Connecting to Active Directory Contents AVG Business SSO Connecting to Active Directory... 1 Selecting an identity repository and using Active Directory... 3 Installing Business SSO cloud
Enterprise Self Service Quick start Guide
Enterprise Self Service Quick start Guide Software version 4.0.0.0 December 2013 General Information: [email protected] Online Support: [email protected] 1 2013 CionSystems Inc. ALL RIGHTS RESERVED.
VMware Horizon FLEX User Guide
Horizon FLEX 1.5 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions of this
Optimization in a Secure Windows Environment
WHITE PAPER Optimization in a Secure Windows Environment A guide to the preparation, configuration and troubleshooting of Riverbed Steelhead appliances for Signed SMB and Encrypted MAPI September 2013
Step-by-Step Guide for Creating and Testing Connection Manager Profiles in a Test Lab
Step-by-Step Guide for Creating and Testing Connection Manager Profiles in a Test Lab Microsoft Corporation Published: May, 2005 Author: Microsoft Corporation Abstract This guide describes how to create
Introduction to DirectAccess in Windows Server 2012
Introduction to DirectAccess in Windows Server 2012 Windows Server 2012 Hands-on lab In this lab, you will configure a Windows 8 workgroup client to access the corporate network using DirectAccess technology,
Digipass Plug-In for IAS. IAS Plug-In IAS. Microsoft's Internet Authentication Service. Getting Started
Digipass Plug-In for IAS IAS Plug-In IAS Microsoft's Internet Authentication Service Getting Started Disclaimer of Warranties and Limitations of Liabilities Disclaimer of Warranties and Limitations of
NetWrix Password Manager. Quick Start Guide
NetWrix Password Manager Quick Start Guide Contents Overview... 3 Setup... 3 Deploying the Core Components... 3 System Requirements... 3 Installation... 4 Windows Server 2008 Notes... 4 Upgrade Path...
4.0. Offline Folder Wizard. User Guide
4.0 Offline Folder Wizard User Guide Copyright Quest Software, Inc. 2007. All rights reserved. This guide contains proprietary information, which is protected by copyright. The software described in this
Creating and Issuing the Workstation Authentication Certificate Template on the Certification Authority
In this post we will see the steps for deploying the client certificate for windows computers. This post is a part of Deploy PKI Certificates for SCCM 2012 R2 Step by Step Guide. In the previous post we
Check Point FDE integration with Digipass Key devices
INTEGRATION GUIDE Check Point FDE integration with Digipass Key devices 1 VASCO Data Security Disclaimer Disclaimer of Warranties and Limitation of Liabilities All information contained in this document
MaaS360 Cloud Extender
MaaS360 Cloud Extender Installation Guide Copyright 2013 Fiberlink Communications Corporation. All rights reserved. Information in this document is subject to change without notice. The software described
Installing Policy Patrol on a separate machine
Policy Patrol 3.0 technical documentation July 23, 2004 Installing Policy Patrol on a separate machine If you have Microsoft Exchange Server 2000 or 2003 it is recommended to install Policy Patrol on the
VMware Identity Manager Administration
VMware Identity Manager Administration VMware Identity Manager 2.6 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new
Preface. Limitations. Disclaimers. Technical Support. Luna SA and IBM HTTP Server/IBM Web Sphere Application Server Integration Guide
Luna SA and IBM HTTP Server/IBM Web Sphere Application Server Integration Guide Preface Preface 2012 SafeNet, Inc. All rights reserved. Part Number: 007-012077-001 (Rev B, 06/2012) All intellectual property
Authentication in XenMobile 8.6 with a Focus on Client Certificate Authentication
Authentication in XenMobile 8.6 with a Focus on Client Certificate Authentication Authentication is about security and user experience and balancing the two goals. This document describes the authentication
