NetIQ Access Manager - Advanced Authentication Plugin. User's Guide. Version 5.1.0



Similar documents
NetIQ Advanced Authentication Framework

NetIQ Advanced Authentication Framework - Network Policy Server (NPS) Plugin. Administrator's Guide. Version 5.1.0

NetIQ Advanced Authentication Framework - Smartphone Applications

NetIQ Advanced Authentication Framework - Citrix XenDesktop Plugin. Installation Guide. Version 5.1.0

NetIQ Advanced Authentication Framework - Password Filter. Installation Guide. Version 5.1.0

NetIQ Advanced Authentication Framework - Administrative Tools. Installation Guide. Version 5.1.0

NetIQ Advanced Authentication Framework. FIDO U2F Authentication Provider Installation Guide. Version 5.1.0

NetIQ Advanced Authentication Framework - Client. User's Guide. Version 5.1.0

Yale Software Library

How To Integrate Watchguard Xtm With Secur Access With Watchguard And Safepower 2Factor Authentication On A Watchguard 2T (V2) On A 2Tv 2Tm (V1.2) With A 2F

External Authentication with Juniper SSL VPN appliance Authenticating Users Using SecurAccess Server by SecurEnvoy

Shakambaree Technologies Pvt. Ltd.

NetIQ Advanced Authentication Framework - MacOS Client

External Authentication with Citrix Access Gateway Advanced Edition

Configuring Microsoft RADIUS Server and Gx000 Authentication. Configuration Notes. Revision 1.0 February 6, 2003

External authentication with Astaro AG Astaro Security Gateway UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

External authentication with Fortinet Fortigate UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

ipad or iphone with Junos Pulse and Juniper SSL VPN appliance Authenticating Users Using SecurAccess Server by SecurEnvoy

Accessing Derbyshire County Council s Outlook Web Access (OWA) Service. Mobile Phone SMS version

PROCEDURE FOR DSC CONFIGURATION. A. Installation of the driver has to be done for the first time and only once.

These additional levels of security are NOT required if you are using a Derbyshire County Council machine on council premises.

External Authentication with Windows 2003 Server with Routing and Remote Access service Authenticating Users Using SecurAccess Server by SecurEnvoy

2-FACTOR AUTHENTICATION WITH OPENLDAP, OATH-HOTP AND YUBIKEY. Axel Hoffmann

How To Set Up Ops Cser.Com (Pros) For A Pc Or Mac) With A Microsoft Powerbook (Proos) (Prosecco) (Powerbook) (Pros) And Powerbook.Com/

HOTPin Integration Guide: DirectAccess

Apache Server Implementation Guide

External Authentication with Cisco ASA Authenticating Users Using SecurAccess Server by SecurEnvoy

Defender Token Deployment System Quick Start Guide

Get Smart Card Ready. How to Recover Your Old (Expired) Certificates

Using RD Gateway with Azure Multifactor Authentication

User Guide Remote PIV to VDI Using a PIV Card

db-direct internet EU

ZyWALL SSL 10. User s Guide. Integrated SSL-VPN Appliance. Version /2008 Edition 1

Application Note. Intelligent Application Gateway with SA server using AD password and OTP

User Guide Remote Access to VDI/Workplace Using PIV

Implementation Guide for. Juniper SSL VPN SSO with OWA. with. BlackShield ID

USER GUIDE WWPass Security for Windows Logon

CYCLOPE let s talk productivity

Change Advanced Proxy Server Configuration Settings


REMOTE ACCESS - OUTLOOK WEB APP

Implementation Guide for protecting

Accessing Derbyshire County Council s Outlook Web Access (OWA) Service. Smart Phone App version

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

Use the below instructions to configure your wireless settings to connect to the secure wireless network using Microsoft Windows Vista/7.

Download and Launch Instructions for WLC Client App Program

SafeNet Authentication Client

BlackShield ID Agent for Terminal Services Web and Remote Desktop Web

Employee Express - PIV Card Registration Instructions

REMOTE ACCESS USER GUIDE

PUBLIC Secure Login for SAP Single Sign-On Implementation Guide

Quick Start Guide to Logging in to Online Banking

PrivateServer HSM EKM Provider for Microsoft SQL Server

These instructions will allow you to configure your computer to install necessary software to access mystanwell.com.

Dell SonicWALL and SecurEnvoy Integration Guide. Authenticating Users Using SecurAccess Server by SecurEnvoy

Outlook Web Access 2003 Remote User Guide

YubiKey PIV Deployment Guide

SalesForce SSO with Active Directory Federated Services (ADFS) v2.0 Authenticating Users Using SecurAccess Server by SecurEnvoy

CRYPTOLogon Agent. for Windows Domain Logon Authentication. Deployment Guide. Copyright , CRYPTOCard Corporation, All Rights Reserved.

MRU Secure Remote Access Service (SRAS) External User Guide

External Authentication with Citrix Secure Gateway - Presentation server Authenticating Users Using SecurAccess Server by SecurEnvoy

etoken PKI Client (Windows) Administrator s Guide Version 5.1 SP1 Rev A

Configuring Your Client: Eudora 5.x. Quick Reference

The same as the Bold convention (see above) but with the intent of providing a greater emphasis.

SafeNet Authentication Client (Windows)

SonicWALL SSL VPN 5.0 User s Guide

Entrust Managed Services PKI Administrator Guide

External Authentication with Cisco VPN 3000 Concentrator Authenticating Users Using SecurAccess Server by SecurEnvoy

Step by Step Guide to implement SMS authentication to F5 Big-IP APM (Access Policy Manager)

Smart Policy - Web Collector. Version 1.1

Two Factor Authentication and PKI Token (for Windows)

CA /BrightStor ARCserve9 Backup Software

Manual for configuring NIC VPN in Windows OS

Internet Banking User Guide

Managed Services PKI 60-day Trial Quick Start Guide

One-Time Password Contingency Access Process

DIGIPASS CertiID. Getting Started 3.1.0

CONNECTING TO THE DTS WIRELESS NETWORK USING WINDOWS VISTA

Installing Oracle 12c Enterprise on Windows 7 64-Bit

USB HSPA Modem. User Manual

External Authentication with Windows 2012 R2 Server with Remote Desktop Web Gateway Authenticating Users Using SecurAccess Server by SecurEnvoy

BlackShield ID Agent for Remote Web Workplace

A. I do not have my own personal certificate I am a new client or want to download a new certificate

1. Accessing the LONZA network from a private PC or Internet Café

Configuring Your Client: Eudora 5.x

Multi-Factor Authentication (MFA)

IDENTIKEY Server Windows Installation Guide 3.1

Two Factor Authentication in SonicOS

USER GUIDE WWPass Security for (Outlook) For WWPass Security Pack 2.4

ID Pictures collection for Membership card of ARBH- KBHB/LFH/VHL

GoldKey Software. User s Manual. Revision WideBand Corporation Copyright WideBand Corporation. All Rights Reserved.

SRA 6.0 User s Guide 1

Department of Veterans Affairs Two-Factor Authentication MobilePASS Quick Start Guide November 18, 2015

WORK INSTRUCTION 3 ONLINE REGISTRATION,DATA ENTRY AND WEB REPORTS

Agent Configuration Guide

ThinPoint Quick Start Guide

Ubuntu To install the required card reader software:

isupplier PORTAL ACCESS SYSTEM REQUIREMENTS


Transcription:

NetIQ Access Manager - Advanced Authentication Plugin User's Guide Version 5.1.0

Table of Contents 1 Table of Contents 2 Introduction 3 About This Document 3 Environment 4 Flash Drive Authentication Support Configuration for Linux 5 Authentication Using NetIQ Access Manager Advanced Authentication Plugin 7 NetIQ Email Authentication Method 7 NetIQ Flash Drive Authentication Method 7 NetIQ OATH OTP Authentication Method 8 NetIQ RADIUS Authentication Method 8 NetIQ Security Questions Authentication Method 8 NetIQ Smartcard Authentication Method 8 NetIQ Smartphone Authentication Method 9 NetIQ SMS Authentication Method 9 NetIQ Voice Call Authentication Method 9 Index 11 2

Introduction About This Document Purpose of the Document This NetIQ Access Manager Advanced Authentication Plugin Installation Guide is intended for all user categories and describes how to use NetIQ Access Manager Advanced Authentication Plugin. Document Conventions This document uses the following conventions: Warning. This sign indicates requirements or restrictions that should be observed to prevent undesirable effects. Important notes. This sign indicates important information you need to know to use the product successfully. Notes. This sign indicates supplementary information you may need in some cases. Tips. This sign indicates recommendations. Terms are italicized, e.g.: Authenticator. Names of GUI elements such as dialogs, menu items, and buttons are put in bold type, e.g.: the Logon window. 3

Environment Components that are required: NetIQ Access Manager 3.2 SP1/3.2 SP2/4.0 RC server/appliance; NetIQ Web Service 4.8 and higher; Java Runtime Environment should be installed on the Client side. It is not recommended to install Java Runtime Environment 7.0 Update 45 due to the problem (https://forums.oracle.com/thread/2594401). 4

Flash Drive Authentication Support Configuration for Linux To enable flash drive authentication method for Linux, two requirements must be accomplished: Make sure that the libblkid library is installed (it is installed on most Linux versions by default). Check it with the blkid command that makes a call to the library mentioned above. On Fedora it is possible to install it using yum. To do it, write down in the terminal window [root permissions required]: yum install libblkid Add udev rules, so that a user could gain access to flash drives. Otherwise only root can gain access to them. a. Create a new user group that will have permissions to access flash drives: groupadd [your_group] b. Add a user to the group from the previous stage: useradd G [your_group] [your_user] To change a user group: usermod G [your_group1],[your_group2] [your_user] c. Create a new udev file in /etc/udev/rules.d, udev rule files applies in alphabetical order that numbers in names are for [10-my-usb.rules]. E.g., the file containing number 10 in the name applies earlier than the file with the number 50 in its name. d. Run udevadm info /dev/sdb1 to get attributes of the required flash drive. E.g., it contains the attribute DEVTYPE=partition. e. Write your udev rule to the previously created file! ENV{DEVTYPE}=="partition", MODE="0666", GROUP=[your_group] E.g.: 5

ENV{DEVTYPE}=="partition", MODE="0666", GROUP="users" This will grant permission to the users from the group users to access USB devices of the type partition. If you use the Konqueror browser, then in it necessary to enable Java Runtime Environment. If you use the Firefox browser, then Java Runtime Environment will be enabled by default and Sun Java Plugin will be used automatically. Flash drive is set automatically in opensuse Linux when it is opened through Dolpfin for the first time. It is also possible to set automount or to set flash drive manually. 6

Authentication Using NetIQ Access Manager Advanced Authentication Plugin NetIQ Access Manager Advanced Authentication Plugin supports the following methods of authentication: NetIQ Email Authentication Method NetIQ Flash Drive Authentication Method NetIQ OATH OTP Authentication Method NetIQ RADIUS Authentication Method NetIQ Security Questions Authentication Method NetIQ Smartcard Authentication Method NetIQ Smartphone Authentication Method NetIQ SMS Authentication Method NetIQ Voice Call Authentication Method NetIQ Email Authentication Method To authenticate using NetIQ SMS authentication method: 2. Select Email authentication method. 4. Enter your domain password. Click Login. A new email will be sent to your email address. 5. Enter One-Time Password from the new email that was sent to your email address. Click Login. 6. Your session will be authenticated. NetIQ Flash Drive Authentication Method To authenticate using NetIQ Flash Drive authentication method: 2. Select Flash Drive authentication method. 3. Insert a flash drive. 4. When the flash drive is inserted, enter your PIN. Click Login. 7

NetIQ OATH OTP Authentication Method To authenticate using NetIQ OATH OTP authentication method: 2. Select OATH OTP authentication method. 4. Enter One-Time Password that is automatically generated by smartphone or hardware token. Click Login. NetIQ RADIUS Authentication Method To authenticate using NetIQ RADIUS authentication method: 2. Select RADIUS authentication method. 4. Enter your domain password. Click Login. NetIQ Security Questions Authentication Method To authenticate using NetIQ Security Questions authentication method: 2. Select Security Questions authentication method. 4. Enter your answers to the list of security questions. Click Login. NetIQ Smartcard Authentication Method To authenticate using NetIQ Smartcard authentication method: 2. Select Smartcard authentication method. 3. Present a smart card on the reader. 8

4. When the smart card is detected, enter your PIN. Click Login. NetIQ Smartphone Authentication Method To authenticate using NetIQ Smartphone authentication method: 2. Select Smartphone authentication method. 4. Select one of the following ways: Enter One- Time Password (automatically generated by NetIQ Smartphone Authenticator) and your domain password. Click Login. Enter your domain password. Click Login. The confirmation window will be displayed on a mobile device with installed NetIQ Smartphone Authenticator. Tap Accept to authenticate with the selected method. NetIQ SMS Authentication Method To authenticate using NetIQ SMS authentication method: 2. Select SMS authentication method. 4. Enter your domain password. Click Login. A new SMS message will be sent to your phone. 5. Enter One-Time Password from the new SMS message that was sent to your phone. Click Login. 6. Your session will be authenticated. NetIQ Voice Call Authentication Method To authenticate using NetIQ Voice Call authentication method: 2. Select Voice Call authentication method. 9

4. Enter your domain password. Click Login. 5. You will get a call on your phone. Input the specified PIN to accept authentication. 6. Your session will be authenticated. 10

Index A Authentication 1, 3, 5, 7-9 Authenticator 3, 9 C Client 4 Create 5 L Logon 3 O OATH 7-8 OTP 8 P Password 7-9 PIN 7, 9-10 R RADIUS 7-8 S Security 7-8 U User 1 11