Configuration Guide. SafeNet Authentication Service. Token Validator Proxy Agent



Similar documents
SAS Token Validator Proxy Agent Configuration Guide

Configuration Guide. SafeNet Authentication Service. Remote Logging Agent

Configuration Guide. SafeNet Authentication Service AD FS Agent

Integration Guide. SafeNet Authentication Service. VMWare View 5.1

Installation Guide. SafeNet Authentication Service

Integration Guide. SafeNet Authentication Service. Using SAS with Web Application Proxy. Technical Manual Template

SafeNet Authentication Service Token Validator Proxy Agent. Configuration Guide

Integration Guide. SafeNet Authentication Client. Using SAC with Putty-CAC

Configuration Guide. SafeNet Authentication Service. SAS Agent for Microsoft Outlook Web Access 1.06

Integration Guide. SafeNet Authentication Service. Using SAS as an Identity Provider for Tableau Server

Synchronization Agent Configuration Guide

Integration Guide. SafeNet Authentication Service. Using SAS as an Identity Provider for Salesforce

Integration Guide. SafeNet Authentication Service. SAS Using RADIUS Protocol with Apache HTTP Server

Agent Configuration Guide

Integration Guide. SafeNet Authentication Service. SAS Using RADIUS Protocol with Microsoft DirectAccess

Configuration Guide. SafeNet Authentication Service. SAS Agent for Microsoft Outlook Web App. Technical Manual Template

Configuration Guide. SafeNet Authentication Service. SAS Agent for Microsoft Internet Information Services (IIS)

Integration Guide. SafeNet Authentication Client. Using SAC CBA for Check Point Security Gateway

SafeNet Authentication Manager Express. Upgrade Instructions All versions

Integration Guide. SafeNet Authentication Service. Using SAS as an Identity Provider for Drupal

Microsoft IAS and NPS Agent Configuration Guide

Gemalto SafeNet Minidriver 9.0

Remote Logging Agent Configuration Guide

Integration Guide. SafeNet Authentication Service. Oracle Secure Desktop Using SAS RADIUS OTP Authentication

Integration Guide. SafeNet Authentication Service. Integrating Active Directory Lightweight Services

SafeNet Cisco AnyConnect Client. Configuration Guide

Integration Guide. SafeNet Authentication Service. Using RADIUS Protocol for Radiator RADIUS Server

Microsoft IIS Integration Guide

User Guide. SafeNet MobilePASS for Windows Phone

SafeNet MobilePASS Version 8.2.0, Revision B

SAS Agent for Outlook Web Access

SafeNet MSSQL EKM Provider User Guide

Active Directory Rights Management Service Integration Guide

Preface. Microsoft Office Sharepoint Server 2007 Integration Guide SafeNet, Inc. All rights reserved. Part Number: (Rev A, 06/2009)

Migration Guide. SafeNet Authentication Service. SafeWord/SAMx. Migration Guide: SafeNet Authentication Service. SafeWord/SAMx

Microsoft SQL Server Integration Guide

SafeNet KMIP and Amazon S3 Integration Guide

Juniper SSL VPN Authentication QUICKStart Guide

Integration Guide. SafeNet Authentication Service. Using RADIUS and LDAP Protocols for Cisco Secure ACS

Cisco ASA Authentication QUICKStart Guide

Sentinel Cloud V.3.5 Installation Guide

Preface. Limitations. Disclaimers. Technical Support. Luna SA and IBM HTTP Server/IBM Web Sphere Application Server Integration Guide

For Active Directory Installation Guide

Interact for Microsoft Office

SafeNet Authentication Service

LDAP Synchronization Agent Configuration Guide

SafeNet Authentication Service

Configuration Guide. SafeNet Authentication Service. SAS Agent for PEAP

Agent Configuration Guide for Microsoft Windows Logon

SAS Agent for Outlook Web App

Dell Statistica Statistica Enterprise Installation Instructions

Apache HTTP Server Integration Guide

Symantec Backup Exec TM 11d for Windows Servers. Quick Installation Guide

Migrating Cirrus. Revised 7/19/2007

Strong Authentication for Juniper Networks SSL VPN

Upgrade: SAP Mobile Platform Server for Windows SAP Mobile Platform 3.0 SP02

Setting Up a Unisphere Management Station for the VNX Series P/N Revision A01 January 5, 2010

Server Installation Guide ZENworks Patch Management 6.4 SP2

LDAP Synchronization Agent Configuration Guide for

Configuration Guide. SafeNet Authentication Service. SAS Agent for AD FS

formerly Help Desk Authority Upgrade Guide

KeyAdvantage System DMS Integration. Software User Manual

VERITAS Backup Exec 9.1 for Windows Servers Quick Installation Guide

Setup and Configuration Guide for Pathways Mobile Estimating

SafeNet Authentication Service Agent for Windows Logon. Configuration Guide

Integration Guide. SafeNet Authentication Service. Using RADIUS Protocol for Cisco ASA

Server Installation ZENworks Mobile Management 2.7.x August 2013

Technical Brief for Windows Home Server Remote Access

Troubleshooting File and Printer Sharing in Microsoft Windows XP

COM Port Stress Test

Installation Guide. Novell Storage Manager for Active Directory. Novell Storage Manager for Active Directory Installation Guide

Strong Authentication for Juniper Networks

Patching the Windows 2000 Server Operating System on S8100 Media Servers, IP600 Communications Servers, & DEFNITY ONE Communications Systems

Report Designer and Report Designer Add-In Installation Guide Version 1.0

Install Guide for Time Matters and Billing Matters 11.0

Configuring File Servers and Active Directory with Domain Services for Windows-Lab

Feith Rules Engine Version 8.1 Install Guide

Digipass Plug-In for IAS. IAS Plug-In IAS. Microsoft's Internet Authentication Service. Getting Started

uh6 efolder BDR Guide for Veeam Page 1 of 36

DESLock+ Basic Setup Guide Version 1.20, rev: June 9th 2014

DeviceAnywhere Automation for Smartphones Setup Guide Windows Mobile

Archive Attender Version 3.5

SafeNet Authentication Service

HELP DOCUMENTATION E-SSOM DEPLOYMENT GUIDE

ACTi NVR Config Converter User s Manual. Version /06/07

MobileStatus Server Installation and Configuration Guide

Omniquad Exchange Archiving

Introduction 1-1 Installing FAS 500 Asset Accounting the First Time 2-1 Installing FAS 500 Asset Accounting: Upgrading from a Prior Version 3-1

FAS Asset Accounting FAS CIP Accounting FAS Asset Inventory SQL Server Installation & Administration Guide Version

Lepide Event Log Manager: Installation Guide. Installation Guide. Lepide Event Log Manager. Lepide Software Private Limited

Set Up Your . HTC Touch Pro.

Magaya Software Installation Guide

Sage Fixed Assets. for Depreciation, Tracking, Planning, and Reporting. Network Installation Administrator Guide

Diamond II v2.3 Service Pack 4 Installation Manual

WhatsUp Gold v16.2 Installation and Configuration Guide

Sage 300 ERP Sage CRM 7.2 Integration Guide

Step-by-Step Guide for Microsoft Advanced Group Policy Management 4.0

Administration guide. Océ LF Systems. Connectivity information for Scan-to-File

DIGIPASS Authentication for Windows Logon Getting Started Guide 1.1

Transcription:

SafeNet Authentication Service Configuration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1

Document Information Document Part Number 007-012423-001, Rev A Release Date September 2014 Trademarks All intellectual property is protected by copyright. All trademarks and product names used or referred to are the copyright of their respective owners. No part of this document may be reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, chemical, photocopy, recording, or otherwise, without the prior written permission of SafeNet, Inc. Disclaimer SafeNet makes no representations or warranties with respect to the contents of this document and specifically disclaims any implied warranties of merchantability or fitness for any particular purpose. Furthermore, SafeNet reserves the right to revise this publication and to make changes from time to time in the content hereof without the obligation upon SafeNet to notify any person or organization of any such revisions or changes. We have attempted to make these documents complete, accurate, and useful, but we cannot guarantee them to be perfect. When we discover errors or omissions, or they are brought to our attention, we endeavor to correct them in succeeding releases of the product. SafeNet invites constructive comments on the contents of this document. These comments, together with your personal and/or company details, should be sent to the address or email below. Contact Method Mail Email Contact Information SafeNet, Inc. 4690 Millennium Drive Belcamp, Maryland 21017, USA TechPubs@safenet-inc.com 2

Contents Contents Applicability... 4 Environment... 4 Overview... 4 Architecture... 5 Configuring the SafeNet Authentication Service Manager... 5 Installing the Agent... 6 Configuring Token Validator Proxy... 9 Loading and Registering the Key File... 9 Changing Settings after Installation... 10 Main SAS Server... 10 Backup SAS Server... 10 Token Validator Proxy Logs... 10 Support Contacts... 11 3

Applicability The information in this document applies to: SafeNet Authentication Service (SAS) - A cloud authentication service of SafeNet Inc. SafeNet Authentication Service Service Provider Edition (SAS-SPE) - The software used to build a SafeNet authentication service. SafeNet Authentication Service Private Cloud Edition (SAS-PCE) - A term used to describe the implementation of SAS-SPE/PCE. Note: References to BlackShield and CRYPTOCard reflect CRYPTOCard branding prior to acquisition by SafeNet. Over time these references will change to reflect SafeNet branding including program installation locations. Environment Supported Platforms Windows 2008 SP2 and Windows 2008 R2 Windows 8 Windows 7 Window Vista Windows XP Supported Architecture 32-bit 64-bit Additional Software Components IIS 6 IIS 7 IIS 8 Overview The function of the Token Validator Proxy (TVP) Agent is to implement proxy authentication requests from other agents to SAS. It has two main uses: When working with Network Logon, without TVP you would be required to register each workstation's IP address to SAS and have each workstation communicate directly with SAS. With TVP, each Network Logon agent can be pointed at TVP and only the IP address of their TVP need be registered with SAS. When using SafeNet Authentication Service API with a cloud application such as MS Azure, you cannot be sure of the IP address of the cloud server, nor are you entitled to claim this IP address as your own. To solve this problem, you can point your cloud application at the TVP and register your TVP as their Auth Node. 4

Architecture If each client was to be connected directly to SafeNet Authentication Service, each would require its own IP address to be configured. By using the SafeNet Authentication Service TVP, it needs to be configured just once with the IP address of the SAS Auth Node. Multiple clients can then be connected to SAS through the TVP without further IP addresses being configured. Client 1 SAS (AuthNode) Token Validator Proxy Client 2 Client...n Configuring the SafeNet Authentication Service Manager The SafeNet Authentication Service Manager must be configured as follows: 1. In the SafeNet Authentication Service Manager, select Virtual Servers > COMMS > Auth Nodes. 2. Click Add. 3. Add the IP of the TVP computer. 4. Click Apply. 5

Installing the Agent 1. On the TVP computer, run one of the following installation files: SafeNet TokenValidator Proxy x64.exe (64-bit) SafeNet TokenValidator Proxy.exe (32-bit) The Welcome to the InstallShield Wizard for SafeNet Authentication Service TokenValidator Proxy window opens. Click Next to continue. 2. On the License Agreement window, select I accept the terms in the license agreement and click Next. 6

3. On the Customer Information window, do the following: a. Enter the User Name and Organization. b. Select one of the following options to determine who can use the application: Anyone who uses this computer (all users) Only for me c. Click Next. 4. On the Destination Folder window, the installation folder is displayed. To change the location, click Change and then browse to the required location. Once a location is selected, click Next. 7

5. On the Authentication Service Setup window, enter the IP address of the SAS server. Click Next. 6. On the Ready to Install the Program window, click Install to begin installation. 8

7. When the process has been completed, the InstallShield Wizard Completed window opens. 8. Click Finish to exit the installation wizard. Following installation, the SAS Proxy Source Server service is installed on Windows. Configuring Token Validator Proxy Loading and Registering the Key File The Token Validator Proxy (TVP) uses an encrypted key file to communicate with the agents and the authentication server. This ensures all authentication attempts made against the TVP and the server are from valid recognized agents. Loading the Key File The key file must be saved on the client computer and the TVP computer 1. In SAS, select the System tab and download a key file from the Agent Settings section. 2. Using Windows Explorer, change your current working directory to the KeyFile directory by entering [INSTALLDIR]\KeyFile\ in the address bar, where [INSTALLDIR] represents the installation directory of the TVP. 3. Copy and paste the key file to the KeyFile directory. 9

Registering the Key File You must register the loaded files. To do so, perform the following steps: 1. In Windows, select Start > Run. 2. Enter regedit and then click OK. 3. Expand HKEY_LOCAL_MACHINE > SOFTWARE > CRYPTOCARD > BlackShield ID > TokenValidatorProxy. 4. Double-click EncryptionKeyFile. 5. In the text box, enter the fully qualified path to the loaded key file that was loaded above. For more details, see the Token Validator Proxy Configuration Notes. To view the Token Validator Proxy Configuration Notes, from the Windows Desktop, select Start > More Programs > SafeNet >SafeNet Authentication Service > Token Validator Proxy Configuration Notes. Changing Settings after Installation Once installed, the paths to the main SAS server and the backup SAS server can be changed, if required. Main SAS Server Enter the path to the main SAS server in the following Registry key: HKEY_LOCAL_MACHINE \SOFTWARE\CRYPTOCard\BlackShield ID\TokenValidatorProxy\PrimaryServiceURL Backup SAS Server Enter the path to the backup SAS server in the following Registry key: HKEY_LOCAL_MACHINE \SOFTWARE\CRYPTOCard\BlackShield ID\TokenValidatorProxy\OptionalSecondaryServiceURL Token Validator Proxy Logs TVP logs can be viewed in the Windows Event Viewer. 10

Support Contacts If you encounter a problem while installing, registering, or operating this product, please make sure that you have read the documentation. If you cannot resolve the issue, contact your supplier or SafeNet Customer Support. SafeNet Customer Support operates 24 hours a day, 7 days a week. Your level of access to this service is governed by the support plan arrangements made between SafeNet and your organization. Please consult this support plan for further information about your entitlements, including the hours when phone support is available to you. Table 1: Support Contacts Contact Method Address Contact Information SafeNet, Inc. 4690 Millennium Drive Belcamp, Maryland 21017 USA Phone United States 1-800-545-6608 International 1-410-931-7520 Technical Support Customer Portal https://serviceportal.safenet-inc.com Existing customers with a Technical Support Customer Portal account can log in to manage incidents, get the latest software upgrades, and access the SafeNet Knowledge Base. 11