Example: stock market

RSA Authentication Manager 7.1 Administrator’s Guide ...

RSA Authentication Manager s Guide 2007-2008 RSA Security Inc. All rights printing: April 2008 Contact InformationGo to the RSA corporate web site for regional Customer Support telephone and fax numbers: a d e m a r k sRSA and the RSA logo are registered trademarks of RSA Security Inc. in the United States and/or other countries. For the most up-to-date listing of RSA trademarks, go to EMC is a registered trademark of EMC Corporation. All other goods and/or services mentioned are trademarks of their respective agreementThis software and the associated documentation are proprietary and confidential to RSA, are furnished under license, and may be used and copied only in accordance with the terms of such license and with the inclusion of the copyright notice below.

RSA Authentication Manager 7.1 Administrator’s Guide. 66 3: Protecting Network Resources with RSA SecurID. Installing Authentication Agent Software on the Resource You Want to Protect. There are different types of authentication agents. The agent that you need depends on

Tags:

  Manager, Authentication, Administrator, Rsa authentication manager

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of RSA Authentication Manager 7.1 Administrator’s Guide ...

1 RSA Authentication Manager s Guide 2007-2008 RSA Security Inc. All rights printing: April 2008 Contact InformationGo to the RSA corporate web site for regional Customer Support telephone and fax numbers: a d e m a r k sRSA and the RSA logo are registered trademarks of RSA Security Inc. in the United States and/or other countries. For the most up-to-date listing of RSA trademarks, go to EMC is a registered trademark of EMC Corporation. All other goods and/or services mentioned are trademarks of their respective agreementThis software and the associated documentation are proprietary and confidential to RSA, are furnished under license, and may be used and copied only in accordance with the terms of such license and with the inclusion of the copyright notice below.

2 This software and the documentation, and any copies thereof, may not be provided or otherwise made available to any other title to or ownership of the software or documentation or any intellectual property rights thereto is hereby transferred. Any unauthorized use or reproduction of this software and the documentation may be subject to civil and/or criminal software is subject to change without notice and should not be construed as a commitment by licensesThis product may include software developed by parties other than RSA. The text of the license agreements applicable to third-party software in this product may be viewed in the on encryption technologiesThis product may contain encryption technology. Many countries prohibit or restrict the use, import, or export of encryption technologies, and current use, import, and export regulations should be followed when using, importing or exporting this distribution of this document to trusted noticeThe RC5 Block Encryption Algorithm With Data-Dependent Rotations is protected by Patent #5,724,428 and #5,835, Authentication Manager administrator s Guide4 ContentsSetting Token Usage Requirements.

3 51 Limiting the Number of Incorrect Passcodes 52 Setting Tokencode Ranges for Event-Based 53 Requiring Periodic RSA SecurID PIN 53 Restricting Reuse of Old 54 Limiting RSA SecurID PIN 54 Setting RSA SecurID PIN Character 55 Requiring Periodic Fixed Passcode 55 Restricting Reuse of Old Fixed Passcodes .. 56 Limiting Fixed Passcode Length .. 56 Setting Fixed Passcode Character 57 Setting Emergency Access Code Formats .. 57 Locking Users Out of the System .. 57 Locking Out Users After a Specified Number of Logon Attempts .. 58 Setting Offline Authentication 59 Integrating Your Windows Password with RSA SecurID .. 61 Setting Minimum Online Passcode 61 Handling Offline Authentication with Devices that Do Not Meet Security Recommendations.

4 62 Setting Offline Emergency Codes .. 62 Refreshing Users Supplies of Offline Authentication Data .. 63 Setting Self-Service Troubleshooting Requirements .. 63 Chapter 3: Protecting Network Resources with RSA 65 Overview of RSA SecurID 65 Installing Authentication Agent Software on the Resource You Want to Protect .. 66 Creating an RSA Agent Record Using the RSA Security Console .. 66 Allowing Agents to Automatically Add Authentication Agent Records .. 68 Creating and Installing the RSA Authentication Manager Configuration 71 Specifying Where Agents Send Authentication Requests .. 72 Using Authentication Agents to Restrict User 73 Granting Access to Restricted Agents Using User Groups .. 74 Setting Restricted Access Times for User 75 Deploying Tokens to 75 Importing Hardware and Software Token Records.

5 78 Transferring Hardware and Software Token Records to Other Security Domains .. 79 Assigning and Unassigning Hardware and Software 79 Distributing Hardware Tokens to Users .. 80 Distributing Software Tokens to 81 RSA Authentication Manager administrator s GuideContents5 Delivering Tokencodes Using Text Message or E-mail .. 85 Configuring RSA Authentication Manager for On-Demand Authentication .. 87 Changing the SMS Service Provider .. 89 Enabling Users for On-Demand 89 Setting PINs for On-Demand Tokencodes .. 90 Preventing and Handling User Authentication Problems .. 91 Educating Users About Security Responsibilities .. 91 Chapter 4: Administering 93 Enabling and Disabling Users .. 93 Assisting Users Who Have Been Locked Out of the System.

6 94 Assisting Users Whose Tokens Are Lost, Stolen, Damaged, or Expired .. 95 Providing Users with Temporary Emergency Access .. 96 Providing Temporary Emergency Access for Online Authentication .. 97 Providing Temporary Emergency Access for Offline Authentication .. 99 Replacing 101 Enabling and Disabling Tokens .. 102 Resynchronizing 103 Clearing PINs ..104 Requiring Users to Change Their 105 Providing Users with Fixed Passcodes .. 106 Clearing Incorrect Passcodes .. 106 Designating a Default Shell for UNIX 106 Assigning Logon Aliases .. 107 Updating Phone Numbers and E-mail Addresses for On-Demand Tokencodes .. 107 Granting Access with User 107 Chapter 5: Administering RSA Authentication 109 Modifying administrator 109 Displaying All of the Administrative Roles with View or None Permission for a Specific the Store Utility to Display Administrative Roles with a View or None Permission for a Specific Communications Between the Authentication Agent and RSA Authentication Manager .

7 112 Refreshing the Node Secret Using the Node Secret Load Limits on Administrative Sessions ..114 Limiting the Number of Concurrent Administrative Sessions ..115 Limiting the Length of Administrative Sessions ..116 Limiting Periods of Inactivity Allowed for Administrative and Closing Administrative Sessions ..117 Configuring the System Cache for Improved Identity Source Attributes ..119 RSA Authentication Manager administrator s GuideContents7 Chapter 8: Managing RSA 159 Overview of RSA RADIUS .. 159 RSA RADIUS Supports Secure Network Access .. 160 How You Manage RSA RADIUS .. 160 How RSA RADIUS Helps Enforce Access Control .. 161 Other Attribute Types Provide Flexibility .. 165 How RSA RADIUS Maintains Secure Communications.

8 166 Managing User 167 Managing 167 Managing Profile 168 Managing RADIUS User 169 Managing RADIUS Clients .. 169 Managing RSA RADIUS 170 Starting and Stopping RSA RADIUS Servers .. 170 Adding a New RSA RADIUS Server .. 170 List or Delete Existing RSA RADIUS Server 170 View or Edit Existing RSA RADIUS Server Properties .. 171 Managing 171 Manage EAP-POTP Configuration .. 172 Monitoring System 173 Viewing RSA RADIUS Usage 173 View RADIUS Server Accounting Statistics .. 174 View RADIUS Server's Client Authentication and Accounting 176 Choosing Accounting Attributes and administrator Actions to Record .. 177 Displaying the Authentication Log Files .. 178 Configuring the Log Retention 182 Using the Server Log File .. 182 Using the Accounting Log 183 Maintaining RSA RADIUS Servers.

9 188 Removing an RSA RADIUS Server from Service .. 188 Backing Up a RADIUS Server .. 189 Restoring a RADIUS Server .. 189 Promoting an RSA RADIUS Replica Server .. 191 Modify RSA RADIUS Server Configuration and Dictionary Files .. 192 Change the IP Address or Name of an RSA RADIUS 193 Chapter 9: Logging and 195 Configuring RSA Authentication Manager 195 Archiving Log Files .. 197 Generating Reports .. 198 Creating Custom 198 Running Reports .. 200 Scheduling Recurring Reports .. 201 Setting Report 202 Viewing Reports .. 203 RSA Authentication Manager administrator s GuideContents11 Appendix F: RSA Authentication Manager Message 361 Audit Log 361 System Log Messages .. 363 RSA Authentication Manager Administrative Audit Log 373 RSA Authentication Manager Runtime Audit Log Messages.

10 380 RSA Authentication Manager System Log Messages .. 382 Appendix G: 391 Common Problems and Resolutions .. 391 General Troubleshooting Tips .. 400 Using the Activity Monitor and Log Messages for Troubleshooting .. 400 Making Sure the RSA Authentication Manager Machine Meets Minimum System 407 Supported Browsers ..411 Configuring Browser Settings for the RSA Security Console, RSA Operations Console, and RSA Self-Service Console ..411 Assessing the Impact of Firewalls on RSA Authentication Manager .. 412 Configuring the Cache for Improved Performance .. 415 Test User Access to Restricted 415 User and Token-Related 416 Unlocking a User .. 416 Assisting Users with Lost, Stolen, Damaged or Expired Tokens .. 416 Providing Emergency Access.


Related search queries