Transcription of RSA Authentication Manager 8.1 Administrator’s Guide
1 RSA Authentication Manager administrator s GuideCopyright 1994-2013 EMC Corporation. All Rights Reserved. Published in the 2013 Contact InformationGo to the RSA corporate website for regional Customer Support telephone and fax numbers: , the RSA Logo and EMC are either registered trademarks or trademarks of EMC Corporation in the United States and/or other countries. All other trademarks used herein are the property of their respective owners. For a list of RSA trademarks, go to #rsa. License AgreementThis software and the associated documentation are proprietary and confidential to EMC, are furnished under license, and may be used and copied only in accordance with the terms of such license and with the inclusion of the copyright notice below.
2 This software and the documentation, and any copies thereof, may not be provided or otherwise made available to any other title to or ownership of the software or documentation or any intellectual property rights thereto is hereby transferred. Any unauthorized use or reproduction of this software and the documentation may be subject to civil and/or criminal software is subject to change without notice and should not be construed as a commitment by LicensesThis product may include software developed by parties other than RSA. The text of the license agreements applicable to third-party software in this product may be viewed on the product documentation page on RSA SecurCare Online.
3 By using this product, a user of this product agrees to be fully bound by terms of the license on Encryption TechnologiesThis product may contain encryption technology. Many countries prohibit or restrict the use, import, or export of encryption technologies, and current use, import, and export regulations should be followed when using, importing or exporting this , copying, and distribution of any EMC software described in this publication requires an applicable software believes the information in this publication is accurate as of its publication date.
4 The information is subject to change without INFORMATION IN THIS PUBLICATION IS PROVIDED "AS IS." EMC CORPORATION MAKES NO REPRESENTATIONS OR WARRANTIES OF ANY KIND WITH RESPECT TO THE INFORMATION IN THIS PUBLICATION, AND SPECIFICALLY DISCLAIMS IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR Authentication Manager administrator s 15 About This 15 RSA Authentication Manager Documentation .. 15 Related 16 Support and Service .. 16 Before You Call Customer Support .. 17 Chapter 1: RSA Authentication Manager 19 Introduction to RSA Authentication Manager .
5 19 Multifactor Authentication .. 19 Key Components for RSA Authentication Manager .. 20 Primary Instance .. 20 Replica Instance .. 21 Identity Sources .. 21 RSA Authentication 21 Risk-Based Authentication for a Web-Based Resource .. 22 RSA RADIUS Overview .. 22 Web Tier .. 23 Load Balancer .. 24 RSA SecurID Authentication Overview .. 24 RSA SecurID Authentication Process .. 25 RSA SecurID 26 The Role of RSA Authentication Manager In SecurID Authentication .. 28On-Demand Authentication .. 28On-Demand Authentication User Logon 29 Risk-Based Authentication .
6 29 Risk-Based Authentication Prevents Data Loss from Stolen Passwords .. 30 How Risk-Based Authentication Works .. 31 Chapter 2: Preparing RSA Authentication Manager for 33 Security Console ..33 Log On to the Security 34 Security Console 34 Security Console 37 Configure Security Console Authentication Methods .. 37 Identity 38 Data from an LDAP 39 Data from the Internal Database .. 39 Security Domain 39 User Organization and Management .. 39 Policy 404 ContentsRSA Authentication Manager administrator s GuideScope of administrator s Control.
7 40 Security Domains and Policies .. 40 Add a Security 41 Default Security Domain Mappings .. 43 Planning for Domain Name System Updates .. 44 Administrative Role Overview .. 44 Types of Administrative Roles .. 44 Administrative Role 44 Administrative Role 45 Predefined Administrative Roles .. 50 Administrative Role Settings .. 55 Administrative Role Scope and Permissions .. 57 Add an Administrative Role .. 58 Assign an Administrative Role .. 60 View Available Permissions of an administrator .. 60 Chapter 3: Deploying Authentication 63 RSA Authentication 63 Authentication Agent Types.
8 63 Obtaining RSA Authentication Agents .. 63 Deploying an Authentication Agent .. 64 Generate the Authentication Manager Configuration File .. 65 Add an Authentication Agent .. 66 Node Secret for 68 Manual Delivery of the Node Secret .. 68 Manage the Node Secret .. 69 Refresh the Node Secret Using the Node Secret Load 69 Automatic Agent Registration .. 70 Allow an Agent to Auto-Register .. 71 Download an RSA Authentication Manager Server Certificate .. 71 Contact Lists for Authentication 72 Automatic Contact Lists .. 72 Manual Contact Lists.
9 73 Chapter 4: Configuring Authentication 75 Policies .. 75 Token Policy .. 76 Token Policy Settings .. 77 Add a Token Policy .. 80 Offline Authentication Policy .. 82 Offline Authentication Policy Settings .. 82 Add an Offline Authentication Policy .. 83 Password Policy ..85 Password Policy Settings .. 86 Add a Password Policy .. 88 Contents5 RSA Authentication Manager administrator s GuideLockout Policy ..90 Lockout Policy Settings .. 90 Add a Lockout Policy .. 91 Self-Service Troubleshooting Policy .. 92 Self-Service Troubleshooting Policy Settings.
10 92 Add a Self-Service Troubleshooting Policy .. 93 Risk-Based Authentication 94 Risk-Based Authentication (RBA) Policy Settings .. 94 Add a Risk-Based Authentication Policy .. 95 Risk-Based Authentication Message Policy .. 97 Risk-Based Authentication Message Policy Settings .. 97 Add a Risk-Based Authentication Message Policy .. 97 Chapter 5: Integrating LDAP 99 Identity 99 Data from an LDAP 99 Data from the Internal Database .. 99 Identity Source Data Flow .. 100 Identity Source Properties .. 101 Identity Source Scope .. 105 Active Directory Identity Sources that are Not Global 106 Active Directory Global Catalog Identity Sources.