RSA SecurID Ready Implementation Guide

Similar documents
How to Integrate CA SiteMinder with the Barracuda Web Application Firewall

Last Updated: July 04 th, 2014.Changes from the previous version are in green. SITEMINDER ,29 PLATFORM SUPPORT 1. Policy Server 11,

etrust SiteMinder Agent r5.5 for BEA WebLogic 9.0 etrust SiteMinder Agent for BEA WebLogic Guide

Configuring a Secure Access etrust SiteMinder Server Instance (NSM Procedure)

CA SiteMinder. Agent for JBoss Guide SP1

etrust SiteMinder Agent r6.0 for IBM WebSphere

OTP SERVER NETEGRITY SITEMINDER 6. Rev 1.0 INTEGRATION MODULE. Copyright, NordicEdge, 2005 O T P S E R V E R I N T E G R A T I O N M O D U L E

CA SITEMINDER OVERVIEW

IBM Tivoli!"!"#$%&'() IBM!"#$%&'()*+,

CA SiteMinder. Agent for JBoss Guide. r12.1 SP3. Third Edition

CA SiteMinder. Agent for JBoss Guide 12.51

etrust SiteMinder Connector for Oracle Solutions Architecture, Installation and Configuration Guide For UNIX Version 1.6 (Rev 1.

KB 2449 CA Wily APM security example: CA SiteMinder for authentication with CA EEM for authorization

API Gateway Version September Authentication and Authorization Integration Guide

The implications of. Simon Willison Google Tech Talk, 25th June 2007

Integrating CA (formerly Netegrity) SiteMinder 6.0 with IBM Lotus Connections 2.0

CA SiteMinder Federation Standalone

Dell EMC Unisphere 360

CA SiteMinder Web Access Manager r12

CA SiteMinder Web Services Security

CA SiteMinder Web Services Security

Installation Guide. Unisphere Central. Installation. Release number REV 07. October, 2015

Setup and Configure the Siteminder Policy Store with Dxmanager

ICTAP Program. Interoperable Communications Technical Assistance Program. Communication Assets Survey and Mapping (CASM) Tool Short Introduction

EMC Unisphere 360 for VMAX

IBM Tivoli Storage Manager Version Configuring an IBM Tivoli Storage Manager cluster with IBM Tivoli System Automation for Multiplatforms

INTERNATIONAL CIVIL AVIATION ORGANIZATION AFI REGION AIM IMPLEMENTATION TASK FORCE. (Dakar, Senegal, 20 22nd July 2011)

SUPPLEMENT AUGUST CITATION PERFORMANCE CALCULATOR (CPCalc) MODEL THRU FM-S51-00 S51-1 U.S.

MyTraveler User s Manual

SUPPLEMENT 3 11 APRIL CITATION PERFORMANCE CALCULATOR (CPCalc) MODEL AND ON 510FM-S3-00 S3-1 U.S.

EMC Unisphere 360 for VMAX

Tivoli/Plus for ADSM 1.0

Incorporates passenger management, fleet management and revenue/cost reporting

Tivoli Inventory 3.6.2

Cisco CMX Cloud Proxy Configuration Guide

Bonita Workflow. Getting Started BONITA WORKFLOW

EMC Unisphere for VMAX

EMC Unisphere 360 for VMAX

Baggage Reconciliation System

Bernina cps software updates. Bernina cps software updates.zip

Schedule Published: 6 th April, 2009

Video Media Center - VMC 1000 Getting Started Guide

Management System for Flight Information

User Guide for E-Rez

Microsoft Courses Schedule February December 2017

Management System for Flight Information

❷ s é ②s é í t é Pr ③ t tr t á t r ít. á s á rá. Pr ③ t t í t. t í r r t á r t á s ý. r t r é s②sté ②

MARKETO INTEGRATION GUIDE

Hitachi GigE Camera. Installation Manual. Version 1.6

Monitoring & Control Tim Stevenson Yogesh Wadadekar

Punt Policing and Monitoring

Firewall Network and Proxy Datasheet

Federal GIS Conference February 10 11, 2014 Washington DC. ArcGIS for Aviation. David Wickliffe

DELMIA V5.19 extends digital manufacturing for production excellence

CA SiteMinder. Federation.NET SDK Guide 12.51

lastminute.com Group Milan November 2018

PSS VM 7.15 announcement

A Survey of Time and Space Partitioning for Space Avionics

Technical Standard Order

Information security supplier rules. Information security supplier rules

Amadeus Virtual MCO. Reservation Platform Ticketing & Payment Amadeus IT Group SA

USER GUIDE Cruises Section

HardSID Uno / UPlay user s guide HardSID Uno HardSID UPlay

Addendum to Model Implementation Conformance Statement for the IEC Ed2 interface in ABB 670 and 650 series version 2.2

Traveltek Agent User Guide APRIL VERSION 01

SUPPLEMENT OCTOBER CITATION PERFORMANCE CALCULATOR (CPCalc) MODEL AND ON REVISION 8 68FM-S17-08

IBM Tivoli Privacy Manager for e-business 1.2 SA

OpenComRTOS: Formally developed RTOS for Heterogeneous Systems

Navitaire GoNow Day-of-departure services

Cvent Passkey Glossary

Virgin Australia s Corporate Booking Portal User Guide

PSS MVS 7.15 announcement

Trail Shuttle Create Your Own Interactive Learning Trail

OVERVIEW OF THE FAA ADS-B LINK DECISION

How To Set Up and Use the SAP ME Earned Standards Feature

Accessibility DOT/CTA Updates

Deutscher Wetterdienst

Interacting with HDFS

ARIS/CI check-in counter allocator

2.2 Air Navigation Deficiencies ICAO CAR/SAM AIR NAVIGATION DEFICIENCIES DATABASE SIP. (Presented by the Secretariat) SUMMARY

Regional Seminar/Workshop on CMA and SAST

The Mass HIway Connection Requirement: Year 1 & Year 2

KEY FEATURES IN SHORT

ARIS/SL schedule loader

IATA Paperless Aircraft Operations Conference Review of e-operation initiatives since SWISS

Distributed Object Storage System Ceph in Practice

FOR SMALL AND MEDIUM SIZED AIRPORTS Velocity FIDS

Concur Travel User Guide

ADS-B. Installation Challenges. July 13, Federal Aviation Administration. James Marks ADS-B Focus Team Lead FAA Flight Standards Service

Thematic Challenge #1 10,000 Steps to Fly with Singapore Airlines Challenge Frequently Asked Questions (FAQs)

CruisePay Enhancements for 2005 Training Guide Version 1.0

CruiseBuilder 2.0 Tutorial. How to Set Up CruiseBuilder 2.0 How to Use CruiseBuilder 2.0 Booking Engine

Integrated Modular Avionics. The way ahead for aircraft computing platforms?

What Is AWS Icebreaker?

IBM Tivoli Monitoring for Databases GA

Supports full integration with Apollo, Galileo and Worldspan GDS.

NOTAM MANAGER. Presented to: Minnesota Airports Conference Steve Meinders NISC Contract Support. By: or 2550

CRISIS AIREP Guidance

AIRLINE RESERVATION SYSTEM DOCUMENTATION KEMARA

Question Answer. provide a list of these individuals including the the business areas they work in and their positions, is

Transcription:

RSA SecurID Ready Implementation Guide Last Modified Thursday, May 08, 2003 1. Partner Information Partner Name Web Site Product Name Version & Platform Product Description Product Category Netegrity, Inc. www.netegrity.com SiteMinder 4.6.1 SP5 & 5.5 SP1 (W2K, Solaris, HP-UX, AIX, Linux), Netegrity SiteMinder enables companies to centrally administer and enforce user authentication and authorization management as well as by provide single signon (SSO) to users. SiteMinder's advanced management tools offer fast development, deployment, and management of sophisticated web security systems Access Management 2. Contact Information Sales Contact Support Contact E-mail sales@netegrity.com Support@Netegrity.com Phone (800) 325-9870 781-890-1700 Web www.netegrity.com www.netegrity.com/support 1

3. Solution Summary Feature Authentication Methods Supported Details Native SecurID ACE/Agent Library Version 5.02 ACE 5 Locking Replica ACE/Server Support Secondary RADIUS/TACACS+ Server Support Location of Node Secret on Client ACE/Server Agent Host Type SecurID User Specification SecurID Protection of Administrators Yes Full Replica Support Yes Registry or Windows: \winnt\system32 Unix: /var/ace Net OS, UNIX Designated users Yes 2

4. Product Requirements Hardware requirements Component Name: SiteMinder CPU make/speed required Memory HD space Pentium 3 600Mhz 128 MB (256 MB recommended) 100 MB (500 MB recommended) Component Name: SiteMinder CPU make/speed required Memory HD space Sparc or other UNIX 128 MB (256 MB recommended) 100 MB (500 MB recommended) Software requirements Component Name: SiteMinder Operating System Version (Patch-level) NT 4.0 SP5 or SP6a Windows 2000 SP1 Solaris 2.6 kernel update = 105181-17 C++ shared library = 105591-09 libc = 105210-25 libthread = 105568-14 Solaris 2.7 kernel update = 106541-08 C++ shared library = 106327-08 libthread = 106980-07 Solaris 2.8 Core Solaris libraries = 108827-12 HP-UX 11.0, 11i PHSS_26263 Web Server: IIS 4, IIS5, iplanet Web Server Enterprise Edition 4.0 or later, Netscape Enterprise Web Server 3.6x or later Browser: Netscape Communicator 4.06, 4.5, 4.6 or later, or Microsoft Internet Explorer 4.0, 4.01, or 5.0 (with Java Virtual Machine 4.79.0.2424 or newer). If you use an older 4.x version of Netscape, you must get the Java 1.1 Patch from http://developer.netscape.com. 3

5. Partner ACE/Agent configuration This document will define how to configure SiteMinder to authenticate users to protected resources using RSA SecurID hardware tokens. SecurID Scheme Prerequisites To use the SecurID authentication scheme, the following criteria must be met: The RSA ACE/Client software must be installed on the same machine as the SiteMinder Policy Server. The ACE/Server must have the Policy Server defined as a client to the ACE/Server. A local test authentication from the ACE/Client on the Policy Server must be successful. Configuration Steps: 1. Install and configure the SiteMinder Web Agent on the appropriate web servers that will provide access to resources managed by SiteMinder. 2. Within the SiteMinder Policy Server create a Policy Domain (see Figure 1). A policy domain is a logical grouping of resources associated with one or more user directories. Figure 1 4

3. Create a SecurID Authentication Scheme (see Figure 2). When a user attempts to access a protected resource, SiteMinder uses the Authentication Scheme associated with the resource s realm to identify the user. Figure 2 5

4. Create a Realm (see Figure 3). A realm is a cluster of resources within a policy domain grouped together according to security requirements. The contents of a Realm are protected by Agents. When users request resources within a realm, the associated Agent handles authentication and authorization of the user. Figure 3 6

5. Create a Rule (see Figure 4). SiteMinder rules identify specific resources and either allow or deny access to the resources. Figure 4 7

6. Create a Policy. Policies define how users interact with resources. When a Policy is defined in SiteMinder, you link together (bind) different SiteMinder objects that identify users, resources, and actions associated with the resources. Policies are stored in Policy domains. When you configure a policy, you can select users and groups from the user directories available in the policy domain (see Figure 5). Figure 5 8

SiteMinder identifies resources through rules. When you create a policy, you can select rules that specify the resources you want to include in a policy (see Figure 6). SecurID Passcode prompts Figure 6 Figure 7 - Standard Prompt 9

Figure 8 - New Pin Mode Figure 9 - Next Tokencode Mode 10

6. Certification Checklist Date Tested: August 8, 2002 Product Tested Version ACE/Server 5.01 ACE/Agent 5.03 build 488 SiteMinder 4.61 SP4, 5.5 SP1 Test ACE RADIUS 1 st time auth. (node secret creation) P N/A New PIN mode: System-generated Non-PINPAD token P N/A PINPAD token P N/A User-defined (4-8 alphanumeric) Non-PINPAD token P N/A Password P N/A User-defined (5-7 numeric) Non-PINPAD token P N/A PINPAD token P N/A SoftID token P N/A Deny 4 digit PIN P N/A Deny Alphanumeric P N/A User-selectable Non-PINPAD token P N/A PINPAD token P N/A PASSCODE 16 Digit PASSCODE P N/A 4 Digit Password P N/A Next Tokencode mode Non-PINPAD token P N/A PINPAD token P N/A Replica Servers P N/A User Lock Test (ACE Lock Function) P N/A No ACE/Server P N/A JRV P=Pass or Yes, F=Fail, * = See Section 7 Known Issues N/A=Non-available function 11

7. Known Issues There are no known issues. 12