 |
» |
|
|
 |
To configure the AAA server to work with the RSA ACE/Server,
the following steps must be performed. If you are not familiar with
the ACE/Server, contact your ACE administrator for assistance. Configuring
the AAA Server for RSA Authentication |  |
Identifying
SecurID Users by User Name with Server Manager |  |
For each individual
user that will be authenticated through the ACE/Server, you will
need to add a user profile to the RADIUS server. Select the
Users link from the Navigation Tree. Select the New User link from the Define Users screen. The Users Attributes
screen appears. In the User Name field identify,
identify the user profile by user name and the user's realm. From the Authentication Type
drop-down list, select SecurID. Complete any of the remaining
optional fields as necessary for your configuration. Select the Create button. Repeat steps 2 to 6 for as many
users as needed. Select the Save Configuration link from the Navigation Tree. If you have multiple
remote servers, you will prompted to select and confirm which servers
you wish to add the access device entry to.  |  |  |  |  | CAUTION: Save Configuration will save the entire server configuration (access
devices, proxies, local realms, users, and server properties) to the
servers you specify. |  |  |  |  |
Identifying
SecurID Users by Realm with Server Manager |  |
For each realm using
SecurID, you must associate the realm name with the ACE/Server that
will perform the authentication. Select the Local Realms link from the Navigation Tree. Select the New Realm link from the Local Realms screen. The Realm Attributes screen
appears. In the Name field, enter the
name of the realm to map to the defined SecurID location. This name
does not have to be a DNS host name, although it is highly recommended
that the realm name match a domain name so the user recognizes the
user@realm syntax that resembles their e-mail address. From the Authentication Type
drop-down list, select SecurID. From the Protocol drop-down list,
select PAP.  |  |  |  |  | IMPORTANT: Only PAP authentication is supported with
the SecurID authentication type. |  |  |  |  |
Complete any of the remaining
optional fields as necessary for your configuration. Select the Create button. Repeat steps 2 to 8 as necessary
for your configuration. Select Save Configuration from the Navigation Frame. If you have multiple remote
servers, you will prompted to select and confirm which servers you
wish to add the access device entry to.  |  |  |  |  | CAUTION: Save Configuration will save the entire server configuration (access
devices, proxies, local realms, users, and server properties) to the
servers you specify. |  |  |  |  |
Configuring
the ACE/Server |  |
Start the ACE/Server
Administration program and verify that the AAA server has an entry
on the list of clients. If there is no corresponding
entry, from the Client menu, select Add Client. Complete the Client
dialog box, giving the AAA server a Client type of Net OS Client
as shown in the following figure: Use SecurID documentation to
add user profiles to the SecurID server.
Synchronizing the AAA Server with the ACE/Server |  |
After the first successful SecurID Authentication, the AAA
server will save a file called securid in the AAA server configuration directory (/etc/opt/aaa by default). The securid file contains secret information required for
further ACE/Server authentication requests. If the AAA server has
been reinstalled, or if this file is not present in the AAA server configuration
directory, perform the following steps to synchronize the AAA server
with the ACE/Server. From the Client menu,
select Edit Client. Select the client that you need
to edit From the Edit Client screen,
make sure that the check box for Sent Node Secret is deselected as shown in the following figure.
When this check box is deselected, the ACE/Server sends the
securid file in the AAA server during the next SecurID authentication
attempt initiated by the AAA server. Select the OK button.
|