Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
More options
HP.com home
HP-UX AAA Server A.06.00 Administration and Authentication Guide: HP-UX 11.0, 11i v1 > Chapter 13 SecurID

Configuring SecurID Authentication

» 

Technical documentation

Complete book in PDF
» Feedback
Content starts here

 » Table of Contents

 » Glossary

 » Index

To configure the AAA server to work with the RSA ACE/Server, the following steps must be performed. If you are not familiar with the ACE/Server, contact your ACE administrator for assistance.

Configuring the AAA Server for RSA Authentication

  1. Copy the file sdconf.rec from its usual location on the ACE/Server ( /ACE/data) to the AAA server configuration directory ( /etc/opt/aaa by default).

    IMPORTANT: If you copy the sdconf.rec file after the AAA server has been started, then you must stop and start the AAA server before SecurID will work.
  2. Identify the user profiles that are stored on the SecurID server after you copy the sdconf.rec file to the AAA server configuration directory.

    NOTE: You may identify these user profiles by user name or by realm. It is not necessary to do both. If you have identified a realm that a group of SecurID users belong to, it is not necessary to also identify them by user name.

Identifying SecurID Users by User Name with Server Manager

  1. For each individual user that will be authenticated through the ACE/Server, you will need to add a user profile to the RADIUS server. Select the Users link from the Navigation Tree.

  2. Select the New User link from the Define Users screen. The Users Attributes screen appears.

  3. In the User Name field identify, identify the user profile by user name and the user's realm.

  4. From the Authentication Type drop-down list, select SecurID.

  5. Complete any of the remaining optional fields as necessary for your configuration.

  6. Select the Create button.

  7. Repeat steps 2 to 6 for as many users as needed.

  8. Select the Save Configuration link from the Navigation Tree. If you have multiple remote servers, you will prompted to select and confirm which servers you wish to add the access device entry to.

    CAUTION: Save Configuration will save the entire server configuration (access devices, proxies, local realms, users, and server properties) to the servers you specify.

Identifying SecurID Users by Realm with Server Manager

  1. For each realm using SecurID, you must associate the realm name with the ACE/Server that will perform the authentication. Select the Local Realms link from the Navigation Tree.

  2. Select the New Realm link from the Local Realms screen. The Realm Attributes screen appears.

  3. In the Name field, enter the name of the realm to map to the defined SecurID location. This name does not have to be a DNS host name, although it is highly recommended that the realm name match a domain name so the user recognizes the user@realm syntax that resembles their e-mail address.

  4. From the Authentication Type drop-down list, select SecurID.

  5. From the Protocol drop-down list, select PAP.

    IMPORTANT: Only PAP authentication is supported with the SecurID authentication type.
  6. Complete any of the remaining optional fields as necessary for your configuration.

  7. Select the Create button.

  8. Repeat steps 2 to 8 as necessary for your configuration.

  9. Select Save Configuration from the Navigation Frame. If you have multiple remote servers, you will prompted to select and confirm which servers you wish to add the access device entry to.

    CAUTION: Save Configuration will save the entire server configuration (access devices, proxies, local realms, users, and server properties) to the servers you specify.

Configuring the ACE/Server

  1. Start the ACE/Server Administration program and verify that the AAA server has an entry on the list of clients.

  2. If there is no corresponding entry, from the Client menu, select Add Client. Complete the Client dialog box, giving the AAA server a Client type of Net OS Client as shown in the following figure:

    Figure 13-1 SecurID Add Client Screen

    SecurID Add Client Screen
  3. Use SecurID documentation to add user profiles to the SecurID server.

Synchronizing the AAA Server with the ACE/Server

After the first successful SecurID Authentication, the AAA server will save a file called securid in the AAA server configuration directory (/etc/opt/aaa by default). The securid file contains secret information required for further ACE/Server authentication requests. If the AAA server has been reinstalled, or if this file is not present in the AAA server configuration directory, perform the following steps to synchronize the AAA server with the ACE/Server.

  1. From the Client menu, select Edit Client.

  2. Select the client that you need to edit

  3. From the Edit Client screen, make sure that the check box for Sent Node Secret is deselected as shown in the following figure. When this check box is deselected, the ACE/Server sends the securid file in the AAA server during the next SecurID authentication attempt initiated by the AAA server.

    Figure 13-2  SecurID Edit Client Screen

    SecurID Edit Client Screen
  4. Select the OK button.

Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2003 Hewlett-Packard Development Company, L.P.