Integration Guide. SafeNet Authentication Service. NetDocuments

Similar documents
SafeNet Authentication Manager. Integration Guide. Using SAM as an Identity Provider for Dropbox

Integration Guide. SafeNet Authentication Service. Protecting SugarCRM with SAS

Integration Guide. SafeNet Authentication Service. Protecting Microsoft Internet Security and Acceleration (ISA) Server 2006 with SAS

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for Okta

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for Tableau Server

Integration Guide. SafeNet Authentication Service. Using SAS as an Identity Provider for Better MDM

Integration Guide. SafeNet Authentication Client. Using SAC CBA with Juniper Junos Pulse

Integration Guide. SafeNet Authentication Service. Protecting Syncplicity with SAS

Integration Guide. SafeNet Authentication Service. Strong Authentication for Juniper Networks SSL VPN

Integration Guide. SafeNet Authentication Service. SAS Using RADIUS Protocol with CA SiteMinder

Integration Guide. SafeNet Authentication Service. Strong Authentication for Citrix Web Interface 4.6

Configuration Guide. SafeNet Authentication Service. SAS Agent for Microsoft NPS Technical Manual Template

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for SonicWALL Secure Remote Access

Integration Guide. SafeNet Authentication Service. Using RADIUS Protocol for Citrix GoToMyPC

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for PingFederate

Integration Guide. SafeNet Authentication Manager. Using SafeNet Authentication Manager with Citrix XenApp 6.5

Integration Guide. SafeNet Authentication Service. Using RADIUS Protocol for VMware Horizon 6

Integration Guide. SafeNet Authentication Client. Using SAC CBA with BitLocker

Configuration Guide. SafeNet Authentication Service. SAS Agent for Microsoft SharePoint on IIS 7/8. Technical Manual Template

Integration Guide. SafeNet Authentication Manager. SAM using RADIUS Protocol with SonicWALL E-Class Secure Remote Access

Integration Guide. SafeNet Authentication Manager. SAM using RADIUS Protocol with Microsoft DirectAccess

Integration Guide. SafeNet Authentication Client. Using SAC CBA for VMware Horizon 6 Client

Integration Guide. SafeNet Authentication Manager. Using RADIUS Protocol for Citrix NetScaler 10.5

Integration Guide. SafeNet Authentication Service. SAS using RADIUS Protocol with WatchGuard XTMv. SafeNet Authentication Service: Integration Guide

KT-4 Keychain Token Welcome Guide

Welcome Guide. SafeNet Authentication Service. MP-1 BlackBerry. SafeNet Authentication Service: Welcome Guide. MP-1 BlackBerry

SafeNet Authentication Service Cisco AnyConnect Agent. Configuration Guide

SafeNet Authentication Service

Synchronization Agent Configuration Guide

Synchronization Agent Configuration Guide

SAS Agent for NPS CUSTOMER RELEASE NOTES. Contents

Integration Guide. SafeNet Authentication Manager. SAM using RADIUS Protocol with Check Point Security Gateway

Oracle iplanet Web Server Integration Guide

Integration Guide. SafeNet Authentication Manager. Using RADIUS Protocol for Cisco ASA

SAS Agent for NPS FAQS. Contents. Page 1 of 5. Description... 2 Frequently Asked Questions... 2 Product Documentation... 5 Support Contacts...

SafeNet Authentication Manager

MobilePASS for BlackBerry OS 10

Welcome Guide. SafeNet Authentication Service. RB-1 Tokens. SafeNet Authentication Service: Welcome Guide. RB-1 Tokens

SafeNet Authentication Service

SafeNet Authentication Service

SafeNet Authentication Service

SafeNet Authentication Client

SafeNet Authentication Manager

SafeNet Authentication Service

SafeNet Authentication Service

SafeNet Authentication Service

Oracle Access Manager Configuration Guide

SafeNet Authentication Manager

SafeNet Authentication Client

SAS Agent for Microsoft SharePoint

SAS Agent for Microsoft Internet Information Services (IIS)

Protecting SugarCRM with SafeNet Authentication Manager

SafeNet Authentication Service

Sentinel Cloud V.3.6 Installation Guide

Sentinel Cloud Run-time Java Samples ReadMe

SafeNet Authentication Manager

SafeNet Authentication Client

SafeNet Authentication Service

SAS Synchronization Agent

SafeNet Authentication Client

SafeNet Authentication Client

SafeNet Authentication Client

Preface. Microsoft SQL Server 2008 and Luna SA/Luna PCI Integration Guide SafeNet, Inc. All rights reserved.

SafeNet Authentication Client

SafeNet Authentication Service Token Validator Proxy Agent. Installation and Configuration Guide

SafeNet Authentication Client

SafeNet Authentication Service

Nimsoft Service Desk. Single Sign-On Configuration Guide. [assign the version number for your book]

SafeNet Authentication Service

Five9 Plus Adapter for Agent Desktop Toolkit

SafeNet Authentication Manager

Cloud Access Manager Configuration Guide

SafeNet Authentication Service (SAS) Service Provider Billing and Reporting Guide

Microsoft ADFS Configuration

April Understanding Federated Single Sign-On (SSO) Process

TECHNICAL GUIDE SSO SAML. At 360Learning, we don t make promises about technical solutions, we make commitments.

Copyright

SafeNet Authentication Manager

CONFIGURING AD FS AS A THIRD-PARTY IDP IN VMWARE IDENTITY MANAGER: VMWARE WORKSPACE ONE OPERATIONAL TUTORIAL VMware Workspace ONE

D9.2.2 AD FS via SAML2

October 14, SAML 2 Quick Start Guide

How to Use ADFS to Implement Single Sign-On for an ASP.NET MVC Application

SafeNet Authentication Manager

Configuration Guide - Single-Sign On for OneDesk

NETOP PORTAL ADFS & AZURE AD INTEGRATION

Configuring Alfresco Cloud with ADFS 3.0

Sentinel LDK. Software Protection and Licensing Tutorial: Demo Kit

SafeNet Authentication Service (SAS) SAML Authentication Quick Start Guide

HDI HP-GL/2 Driver for AutoCAD Getting Started

One Identity Starling Two-Factor AD FS Adapter 6.0. Administrator Guide

Five9 Plus Adapter for NetSuite

VIEVU Solution AD Sync and ADFS Guide

SafeNet Authentication Service Agent for Cisco AnyConnect Client. Installation and Configuration Guide

Software Protection and Licensing Tutorial Starter Kit

ADFS integration with Ibistic Commerce Platform A walkthrough of the feature and basic configuration

Integration Guide. BlackBerry Workspaces. Version 1.0

SafeNet Authentication Service Synchronization Agent. Configuration Guide

Novell Access Manager

SafeNet Authentication Service Agent for Microsoft Outlook Web App. Installation and Configuration Guide

AvePoint Online Services for Partners 2

Transcription:

SafeNet Authentication Service Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1

Document Information Document Part Number 007-012560-001, Rev. A Release Date June 2014 Trademarks All intellectual property is protected by copyright. All trademarks and product names used or referred to are the copyright of their respective owners. No part of this document may be reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, chemical, photocopy, recording, or otherwise, without the prior written permission of SafeNet, Inc. Disclaimer SafeNet makes no representations or warranties with respect to the contents of this document and specifically disclaims any implied warranties of merchantability or fitness for any particular purpose. Furthermore, SafeNet reserves the right to revise this publication and to make changes from time to time in the content hereof without the obligation upon SafeNet to notify any person or organization of any such revisions or changes. We have attempted to make these documents complete, accurate, and useful, but we cannot guarantee them to be perfect. When we discover errors or omissions, or they are brought to our attention, we endeavor to correct them in succeeding releases of the product. SafeNet invites constructive comments on the contents of this document. These comments, together with your personal and/or company details, should be sent to the address or email below. Contact Method Mail Email Contact Information SafeNet, Inc. 4690 Millennium Drive Belcamp, Maryland 21017, USA TechPubs@safenet-inc.com 2

Contents Contents Introduction... 4 Third-Party Software Acknowledgement... 4 Overview... 4 Single Sign-On Dataflow... 4 Configuring to Use SAS... 5 Configuring Federated Identity Login... 5 Configuring the MFA Agent... 7 Configuring as a Relying Party of AD FS... 7 Configuring the AD FS Authentication Policy... 12 Running the Solution... 13 Support Contacts... 15 3

Introduction Third-Party Software Acknowledgement This document is intended to help users of SafeNet products when working with third-party software, such as. Material from third-party software is being used solely for the purpose of making instructions clear. Screen images and content obtained from third-party software will be acknowledged as such. Overview This document provides guidance for setting up and managing SafeNet Authentication Service (SAS) as an identity provider for using AD FS 3.0 (bundled with Windows Server 2012 R2) and SafeNet Authentication Agent for AD FS. For prior versions of AD FS, you may use the SafeNet Authentication Management SAML solution by following the instructions provided in the following guide, Microsoft Office 365 Using SAML Integration Guide. NOTE: This document assumes that is already configured and working with AD users and static passwords prior to implementing SafeNet Authentication Service strong authentication. Single Sign-On Dataflow 1. Bob, a user, wants to log in to. First, Bob is asked to enter his organization credentials. After Bob s AD credentials have been authenticated, SafeNet Authentication Service (SAS) credentials are required. SAS collects and evaluates Bob's credentials. 2. SAS returns a response to to accept or reject Bob s credentials for authentication. 4

Configuring to Use SAS This section provides guidance on configuring to use SAS as an authentication method. Configuring Federated Identity Login 1. Log in to as an administrator. 2. On the Home window, click the Admin button (top right corner). (The screen image above is from software. Trademarks are the property of their respective owners.) 3. On the Repository Administration window, click the Add and remove users and groups link. (The screen image above is from software. Trademarks are the property of their respective owners.) 5

4. On the Repository Membership window, click the Configure advanced authentication options link. (The screen image above is from software. Trademarks are the property of their respective owners.) 5. On the Advanced Authentication Configuration window, perform the following steps: a. Under Step 1, select Active Directory Federation Services as your identity provider. b. Under Step 2, configure your identity provider by copying the metadata document URL. To do so, rightclick on the metadata document link and select Copy Link Location. This link will be needed later for Configuring as a Relying Party of AD FS on page 7. c. Under Step 3, configure your repository by entering the Federation metadata document URL as follows: https://<your AD FS domain>/federationmetadata/2007-06/federationmetadata.xml d. Next, enter the URL that your users should use to log in to via your identity provider. (The screen image above is from software. Trademarks are the property of their respective owners.) 6

Configuring the MFA Agent 1. Run the MFA Plugin Manager. 2. On the Policy tab, select Enable/Disable Agent and Pre Generate Challenge. 3. On the Communications tab, type the SAS Primary Server IP address or name (and port if non-causal is used). 4. Click Apply. Enabling the agent registers the SafeNet MFA adapter with AD FS and enables it at a global policy level. 5. You can check your settings by running an authentication test using the Test button. Configuring as a Relying Party of AD FS 1. Run AD FS. 2. In the left pane, expand Trust Relationships, and then click Relying Party Trusts. 7

3. In the left pane, right-click Relying Party Trusts and then select Add Relying Party Trust. The Add Relying Party Trust Wizard will open. 4. Click the Start button. 8

5. In the left pane, click Select Data Source. 6. On the Select Data Source window, do the following: a. Select the option Import data about the relying party published online or on a local network. b. In the Federation metadata address field, paste the federated identity metadata URL that you copied in step 5b of Configuring Federated Identity Login on page 5. c. Click Next. 7. On the Specify Display Name window, in the Display name field, enter a name such as, and then click Next. 9

8. On the Configure Multi-factor Authentication window, enter your preferences, and then click Next. The default values can be used. 9. On the Choose Issuance Authorization Rules window, enter your preferences, and then click Next. The default values can be used. 10. On the Ready to Add Trust window, click Next. 11. Select the Open the Edit Claim Rules dialog check box, and then click Close. 12. On the Edit Claim Rules window, do the following: a. On the Issuance Transform Rules tab, click the Add Rule button. 10

b. Select Send LDAP Attributes as Claims and then click Next. 13. On the Configure Claim Rule tab, do the following: a. In the Claim rule name field, enter a name such as LDAP claims. b. In the Attribute store field, select Active Directory. c. In the Mapping table, do the following: In the LDAP Attribute column, select SAM-Account-Name. In the Outgoing Claim Type column, select Name ID. d. In the Mapping table, create another entry for an Email Address claim. In the LDAP Attribute column, select E-Mail-Addresses. In the Outgoing Claim Type column, select E-Mail Address. e. Click OK to continue. 14. On the Add Transform Claim Rule Wizard window, click Finish. 15. On the Edit Claim Rules window, click OK. 11

Configuring the AD FS Authentication Policy 1. Run AD FS. 2. In the left pane, right-click Authentication Policies and select Edit Global Primary Authentication. 3. In the right pane, on the Primary tab, verify that Form Authentication is enabled for both Extranet and Intranet. 4. Click the Multi-factor tab, and then do the following: a. In the Users/Groups box, use the Add button to add the users/groups that you want the MFA to take control of. b. Under Locations, select Extranet and/or Intranet according to your preferred configuration. c. Verify that SafeNet Multi Factor Authentication (SMFA) is enabled as an additional authentication method. d. Click OK. SafeNet Authentication Service is now configured as an additional authentication method (along with AD FS) for. 12

Running the Solution After is configured to use SAS as its identity provider, and the SAS MFA Agent is configured, users can log in to. To log in to : 1. Browse to your identity provider link for login (defined in Step 5d of Configuring Federated Identity Login on page 5). 2. You will be redirected to your domain login page. Enter your login credentials and then click Sign in. 3. On the SafeNet Authentication login page, enter your SafeNet Authentication Service credentials and then click Submit. 13

4. After successful login, you will be redirected to the Home window. (The screen image above is from software. Trademarks are the property of their respective owners.) 14

Support Contacts If you encounter a problem while installing, registering, or operating this product, please make sure that you have read the documentation. If you cannot resolve the issue, contact your supplier or SafeNet Customer Support. SafeNet Customer Support operates 24 hours a day, 7 days a week. Your level of access to this service is governed by the support plan arrangements made between SafeNet and your organization. Please consult this support plan for further information about your entitlements, including the hours when telephone support is available to you. Table 1: Support Contacts Contact Method Address Contact Information SafeNet, Inc. 4690 Millennium Drive Belcamp, Maryland 21017 USA Phone United States 1-800-545-6608 International 1-410-931-7520 Technical Support Customer Portal https://serviceportal.safenet-inc.com Existing customers with a Technical Support Customer Portal account can log in to manage incidents, get the latest software upgrades, and access the SafeNet Knowledge Base. 15