Assigning policies and enrolling the certificate
If the user's smart card reader is directly attached to a USB port on the AIX® operating system, you must assign one or more policies to a user and enroll the PIV/CAC card certificate you want the user to use.
To assign policies and enroll the PIV/CAC card certificate you want the user to use,
complete the following steps:
Note: If you do not want to use a web browser, you can the bulk
provisioning feature. The bulk provisioning feature is described in Provisioning users in bulk for IBM PowerSC MFA.
- Log in to the IBM PowerSC MFA GUI.
- In the IBM PowerSC MFA GUI, click the User Provisioning tab.
-
Select an existing user.
The All Policies table shows all of the available policies.
- Click + in the Policies section.
- Select one or more policies that includes only the AZFCERT1 authentication method.
-
Click Confirm.
The Authentication Methods table shows the configured authentication methods for the policy.
- Select the AZFCERT1 authentication method.
- Click Check provisioning information.
- You are prompted for the user-specific authentication method settings. For AZFCERT1, upload the user's PIV/CAC card public certificate. You can browse to the file that is in the .cer or .pem format.
- Click Confirm.
- Set Active to On for the authentication method.
- Click Confirm.