Configuring remote authentication with multi-factor authentication- RSA SecurID Authentication Manager

Use the Configure Remote Authentication wizard to configure the storage system for multi-factor authentication(MFA) with RSA SecurID Authentication Manager.

Before you begin

The following prerequisites apply to configuring remote authentication for multi-factor authentication(MFA) with RSA SecurID Authentication Manager.
  • Access to the RSA SecurID Authentication Manager configuration.
  • The Accounts created for the users in RSA Authentication Manager and assigned RSA tokens.
  • Restful API authentication enabled on the RSA SecurID server.

Procedure

  1. Log in to the DS8000® Storage Management GUI as a user with administrator privileges.
  2. Select Access > Remote Authentication to open the Remote Authentication page.
  3. Click Configure Remote Authentication to open the Remote Authentication wizard.
  4. On the Remote Authentication page, select Multi-factor Authentication - RSA SecurID Authentication Manager.
  5. On the Configure RSA SecurID page, enter connection information for the RSA SecurID server.
    RSA SecurID Base URL

    Enter the server name and port number of the RSA SecurID server. (Example: your_domain.com: 5555).

    Retrieve Certificates
    Note: You must either upload a truststore file that holds signer certificate for the RSA SecurID server or retrieve the signer certificate from the RSA SecurID server.
    • To upload a truststore file, click Upload Truststore to open the Upload Truststore window and select a truststore file and enter an optional password for the file.
    • To retrieve signer certificates from the RSA SecurID server, click Retrieve Certificates to open the Retrieve Certificates window and display the certificates. Click Accept to complete the retrieval process.
    Access ID
    An identifier of the API Access Key used to send authentication requests to an RSA SecurID server. It is unique to the API Access Key and it is generated by the SecurID Super Admin when enabling API authentication.
    Access Key
    The unique passcode that is used in combination with access identifier when sending authentication requests to an RSA SecurID server. It is generated by the SecurID Super Admin when enabling API authentication.
  6. On the Enable Local Administrator page, click Enable to use a local authentication Administrator user on the storage system in addition to MFA authentication. If you choose to enable the local Administrator, you must enter the User Name and Password for the Administrator role on the storage system.
  7. If the user intends to configure Data at rest Encryption using key servers and a recovery key, ensure that the local security administrator role is mapped to a user account that is managed by a remote authentication server. For more information, see Creating a remote mapping for the security administrator role.
    Warning: The security administrator must map the security administrator role to a remote user before remote authentication is enabled on the storage system. If remote authentication is enabled without a remote mapping for the security administrator role, the security administrator will be locked out of the storage system and unable to use the recovery key if the system loses access to encryption key servers.
  8. On the Configure Authentication Mappings page, map local roles that are defined on the storage system to users on the RSA SecurID server. Select the RSA SecurID user name, and the associated Role on the storage system.
  9. On the Administrator Verification page, enter the User Name for the RSA SecurID user account that is mapped to the Administrator role on the storage system.
  10. On the Summary page, review the MFA configuration information and click Finish to enable MFA authentication.
  11. Enter the RSA SecurID passcode for the respective user to complete administrative verification.