Use the Configure Remote Authentication wizard to configure the storage system for
multi-factor authentication(MFA) with RSA SecurID Authentication Manager.
Before you begin
The following prerequisites apply to configuring remote authentication for
multi-factor authentication(MFA) with RSA SecurID Authentication Manager.
- Access to the RSA SecurID Authentication Manager configuration.
- The Accounts created for the users in RSA Authentication Manager and assigned RSA tokens.
- Restful API authentication enabled on the RSA SecurID server.
Procedure
-
Log in to the DS8000®
Storage Management GUI as a user with administrator privileges.
-
Select to open the Remote Authentication page.
-
Click Configure Remote Authentication to open the Remote
Authentication wizard.
-
On the Remote Authentication page, select Multi-factor
Authentication - RSA SecurID Authentication Manager.
-
On the Configure RSA SecurID page, enter connection information for the
RSA SecurID server.
- RSA SecurID Base URL
-
Enter the server name and port number of the RSA SecurID server. (Example: your_domain.com:
5555).
- Retrieve Certificates
-
Note: You must either upload a truststore file that holds signer certificate for the RSA SecurID
server or retrieve the signer certificate from the RSA SecurID server.
-
- To upload a truststore file, click Upload Truststore to open the Upload
Truststore window and select a truststore file and enter an optional password for the file.
- To retrieve signer certificates from the RSA SecurID server, click Retrieve
Certificates to open the Retrieve Certificates window and display the certificates.
Click Accept to complete the retrieval process.
- Access ID
- An identifier of the API Access Key used to send authentication requests to an RSA SecurID
server. It is unique to the API Access Key and it is generated by the SecurID Super Admin when
enabling API authentication.
- Access Key
- The unique passcode that is used in combination with access identifier when sending
authentication requests to an RSA SecurID server. It is generated by the SecurID Super Admin when
enabling API authentication.
-
On the Enable Local Administrator page, click
Enable to use a local authentication Administrator user on the storage system
in addition to MFA authentication. If you choose to enable the local Administrator, you must enter
the User Name and Password for the Administrator role
on the storage system.
- If the user intends to configure Data at rest Encryption using key servers and a recovery
key, ensure that the local security administrator role is mapped to a user account that is managed
by a remote authentication server. For more information, see Creating a remote mapping for the security administrator role.
Warning: The security administrator must map the security administrator
role to a remote user before remote authentication is enabled on the storage system. If remote
authentication is enabled without a remote mapping for the security administrator role, the security
administrator will be locked out of the storage system and unable to use the recovery key if the
system loses access to encryption key servers.
-
On the Configure Authentication Mappings page, map local roles that are
defined on the storage system to users on the RSA SecurID server. Select the RSA SecurID
user name, and the associated Role on the storage system.
-
On the Administrator Verification page, enter the User
Name for the RSA SecurID user account that is mapped to the Administrator role on the
storage system.
-
On the Summary page, review the MFA configuration information and click
Finish to enable MFA authentication.
- Enter the RSA SecurID passcode for the respective user to complete administrative
verification.