Add Local Authentication to the Inbound Node Using Password Information
About this task
This scenario builds on the Basic SFTP Configuration by adding user authentication to the inbound connection. It compares a password presented by the inbound node to information defined in the local user store. You must add the password information to the local user store before you can test this scenario.
This authentication method requires that credentials for the remote server be defined in the netmap or should be passed from client when selected From User under Credentials Mapping.
SFTP Forward Proxy policy also has a feature 'password overload’ when External Credentials Mapping is set as From User. This feature is optional.
If opted user has to provide to local password and remote server password i,e credentials for the remote server in overloaded password format as mentioned in Overloaded Password section.
Refer to Manage CM User Accounts for instructions.
To add support for password authentication:Procedure
- From IBM Sterling Secure Proxy, select Configuration from the left hand-side navigation panel.
- Click Policies, then in the SFTP Forward Proxy Policy tile, click View Policies to display the list of created SFTP Forward Proxy Policies.
- Choose the policy you wish to edit, then click on the Edit icon.
- Click the Advanced tab.
- Select Password for Required Authentication Method under SSH Authentication Method.
- Enable the User Authentication: Through Local User Store option.
-
External Credentials Mapping configuration
options:
- If From Netmap is selected under External Credentials then configure below.
- Click Netmap under Configuration and click .
- Click Save.